AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A large enterprise is initiating a migration of several hundred on-premises applications to the AWS Cloud. As a prerequisite, the cloud architecture team must establish a new, secure, and scalable multi-account environment. Key requirements include the automated setup of a best-practice landing zone, enforcement of preventive and detective guardrails, centralized logging and auditing capabilities, and a streamlined 'account factory' process for vending new AWS accounts that conform to corporate governance policies. Which AWS service should a solutions architect recommend to most efficiently meet these comprehensive requirements?
AWS Security Hub and AWS Config
AWS Organizations with a custom set of AWS CloudFormation StackSets
The correct answer is AWS Control Tower. This service is designed to automate the setup of a secure, well-architected, multi-account AWS environment called a landing zone. It orchestrates multiple other AWS services, including AWS Organizations, AWS IAM Identity Center, AWS Service Catalog (for the Account Factory), AWS Config, and AWS CloudTrail, to provide a holistic governance solution out of the box. It includes pre-configured preventive and detective guardrails and a dashboard for monitoring compliance, directly addressing all the specified requirements in the most efficient manner.
Using AWS Organizations with custom CloudFormation templates is a viable but much more labor-intensive approach. It requires the customer to design, build, and maintain the entire landing zone infrastructure and governance logic, which is less efficient than using the managed Control Tower service.
The AWS Landing Zone solution was a predecessor to AWS Control Tower. It was a solution based on CloudFormation templates and has been superseded by AWS Control Tower, which is the recommended service for new landing zone deployments.
AWS Security Hub and AWS Config are essential components for security posture management and compliance auditing (detective controls), respectively. While Control Tower uses these services as part of its landing zone, they do not, by themselves, create the multi-account structure, provide an account factory, or establish the foundational landing zone.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a landing zone in AWS?
Open an interactive chat with Bash
How does AWS Control Tower enforce guardrails?
Open an interactive chat with Bash
What is the purpose of the Account Factory in AWS Control Tower?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access