AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeHard

A large enterprise is adopting a multi-account strategy with a centralized security team responsible for defining baseline security configurations for all AWS accounts. They use AWS CloudFormation for infrastructure provisioning. They need to ensure that every new EC2 instance across all development and production accounts automatically gets a specific set of security groups and an IAM instance profile defined by the security team, without developers having to explicitly include them in their CloudFormation templates. How can this requirement be met with the LEAST operational overhead?

  1. ARequire developers to include a nested stack for security configurations in every EC2 instance template.
  2. BUse CloudFormation StackSets to deploy a baseline security stack to all accounts.
  3. CDevelop custom CloudFormation macros to inject security configurations into templates before deployment.
  4. DImplement AWS Service Catalog to provide pre-approved EC2 products that include the required security configurations.
Show answer & explanation

Correct answer: D. Implement AWS Service Catalog to provide pre-approved EC2 products that include the required security configurations.

AWS Service Catalog allows the centralized security team to create and manage a portfolio of approved AWS resources, including EC2 instances with predefined security groups and IAM instance profiles. Developers can then provision these 'products' without needing to understand or explicitly include the underlying security configurations, ensuring compliance with minimal operational overhead for both developers and the security team. This approach centralizes the definition and decentralizes the consumption of compliant resources.

Why the other options are wrong

  • A. This increases operational overhead for developers by requiring them to remember and include specific nested stacks, which can lead to errors or non-compliance.
  • B. CloudFormation StackSets deploy entire stacks, not individual EC2 instances. While useful for baseline infrastructure, it doesn't directly address the need for developers to provision compliant EC2 instances without explicit security configuration in their templates.
  • C. Custom CloudFormation macros can inject configurations, but they add complexity in development and maintenance, and require developers to opt-in or use a specific macro, which is less seamless than Service Catalog's product-based approach.

AWS Service Catalog

Allows organizations to create and manage catalogs of IT services that are approved for use on AWS, ensuring consistent governance and enabling self-service provisioning.

  • Centralized control over approved resources.
  • Enables self-service provisioning for end-users.
  • Ensures compliance with organizational standards.

Memory trick: Service Catalog is like a vending machine for compliant infrastructure — grab what you need, it's already approved.

More Configuration Management and Infrastructure as Code questions