Amazon AWS Solutions Architect Professional SAP-C02 Organizations Control Tower Resource Sharing Practice Test
Domain 1.4 • 25 original questions
This AWS SAP-C02 AWS Certified Solutions Architect – Professional practice test focuses on organizations control tower resource sharing and governance through original architecture scenarios aligned to the current AWS Certification exam guide. Use the full ExamSnap SAP-C02 collection for practice across all four content domains. For broader exam preparation, review the Amazon AWS Certified Solutions Architect – Professional SAP-C02 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
Lamna Healthcare has already validated the surrounding application components. The remaining architecture requirement for its global web application is to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts while keeping administration centralized across accounts. Which option is best? The current estate includes 35 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: B
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
Option review:
A: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while keeping administration centralized across accounts.
B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
C: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while keeping administration centralized across accounts.
D: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while keeping administration centralized across accounts.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work while keeping administration centralized across accounts.
While conducting a security design review, the cloud platform architect at Fourth Coffee needs to retain centralized audit logs even if a workload account is compromised while keeping administration centralized across accounts. Which architecture decision best matches the stated constraints? The current estate includes 42 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: C
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
Option review:
A: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while keeping administration centralized across accounts.
B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while keeping administration centralized across accounts.
C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while keeping administration centralized across accounts.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work while keeping administration centralized across accounts.
During a modernization initiative at Consolidated Messenger, the site reliability architect is designing a analytics pipeline. The requirement is to reduce duplicate infrastructure across accounts while preserving account isolation while keeping administration centralized across accounts. Which architecture is the best fit? The current estate includes 49 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: B
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
Option review:
A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while keeping administration centralized across accounts.
B: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while keeping administration centralized across accounts.
C: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while keeping administration centralized across accounts.
D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while keeping administration centralized across accounts.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work while keeping administration centralized across accounts.
Litware Manufacturing operates a media processing platform. In a production readiness review, the migration architect must create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts while preserving AWS-native auditability and measurable health signals. Which option should be recommended? The current estate includes 9 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
Correct answer: B
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
Option review:
A: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while preserving AWS-native auditability and measurable health signals.
B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while preserving AWS-native auditability and measurable health signals.
D: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while preserving AWS-native auditability and measurable health signals.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.
A principal architect asks which AWS approach is intended to retain centralized audit logs even if a workload account is compromised while preserving AWS-native auditability and measurable health signals. What is the best answer? The current estate includes 16 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: A
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
Option review:
A: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
B: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while preserving AWS-native auditability and measurable health signals.
C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while preserving AWS-native auditability and measurable health signals.
D: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while preserving AWS-native auditability and measurable health signals.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.
Tailspin Logistics is changing its order-processing system as part of a hybrid connectivity redesign. Which AWS approach best enables the team to reduce duplicate infrastructure across accounts while preserving account isolation while preserving AWS-native auditability and measurable health signals? The current estate includes 23 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: B
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
Option review:
A: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while preserving AWS-native auditability and measurable health signals.
B: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while preserving AWS-native auditability and measurable health signals.
C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while preserving AWS-native auditability and measurable health signals.
D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while preserving AWS-native auditability and measurable health signals.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work while preserving AWS-native auditability and measurable health signals.
An architecture board at Alpine Sports asks the enterprise architect to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts without relying on a one-off operator runbook for a analytics pipeline. Which recommendation is most appropriate? The current estate includes 30 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: B
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
Option review:
A: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without relying on a one-off operator runbook.
B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without relying on a one-off operator runbook.
D: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without relying on a one-off operator runbook.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work without relying on a one-off operator runbook.
For a media processing platform at Adventure Works, a new workload design identifies one priority: retain centralized audit logs even if a workload account is compromised without relying on a one-off operator runbook. Which AWS design should the team choose? The current estate includes 37 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
Correct answer: C
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
Option review:
A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without relying on a one-off operator runbook.
B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without relying on a one-off operator runbook.
C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without relying on a one-off operator runbook.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work without relying on a one-off operator runbook.
VanArsdel Energy has already validated the surrounding application components. The remaining architecture requirement for its global web application is to reduce duplicate infrastructure across accounts while preserving account isolation without relying on a one-off operator runbook. Which option is best? The current estate includes 44 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
Option review:
A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without relying on a one-off operator runbook.
B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without relying on a one-off operator runbook.
C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without relying on a one-off operator runbook.
D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate without relying on a one-off operator runbook.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work without relying on a one-off operator runbook.
Which solution is the strongest match for the following professional-level architecture requirement: create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts while keeping the pattern scalable as the organization adds accounts? The current estate includes 4 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: C
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
Option review:
A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
B: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
D: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.
