AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A global software company maintains a large number of AWS accounts for development, testing, and production environments across various regions. Each account must have a standardized set of IAM roles and policies for cross-account access and service-linked roles. The company wants to automate the creation and consistent management of these baseline IAM resources across all new and existing accounts and regions, ensuring that any updates to the baseline are propagated efficiently. What is the MOST suitable AWS service for this purpose?

  1. ACustom scripts leveraging AWS SDKs.
  2. BAWS Systems Manager State Manager.
  3. CAWS CloudFormation StackSets.
  4. DAWS Organizations with Service Control Policies (SCPs).
Show answer & explanation

Correct answer: C. AWS CloudFormation StackSets.

AWS CloudFormation StackSets are specifically designed to deploy and manage CloudFormation stacks across multiple AWS accounts and regions from a single administrator account. This allows the company to define their standardized IAM roles and policies once in a CloudFormation template and then deploy and update them consistently across all target accounts and regions, ensuring efficient propagation of changes and consistent baseline configuration.

Why the other options are wrong

  • A. Custom scripts would require significant development and maintenance overhead, and lack the built-in management capabilities (e.g., error handling, status tracking) that StackSets provide natively.
  • B. Systems Manager State Manager is primarily for configuration management on EC2 instances, not for provisioning and managing IAM resources across multiple accounts and regions.
  • D. SCPs are for setting maximum permissions and preventing certain actions, not for provisioning or managing specific IAM roles and policies within accounts.

CloudFormation StackSets

CloudFormation StackSets extend the functionality of CloudFormation to deploy and manage stacks across multiple AWS accounts and regions from a single operation.

  • Centralized deployment across distributed accounts/regions.
  • Ensures consistent infrastructure provisioning.
  • Simplifies updates and management of baseline configurations.

Memory trick: StackSets are like a master template that stamps out identical copies everywhere.

More Configuration Management and Infrastructure as Code questions