AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationHard
A development team wants to automate the creation of new AWS accounts for different projects, ensuring that each new account has a predefined baseline of security configurations, IAM roles, and VPC settings. This process needs to be repeatable and consistent across all new accounts. Which AWS service is purpose-built for this account provisioning and baseline enforcement?
- AAWS Control Tower
- BAWS Service Catalog
- CAWS Organizations
- DAWS CloudFormation StackSets
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Control Tower
AWS Control Tower is designed to set up and govern a secure, multi-account AWS environment. It provides a landing zone with best-practices, automates the provisioning of new accounts with pre-configured baselines (including security and networking), and enforces guardrails to maintain compliance.
Why the other options are wrong
- B. Service Catalog allows users to provision approved AWS resources, but Control Tower provides the overarching account provisioning and governance framework.
- C. AWS Organizations allows you to centrally manage multiple AWS accounts, but it doesn't automate the *creation* of accounts with a predefined baseline or enforce governance like Control Tower does.
- D. CloudFormation StackSets can deploy CloudFormation stacks across multiple accounts, but Control Tower provides the higher-level automation for *creating* and *governing* the accounts themselves based on best practices.
AWS Control Tower
A service that provides an easy way to set up and govern a secure, multi-account AWS environment, automating account provisioning and enforcing guardrails.
- Creates a secure 'landing zone'.
- Automates new account provisioning with baselines.
- Enforces preventative and detective guardrails.
Memory trick: Control Tower builds accounts, secure and sound.