Soru

Zorluk: KolayMulti-Account Governance and Organizational Structure

A solutions architect is planning to implement standardized multi-account governance using AWS Control Tower for a new organization. Arrange the steps in the correct chronological order to establish and extend the landing zone.

  1. 1Designate or create a standalone AWS account to serve as the management account for the organization.
  2. 2Configure the Landing Zone parameters and launch AWS Control Tower from the management account.
  3. 3Provision the core shared accounts, including the Log Archive and Security Audit accounts, under the Security Organizational Unit.
  4. 4Use the AWS Control Tower Account Factory to provision individual member accounts for specific workload environments.

Cevap

The correct sequence is: first, designate the root management account; second, configure and launch AWS Control Tower; third, provision the core shared accounts (Log Archive and Security Audit); and finally, use the Account Factory to provision individual workload accounts.
The correct chronological process begins with establishing the management account. Next, the solutions architect launches AWS Control Tower from that account. Following that, core security accounts (Log Archive and Audit) are automatically provisioned. Lastly, standard workload accounts are spawned via the Account Factory.

Adım Adım Çözüm

1
Select a clean AWS account to act as the root management account.
The root management account is established to serve as the administrative anchor of AWS Organizations.
Centralized governance requires an authoritative parent account to host AWS Organizations and AWS Control Tower.
2
Navigate to AWS Control Tower in the management account and initiate landing zone setup.
AWS Control Tower starts orchestrating the multi-account setup from the root account.
Enabling Control Tower initiates the automated creation of the organization, organizational units (OUs), and basic guardrails.
3
Ensure the deployment of core shared accounts under the Security OU.
The Log Archive account and Security Audit account are successfully deployed.
Centralized logging and security auditing configurations must be baseline-integrated before any end-user workloads are deployed.
4
Access the AWS Control Tower Account Factory via Service Catalog.
Workload-specific AWS accounts (such as development or production accounts) are provisioned under standardized templates.
Account Factory is the mechanism to safely scale member account deployment while maintaining organizational compliance.

Anahtar Kavram

Establishing an AWS Control Tower Landing Zone requires configuring administrative management, deploying core security and logging structures, and then scaling through standardized account provisioning.
Tahmini Süre:1m 0s
Bu soruyu puanla