~/aws-sap-c02 · aws-sap-c02_d1_19466a8ae594
aws-sap-c02_d1_19466a8ae594 domain/d1 · medium single

A company's security team attaches an SCP to an OU that denies access to a set of AWS services. An account administrator in that OU then attaches the AdministratorAccess IAM policy to a role. A developer using that role reports they still cannot call one of the denied services. What is the correct explanation?

Unlock this exam to join the per-question discussion and vote on questions.

next question →