Question 1 · choose 1
A company uses AWS Organizations with 30 member accounts. A Lambda function in a central operations account must stop tagged development EC2 instances in every member account each night. The security team does not allow long-term access keys anywhere. Which solution meets these requirements?
- ACreate an IAM role in each member account that trusts the function's execution role, and assume each of those roles with AWS STS
- BIn each member account, create an IAM user with EC2 permissions, and keep the users' access keys in AWS Secrets Manager centrally
- CAttach a service control policy to the organization root that allows the central function to stop instances in all member accounts
- DAttach a resource-based policy to each EC2 instance that allows the central execution role to call the ec2:StopInstances action
Show the answer and why
ACreate an IAM role in each member account that trusts the function's execution role, and assume each of those roles with AWS STS
Correct
The role's trust policy names the central account's execution role as a principal, and assuming the role returns temporary credentials for that account. No long-term keys exist anywhere.
BIn each member account, create an IAM user with EC2 permissions, and keep the users' access keys in AWS Secrets Manager centrally
Incorrect
It would work, but access keys are long-term credentials, which the security team forbids. AWS recommends that workloads use IAM roles with temporary credentials instead.
CAttach a service control policy to the organization root that allows the central function to stop instances in all member accounts
Incorrect
An SCP never grants permissions. It only sets the maximum permissions available to users and roles in member accounts, so it cannot give the central function access.
DAttach a resource-based policy to each EC2 instance that allows the central execution role to call the ec2:StopInstances action
Incorrect
Amazon EC2 does not support resource-based policies, so an instance cannot carry a policy that grants a principal in another account access to it.
Cross-account automation uses a role in each target account plus AssumeRole from the caller. SCPs only limit, they never grant, and EC2 has no resource-based policies to grant access from the resource side.
AWS documentation