A city council policy requires separating billing owners from workload administrators so the same person cannot both pay invoices and change production IAM. Which architecture best enforces that separation of duties?
Select an answer to reveal the explanation.
Short Explanation
Think of the finance clerk and the building electrician—different badges on purpose. Separate accounts or tightly scoped roles keep billing owners off production IAM and keep workload admins out of payment controls. One mega-admin, a shared root password, or dark CloudTrail are how separation of duties collapses.
Full Explanation
Separation of duties reduces fraud and accidental privilege concentration by ensuring billing ownership and workload administration are not held by the same principals. AWS multi-account structures and IAM permission boundaries or role design can isolate Billing and Cost Management actions from administrative actions on compute, IAM, and data planes. Sharing AdministratorAccess with billing rights, circulating root credentials, or disabling audit trails directly undermines that policy. The architect therefore separates accounts or roles accordingly.