During a multi-account governance review at Lucerne Publishing, the site reliability architect is designing a analytics pipeline. The requirement is to retain centralized audit logs even if a workload account is compromised while keeping the pattern scalable as the organization adds accounts. Which architecture is the best fit? The current estate includes 11 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: A
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
Option review:
A: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
B: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
C: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.
Correct answer: A
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
Option review:
A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while keeping the pattern scalable as the organization adds accounts.
B: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
C: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
D: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while keeping the pattern scalable as the organization adds accounts.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work while keeping the pattern scalable as the organization adds accounts.
A principal solutions architect at Wide World Importers is reviewing a global web application. The business requires the team to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts without granting broad administrator permissions. Which design most directly satisfies the requirement? The current estate includes 25 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: A
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
Option review:
A: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
B: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without granting broad administrator permissions.
C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without granting broad administrator permissions.
D: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without granting broad administrator permissions.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work without granting broad administrator permissions.
Bellows University is changing its order-processing system as part of a security design review. Which AWS approach best enables the team to retain centralized audit logs even if a workload account is compromised without granting broad administrator permissions? The current estate includes 32 AWS accounts and active workloads in us-east-1 and eu-west-1. Assume all unspecified components already meet their requirements.
Correct answer: C
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
Option review:
A: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without granting broad administrator permissions.
B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without granting broad administrator permissions.
C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
D: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without granting broad administrator permissions.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work without granting broad administrator permissions.
Which AWS architecture principle or service combination best addresses this requirement for Blue Yonder Airlines: reduce duplicate infrastructure across accounts while preserving account isolation without granting broad administrator permissions? The current estate includes 39 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: D
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
Option review:
A: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without granting broad administrator permissions.
B: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without granting broad administrator permissions.
C: Centralized logs and findings provide traceability and cross-account visibility while keeping security duties separated from workload administration. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without granting broad administrator permissions.
D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate without granting broad administrator permissions.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work without granting broad administrator permissions.
For a media processing platform at City Power, a production readiness review identifies one priority: create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts while preferring managed AWS capabilities over bespoke infrastructure. Which AWS design should the team choose? The current estate includes 46 AWS accounts and active workloads in eu-west-1 and eu-central-1. The team wants the most direct architecture decision for this requirement.
Correct answer: D
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
Option review:
A: A backup is useful only when retention, isolation, encryption, and restore procedures are designed and tested against recovery requirements. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
B: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
C: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
D: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.
Proseware Labs has already validated the surrounding application components. The remaining architecture requirement for its global web application is to retain centralized audit logs even if a workload account is compromised while preferring managed AWS capabilities over bespoke infrastructure. Which option is best? The current estate includes 6 AWS accounts and active workloads in us-east-1 and us-west-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: C
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
Option review:
A: AWS purchasing models trade commitment and flexibility for discounts; the workload interruption tolerance and usage predictability determine the best fit. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
B: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
D: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.
While conducting a hybrid connectivity redesign, the cloud platform architect at Southridge Video needs to reduce duplicate infrastructure across accounts while preserving account isolation while preferring managed AWS capabilities over bespoke infrastructure. Which architecture decision best matches the stated constraints? The current estate includes 13 AWS accounts and active workloads in us-east-1 and eu-west-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: B
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
Option review:
A: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
B: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while preferring managed AWS capabilities over bespoke infrastructure.
C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while preferring managed AWS capabilities over bespoke infrastructure.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work while preferring managed AWS capabilities over bespoke infrastructure.
During a resilience assessment at Woodgrove Bank, the site reliability architect is designing a analytics pipeline. The requirement is to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts while enabling the pattern to be reused consistently across organizational units. Which architecture is the best fit? The current estate includes 20 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: B
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
Option review:
A: Direct Connect is designed for dedicated private connectivity, while VPN can provide encrypted internet-based connectivity and backup diversity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
B: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
C: Transit Gateway provides transitive routing and centralized connectivity for many VPCs and hybrid attachments, reducing route-management complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
D: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.
Relecloud Systems is documenting its target-state architecture. Which choice most accurately addresses the need to retain centralized audit logs even if a workload account is compromised while enabling the pattern to be reused consistently across organizational units? The current estate includes 27 AWS accounts and active workloads in eu-west-1 and eu-central-1. Assume all unspecified components already meet their requirements.
Correct answer: C
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
Option review:
A: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
B: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
C: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
D: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.
A principal solutions architect at Fabrikam Health is reviewing a global web application. The business requires the team to reduce duplicate infrastructure across accounts while preserving account isolation while enabling the pattern to be reused consistently across organizational units. Which design most directly satisfies the requirement? The current estate includes 34 AWS accounts and active workloads in us-east-1 and us-west-2. Prefer an AWS-managed capability when it meets the requirements with less operational overhead.
Correct answer: A
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
Option review:
A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate while enabling the pattern to be reused consistently across organizational units.
