AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationMedium
A SysOps team needs to automate the process of creating new AWS accounts for different departments within their organization, ensuring that each new account is provisioned with a baseline set of security configurations, IAM roles, and VPCs. The solution should also integrate with AWS Organizations. Which AWS service is designed to streamline this multi-account provisioning and governance?
- AAWS Control Tower
- BAWS CloudFormation StackSets
- CAWS Config
- DAWS Service Catalog
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Control Tower
AWS Control Tower is specifically designed to set up and govern a secure, multi-account AWS environment. It automates the creation of new accounts (via Account Factory), applies guardrails, and provisions a baseline of security and networking configurations.
Why the other options are wrong
- B. AWS CloudFormation StackSets deploy CloudFormation stacks across multiple accounts and regions, but Control Tower is the higher-level service for account provisioning and governance baseline.
- C. AWS Config assesses, audits, and evaluates the configurations of your AWS resources, but it doesn't provision new accounts or baseline configurations.
- D. AWS Service Catalog allows organizations to create and manage catalogs of IT services that are approved for use on AWS, but it doesn't automate the creation of new AWS accounts itself.
AWS Control Tower
AWS Control Tower provides an easy way to set up and govern a secure, multi-account AWS environment, automating the creation of accounts with a baseline of security and operational best practices.
- Uses Account Factory for new account provisioning.
- Implements preventive and detective guardrails.
- Integrates with AWS Organizations for account management.
Memory trick: Control Tower *controls* your AWS accounts, setting up a *safe town* for them.