An enterprise is establishing a multi-account AWS environment. The cloud operations team must satisfy the following governance goals:
1. Automatically set up a secure, governed multi-account AWS environment (landing zone) based on AWS best practices.
2. Centrally enforce security guidelines by applying policy controls that restrict allowed AWS services and API actions across all member accounts.
Which AWS services should the enterprise implement to meet these requirements? (Select TWO).
- AWS Control TowerAnswer
- AWS OrganizationsAnswer
- CAWS Config
- DAWS Systems Manager
- EAWS CloudFormation
Answer
AWS Control Tower and AWS Organizations
AWS Control Tower automates the creation of a multi-account environment (landing zone) using best-practice blueprints. AWS Organizations acts as the underlying service to manage these accounts centrally and apply Service Control Policies (SCPs) to enforce permission boundaries and restrict API calls.
Step-by-Step Solution
Key Concept
Multi-account governance using landing zones and central policy boundaries