A police evidence vault AWS account must deny broad access from outside a dedicated security organizational unit. Which Organizations design supports that containment?
Select an answer to reveal the explanation.
Short Explanation
Evidence belongs in a locked wing of city hall—the security OU—with ordinances (SCPs) that block wanderers from other wings. Parking the vault in a sandbox OU or the management account with wide-open admin misses containment. Public buckets are the opposite of a vault.
Full Explanation
AWS Organizations OUs group accounts for policy inheritance. High-sensitivity accounts such as an evidence vault should sit in a dedicated security OU with SCPs that restrict which principals and actions are allowed, limiting lateral movement from less trusted OUs. Management-account co-mingling, unmanaged sandbox placement, or public object access contradict containment goals.