Soru

Zorluk: OrtaMulti-Account Governance and Organizational Structure

A financial services company manages its multi-account environment using AWS Organizations. The security team mandates that all Amazon EBS volumes across all member accounts must be backed up daily, and the backups must be stored in a central vault. The company wants to delegate the administration of these backup policies to a dedicated backup-admin account, minimizing the use of the Organizations management account.

Arrange the correct sequence of steps to configure this centralized backup governance model across the organization.

  1. 1Enable the Backup policy type in the AWS Organizations management account.
  2. 2Register the backup-admin account as the delegated administrator for AWS Backup from the Organizations management account.
  3. 3In the backup-admin account, create the centralized Backup vault and define a vault access policy allowing cross-account backup writes.
  4. 4In the backup-admin account, create the Backup policy that specifies the daily backup schedule and targets the centralized vault.
  5. 5In the backup-admin account, attach the Backup policy to the target Organizational Units (OUs).

Cevap

The correct order begins with enabling the Backup policy type in the management account, followed by registering the delegated administrator, creating the destination backup vault and access policy, creating the backup policy, and finally attaching the policy to the target OUs.
The correct sequence ensures that prerequisites are met at each stage: enabling the policy type, delegating administrative rights, establishing the target storage resource with access controls, defining the compliance policy, and finally applying it to the resource hierarchy.

Adım Adım Çözüm

1
Enable Backup policies in the Organizations management account.
The organization configuration is updated to support Backup policies.
Backup policies cannot be created or managed by any account until the policy type is enabled at the root organization level.
2
Register the backup-admin account as the delegated administrator for AWS Backup.
The backup-admin account receives administrative authority for Backup policies across the organization.
The management account must explicitly grant delegated permissions before the member account can perform administrative actions.
3
Create the centralized Backup vault and associate a cross-account vault access policy in the backup-admin account.
A vault is established that permits recovery points from other accounts in the organization.
Without a valid destination vault ARN and a policy granting cross-account write permissions, backups sent by member accounts will be rejected.
4
Create the Backup policy in the backup-admin account.
A JSON Backup policy is defined within the organization.
The policy must be created with correct plan details and destination vault configurations before it can be distributed.
5
Attach the Backup policy to the target OUs in the backup-admin account.
The backup schedule is applied to all accounts and EBS resources within the target OUs.
Attaching the policy initiates and enforces the backup schedule across the specified resources in the member accounts.

Anahtar Kavram

Delegated administration in AWS Organizations allows member accounts to manage specific service policies, reducing the operational burden on the management account.
Tahmini Süre:2m 0s
Bu soruyu puanla