An organization plans to establish a secure, multi-account AWS environment using AWS Control Tower. The solutions architect must prepare the account, launch the landing zone, establish centralized access, register organizational units, enroll new member accounts under governance, and deploy custom policies across the entire organization. Arrange the steps in the correct chronological order to implement this governance solution.
- 1Disable any pre-existing AWS Config configuration recorders and delivery channels in the management account across all supported regions.
- 2Set up and launch the AWS Control Tower landing zone from the management account to establish core logging and security accounts.
- 3Configure AWS IAM Identity Center to federate access and assign permission sets to administrative groups.
- 4Create custom Organizational Units (OUs) in AWS Organizations and register them with AWS Control Tower to extend guardrails.
- 5Provision new workload accounts through the AWS Control Tower Account Factory to ensure automatic enrollment and guardrail inheritance.
- 6Deploy the Customizations for AWS Control Tower (CfCT) framework to apply custom Service Control Policies (SCPs) across the registered OUs.
Cevap
The correct chronological sequence is to first disable any pre-existing AWS Config configuration recorders and delivery channels, second set up and launch the AWS Control Tower landing zone, third configure AWS IAM Identity Center for federated administrative access, fourth create and register custom OUs with Control Tower, fifth provision new workload accounts using Account Factory, and finally deploy the Customizations for AWS Control Tower (CfCT) framework to apply custom Service Control Policies (SCPs).
Establishing a secure multi-account environment with AWS Control Tower requires a strict ordering. First, pre-existing AWS Config configuration recorders must be disabled in the management account to avoid setup conflicts. Next, the AWS Control Tower landing zone is launched to create core accounts (logging, security) and OUs. Once the environment is initialized, AWS IAM Identity Center is configured to define federated access. Following this, custom OUs must be created and registered under AWS Control Tower governance. Member accounts can then be provisioned using the Account Factory so that they inherit these guardrails from the start. Finally, custom policies and resources are deployed using the Customizations for AWS Control Tower (CfCT) framework once the organizational structure and accounts are in place.
Adım Adım Çözüm
Anahtar Kavram
AWS Control Tower Landing Zone Setup and Governance Customization Sequence
Tahmini Süre:2m 0s