AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A multinational corporation is migrating hundreds of workloads to AWS and needs to establish a robust governance framework before the migration begins. The Chief Information Security Officer (CISO) has mandated that all new AWS accounts created for migrated applications must automatically prevent certain actions, such as disabling AWS CloudTrail. Additionally, the framework must continuously monitor for and report on non-compliant resource configurations. The goal is to provide business units with a self-service portal to request new accounts that are 'born compliant' with these guardrails in place. Which approach best fulfills these governance requirements using a single, managed AWS solution?
Deploy the AWS Landing Zone solution using its provided AWS CloudFormation templates. This will create the core organizational units and security baselines, and account vending will be handled through its pre-configured Service Catalog product.
Create a new AWS Organization and use custom AWS Lambda functions, triggered by Amazon EventBridge, to apply the necessary Service Control Policies (SCPs) and AWS Config rules to newly created accounts. Develop a separate custom web application for the self-service portal.
Deploy AWS Control Tower to establish a landing zone. It will use AWS Organizations to apply preventative guardrails via SCPs and detective guardrails via AWS Config rules, while using an Account Factory with AWS Service Catalog for self-service account provisioning.
Use AWS Service Catalog to define a product based on an AWS CloudFormation template that creates new AWS accounts. Embed all security configurations as IAM policies and resource definitions within the CloudFormation template to enforce restrictions.
The correct answer is to use AWS Control Tower. AWS Control Tower is a managed service that automates the setup of a secure, multi-account AWS environment called a landing zone. It directly addresses all the requirements by orchestrating several other AWS services. It uses AWS Organizations to create the multi-account structure, applies preventative guardrails through Service Control Policies (SCPs) to block actions like disabling CloudTrail, and deploys detective guardrails using AWS Config rules to monitor for non-compliance. Furthermore, it establishes an 'Account Factory' which utilizes AWS Service Catalog to provide a self-service portal for provisioning new accounts that automatically inherit all the defined governance policies.
Using AWS Organizations with custom Lambda functions is a manual, bespoke approach, not a managed service. While it can achieve a similar outcome, it requires significant development and maintenance effort, contrary to the goal of using a managed solution.
Using only AWS Service Catalog with AWS CloudFormation templates is incomplete. This approach lacks the centralized, preventative enforcement at the organization level that SCPs provide. IAM policies within an account can be altered by administrators of that account, whereas SCPs set at the organizational unit level cannot be overridden by member accounts.
The AWS Landing Zone solution was a template-based predecessor to AWS Control Tower. While it provided similar functionality, it is no longer recommended by AWS for setting up new multi-account environments; AWS Control Tower is the current, managed service that supersedes it.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Control Tower and how does it work?
Open an interactive chat with Bash
What are Service Control Policies (SCPs) and how do they work in AWS Control Tower?
Open an interactive chat with Bash
How does AWS Config ensure compliance in AWS Control Tower?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access