AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A multinational corporation is migrating hundreds of workloads to AWS and needs to establish a robust governance framework before the migration begins. The Chief Information Security Officer (CISO) has mandated that all new AWS accounts created for migrated applications must automatically prevent certain actions, such as disabling AWS CloudTrail. Additionally, the framework must continuously monitor for and report on non-compliant resource configurations. The goal is to provide business units with a self-service portal to request new accounts that are 'born compliant' with these guardrails in place. Which approach best fulfills these governance requirements using a single, managed AWS solution?

  • Deploy the AWS Landing Zone solution using its provided AWS CloudFormation templates. This will create the core organizational units and security baselines, and account vending will be handled through its pre-configured Service Catalog product.

  • Create a new AWS Organization and use custom AWS Lambda functions, triggered by Amazon EventBridge, to apply the necessary Service Control Policies (SCPs) and AWS Config rules to newly created accounts. Develop a separate custom web application for the self-service portal.

  • Deploy AWS Control Tower to establish a landing zone. It will use AWS Organizations to apply preventative guardrails via SCPs and detective guardrails via AWS Config rules, while using an Account Factory with AWS Service Catalog for self-service account provisioning.

  • Use AWS Service Catalog to define a product based on an AWS CloudFormation template that creates new AWS accounts. Embed all security configurations as IAM policies and resource definitions within the CloudFormation template to enforce restrictions.

AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot