Soru

Zorluk: OrtaMulti-Account Governance and Organizational Structure

A solutions architect is establishing a governed multi-account environment for an enterprise using AWS Control Tower. The architect needs to initialize the landing zone, enforce corporate compliance guardrails, and onboard the first set of application team accounts. Arrange the steps to design and implement this multi-account governance structure in the correct chronological sequence.

  1. 1Configure the AWS Organizations management account and establish the Root organizational structure.
  2. 2Deploy the AWS Control Tower Landing Zone to automatically provision the Security OU, Log Archive account, and Audit account.
  3. 3Apply preventative guardrails (Service Control Policies) to the target Organizational Units to establish baseline governance boundaries.
  4. 4Provision new operational member accounts using the AWS Control Tower Account Factory under the governed OUs.
  5. 5Trigger the Customizations for AWS Control Tower (CfCT) pipeline to deploy local IAM roles and region-specific resources to the enrolled accounts.

Cevap

The correct chronological sequence starts with configuring the AWS Organizations management account, followed by deploying the AWS Control Tower Landing Zone to establish the Security OU and core accounts. Next, preventative guardrails must be applied to the target OUs. Then, operational member accounts can be provisioned via Account Factory. Finally, the Customizations for AWS Control Tower pipeline is triggered to bootstrap resources inside the enrolled accounts.
Establishing a secure multi-account environment requires building from the foundational organization structure up to the account level. The correct path starts with designating the management account and setting up AWS Organizations. Next, the AWS Control Tower Landing Zone is deployed to establish core security OUs and shared accounts (Log Archive and Audit). Guardrails and SCPs are then applied to OUs to ensure governance boundaries are active. Only after the OUs are secured are operational member accounts provisioned using Account Factory, followed by CfCT pipelines to deploy application-specific resources and configurations within those accounts.

Adım Adım Çözüm

1
Set up the management account.
An AWS Organization is initialized with a designated management account.
AWS Control Tower orchestration requires a management account to launch the landing zone.
2
Deploy the Landing Zone.
Security OUs, Log Archive, and Audit accounts are provisioned and integrated.
This establishes the core administrative and security baseline of the landing zone.
3
Enable Service Control Policies (SCPs) on OUs.
The target OUs are configured with mandatory compliance restrictions.
Applying guardrails at the OU level first ensures that any account created under or moved to these OUs is instantly compliant.
4
Use AWS Control Tower Account Factory to provision member accounts.
New member accounts are created, registered with Control Tower, and placed under the governed OUs.
Member accounts should be created using the standardized Account Factory after the target OUs and guardrails are already defined.
5
Apply post-provisioning customizations via CfCT.
Resources such as IAM roles, KMS keys, and local VPC configurations are deployed to the new member accounts.
Customizations are applied to bootstrap accounts after they are successfully created and registered.

Anahtar Kavram

AWS Control Tower Landing Zone Setup and Account Lifecycle Management
Bu soruyu puanla