AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsEasy

A global financial institution is expanding its operations into new regions and needs to establish a secure and compliant AWS environment for each region. The solution must ensure consistent security baselines, regulatory compliance, and centralized governance across all accounts and regions. Existing accounts must also be integrated into this new structure without interruption. Which AWS service should be used to meet these requirements?

  1. AAWS Control Tower
  2. BAWS Security Hub with AWS Config
  3. CAWS CloudFormation StackSets
  4. DAWS Organizations with Service Control Policies (SCPs)
Show answer & explanation

Correct answer: A. AWS Control Tower

AWS Control Tower is specifically designed to set up and govern a secure, multi-account AWS environment, providing a landing zone with pre-configured guardrails and centralized management. It automates the setup of AWS Organizations, SCPs, and other foundational services, making it ideal for establishing consistent governance across multiple regions and integrating existing accounts.

Why the other options are wrong

  • B. AWS Security Hub and AWS Config are used for security posture management and configuration compliance, respectively, but do not provide the overarching framework for setting up and governing a landing zone across multiple regions and accounts.
  • C. AWS CloudFormation StackSets can deploy resources consistently across accounts and regions but does not provide the pre-built guardrails, centralized logging, and integrated identity management that Control Tower offers for a secure landing zone.
  • D. AWS Organizations with SCPs provides the foundational structure but requires significant manual configuration to achieve the full governance capabilities offered by Control Tower, especially for new regions and existing account integration.

AWS Control Tower

A managed service that automates the setup of a secure, multi-account AWS environment (landing zone) with pre-configured guardrails, centralized logging, and identity management.

  • Establishes a secure and compliant multi-account environment.
  • Provides preventative and detective guardrails.
  • Automates the creation of AWS Organizations, SCPs, and other foundational services.

Memory trick: Control Tower builds a strong, secure foundation for your AWS empire.

More Design for New Solutions questions