AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A CloudOps engineer must ensure that a new IAM role and a set of required AWS Config rules are deployed to every account in the company's AWS Organization. The resources must exist in us-east-1 and eu-west-1, and they must also be automatically provisioned when new member accounts are created. The engineer wants the simplest solution with minimal ongoing maintenance. Which approach meets these requirements?

  • Create a CloudFormation StackSet with service-managed permissions, target the organization's root, enable automatic deployments to new accounts, and specify us-east-1 and eu-west-1 as deployment Regions.

  • Create a CloudFormation StackSet with self-managed permissions, manually create the required execution roles in each account and Region, and deploy the stack set.

  • Store the CloudFormation template in an S3 bucket, grant cross-account access, and configure a CodeBuild project in each account and Region to run the template when an EventBridge rule detects a new account.

  • Add the IAM role and Config rules to an AWS Resource Access Manager (RAM) resource share, share it with the organization, and enable automatic sharing with new accounts.

AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot