AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsEasy

A global financial institution is expanding its operations into new regions and needs to ensure that all new AWS accounts provisioned for these regions adhere to corporate security and compliance standards from day one. The solution must enable rapid provisioning of new accounts, enforce mandatory security controls, and provide a unified view of compliance status across all accounts. The institution wants to minimize manual configuration and ensure consistency across its global footprint. Which AWS service is best suited for this scenario?

  1. AAWS Organizations with Service Control Policies (SCPs) and AWS CloudFormation templates.
  2. BAWS Config rules deployed via Conformance Packs across all accounts.
  3. CAWS CloudFormation StackSets with centralized templates for resource deployment.
  4. DAWS Control Tower with Account Factory and Guardrails.
Show answer & explanation

Correct answer: D. AWS Control Tower with Account Factory and Guardrails.

AWS Control Tower is designed for exactly this scenario: setting up and governing a multi-account AWS environment. Its Account Factory allows rapid provisioning of new accounts, and its Guardrails (both preventative and detective) enforce mandatory security and compliance controls automatically, providing a unified compliance view.

Why the other options are wrong

  • A. Organizations and SCPs provide a good foundation for policies, and CloudFormation helps with automation, but this combination requires significant manual effort to build out the full landing zone, centralized logging, and comprehensive guardrails that Control Tower provides out-of-the-box.
  • B. AWS Config Conformance Packs help assess and audit compliance post-deployment but do not provision accounts, enforce preventative guardrails, or establish the foundational landing zone environment from day one.
  • C. CloudFormation StackSets are excellent for deploying resources consistently across accounts but don't inherently establish the foundational account structure, centralized logging, or comprehensive governance framework of a landing zone.

AWS Control Tower for Multi-Region Governance

AWS Control Tower helps global enterprises establish and govern secure, multi-account AWS environments (landing zones) across multiple regions, ensuring consistent compliance and security policies from initial account provisioning.

  • Automates the creation of new AWS accounts with a predefined baseline.
  • Enforces preventative and detective guardrails for compliance.
  • Provides a centralized dashboard for governance and compliance status.

Memory trick: Control Tower Governs Global Growth with Guardrails.

More Design for New Solutions questions