B: AWS network telemetry helps isolate routing and security failures, while VPC endpoints keep supported service traffic off the public internet. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
D: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of while enabling the pattern to be reused consistently across organizational units.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work while enabling the pattern to be reused consistently across organizational units.
Trey Research is changing its order-processing system as part of a global expansion project. Which AWS approach best enables the team to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts without introducing an unrelated application rewrite? The current estate includes 41 AWS accounts and active workloads in us-east-1 and eu-west-1. The team wants the most direct architecture decision for this requirement.
Correct answer: D
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: Rightsizing tools identify resource-efficiency opportunities, while tagging provides durable cost attribution for reporting and accountability. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without introducing an unrelated application rewrite.
B: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without introducing an unrelated application rewrite.
C: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of without introducing an unrelated application rewrite.
D: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work without introducing an unrelated application rewrite.
An architecture board at Northwind Media asks the enterprise architect to retain centralized audit logs even if a workload account is compromised without introducing an unrelated application rewrite for a analytics pipeline. Which recommendation is most appropriate? The current estate includes 48 AWS accounts and active workloads in ap-southeast-1 and ap-southeast-2. The design must preserve security and auditability while meeting the stated objective.
Correct answer: D
Why: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: AWS cost-management tools provide different levels of trend analysis, forecasting, detailed usage data, and proactive budget notifications. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without introducing an unrelated application rewrite.
B: AWS Global Infrastructure choices should be driven by business latency, regulatory, service-availability, and resilience requirements rather than geography alone. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without introducing an unrelated application rewrite.
C: Route 53 Resolver endpoints provide managed hybrid DNS resolution between VPCs and on-premises DNS systems without custom resolver fleets. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to retain centralized audit logs even if a workload account is compromised under the additional constraint of without introducing an unrelated application rewrite.
D: Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Learning point: Use organization-level logging and centralized event aggregation, with delegated administration and protected log destinations. Centralized event and log collection improves detection, auditability, and resilience against tampering in individual workload accounts. In this variant, the decision also has to work without introducing an unrelated application rewrite.
For a media processing platform at Coho Financial, a migration wave planning session identifies one priority: reduce duplicate infrastructure across accounts while preserving account isolation without introducing an unrelated application rewrite. Which AWS design should the team choose? The current estate includes 8 AWS accounts and active workloads in eu-west-1 and eu-central-1. Select the option that satisfies the requirement with the fewest unnecessary moving parts.
Correct answer: A
Why: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
Option review:
A: AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. This directly addresses the primary requirement and remains appropriate without introducing an unrelated application rewrite.
B: KMS provides auditable key control for supported AWS services and ACM manages certificate issuance and renewal for supported integrations. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without introducing an unrelated application rewrite.
C: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without introducing an unrelated application rewrite.
D: Elastic self-healing architectures reduce manual recovery steps and avoid dependence on a single vertically scaled component. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to reduce duplicate infrastructure across accounts while preserving account isolation under the additional constraint of without introducing an unrelated application rewrite.
Learning point: Use AWS Resource Access Manager and supported shared-resource patterns under Organizations. AWS RAM enables governed sharing of supported resources across accounts and organizational units while retaining centralized ownership. In this variant, the decision also has to work without introducing an unrelated application rewrite.
Following an acquisition, Lamna Healthcare is rationalizing its global web application. The architecture board documented two acceptance criteria: create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts; and the solution must do so while minimizing manual intervention during steady-state operations. Which target-state recommendation should the security architect approve? The current estate includes 15 AWS accounts and active workloads in us-east-1 and us-west-2. Choose the option that best meets the stated constraints without introducing an unrelated redesign.
Correct answer: C
Why: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.
Option review:
A: Centralized federation and role assumption avoid long-lived IAM users in every account and provide consistent least-privilege access across accounts. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while minimizing manual intervention during steady-state operations.
B: Non-overlapping addressing and deliberate segmentation make routing, inspection, and future network growth predictable and auditable. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while minimizing manual intervention during steady-state operations.
C: Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. This directly addresses the primary requirement and remains appropriate while minimizing manual intervention during steady-state operations.
D: RTO and RPO should drive the DR pattern; higher readiness generally reduces recovery time but increases steady-state cost and operational complexity. This can be valid in another AWS architecture context, but it does not most directly satisfy the primary requirement to create a governed multi-account landing zone with separate security, logging, infrastructure, and workload accounts under the additional constraint of while minimizing manual intervention during steady-state operations.
Learning point: Use AWS Organizations with AWS Control Tower to establish an organizational-unit and account model with guardrails and centralized governance. Organizations and Control Tower provide account vending, OU structure, policy guardrails, and baseline governance for scalable multi-account environments. In this variant, the decision also has to work while minimizing manual intervention during steady-state operations.
Popular posts
Recent Posts
