AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationHard

A development team wants to automate the creation of new AWS accounts for different projects, ensuring that each new account has a predefined baseline of security configurations, IAM roles, and VPC settings. This process needs to be repeatable and consistent across all new accounts. Which AWS service is purpose-built for this account provisioning and baseline enforcement?

  1. AAWS Control Tower
  2. BAWS Service Catalog
  3. CAWS Organizations
  4. DAWS CloudFormation StackSets
Show answer & explanation

Correct answer: A. AWS Control Tower

AWS Control Tower is designed to set up and govern a secure, multi-account AWS environment. It provides a landing zone with best-practices, automates the provisioning of new accounts with pre-configured baselines (including security and networking), and enforces guardrails to maintain compliance.

Why the other options are wrong

  • B. Service Catalog allows users to provision approved AWS resources, but Control Tower provides the overarching account provisioning and governance framework.
  • C. AWS Organizations allows you to centrally manage multiple AWS accounts, but it doesn't automate the *creation* of accounts with a predefined baseline or enforce governance like Control Tower does.
  • D. CloudFormation StackSets can deploy CloudFormation stacks across multiple accounts, but Control Tower provides the higher-level automation for *creating* and *governing* the accounts themselves based on best practices.

AWS Control Tower

A service that provides an easy way to set up and govern a secure, multi-account AWS environment, automating account provisioning and enforcing guardrails.

  • Creates a secure 'landing zone'.
  • Automates new account provisioning with baselines.
  • Enforces preventative and detective guardrails.

Memory trick: Control Tower builds accounts, secure and sound.

More Deployment, Provisioning, and Automation questions