AWS Certified Solutions Architect Associate SAA-C03 Practice Question
Which service enables the automated creation and governance of a secure, compliant multi-account environment?
Control Tower
Security Hub
The correct answer is AWS Control Tower as it enables the automated setup of a baseline environment that adheres to best practices for governance and security. Other services mentioned, like AWS Organizations, manage accounts at scale but lack the automation for security baselines. AWS Config monitors and records configurations changes, whereas AWS Security Hub aggregates and assesses security findings across accounts but neither service establishes a multi-account environment.
