Tüm alıştırma soruları
27 soru
An enterprise is designing a secure governance framework for its AWS Organizations structure, which consists of multiple organizational units (OUs) and a dedicated centralized Logging account. To comply with regulatory standards, a solutions architect must establish an organizational CloudTrail that logs all API activity across all member accounts. The architecture must adhere to the principle of least privilege by avoiding the use of the Management account for daily auditing tasks, and it must prevent any modifications or deletions of logging resources by member accounts.
What is the correct sequence of steps to configure this centralized, secure auditing solution?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is planning to establish a governed, multi-account AWS environment. The security team requires that all workload accounts inherit custom security baseline policies immediately upon creation or enrollment. The solutions architect decided to implement AWS Control Tower to manage this environment. The architect needs to initialize the landing zone, prepare the account hierarchy, configure custom guardrails, and onboard an existing standalone AWS account into the environment. Arrange the following steps in the correct chronological sequence to implement this architecture while ensuring no account is left temporarily un-governed.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is establishing a secure, automated multi-account landing zone using AWS Organizations and AWS Control Tower. The solutions architect needs to design a governance structure that automatically deploys custom Service Control Policies (SCPs) and baseline resources to all new accounts, while securing federated access for developers.
Arrange the following steps in the correct chronological sequence to implement this governance architecture from scratch according to AWS best practices.
Öğeleri doğru sıraya koymak için sürükleyin
A solutions architect is establishing a multi-account governance structure using AWS Organizations. The security architecture requires that corporate permission guardrails are active and applied to all member accounts immediately upon their inclusion in the organization, preventing any temporary window of non-compliance. What is the correct sequence of steps to configure this organizational structure?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is planning to establish a secure multi-account structure using AWS Organizations. The solutions architect needs to set up a new organizational structure with Service Control Policies (SCPs) to restrict unauthorized services before any member accounts begin deploying workloads. Arrange the steps in the correct order to implement this multi-account governance structure safely.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is designing a secure multi-account AWS environment using AWS Organizations. The solutions architect needs to establish AWS Control Tower to govern the landing zone, apply baseline compliance controls, and deploy custom CloudFormation templates across all member accounts. Arrange the following steps in the correct chronological order to implement this multi-account governance solution.
Öğeleri doğru sıraya koymak için sürükleyin
A solutions architect is planning to implement standardized multi-account governance using AWS Control Tower for a new organization. Arrange the steps in the correct chronological order to establish and extend the landing zone.
Öğeleri doğru sıraya koymak için sürükleyin
An organization plans to establish a secure, multi-account AWS environment using AWS Control Tower. The solutions architect must prepare the account, launch the landing zone, establish centralized access, register organizational units, enroll new member accounts under governance, and deploy custom policies across the entire organization. Arrange the steps in the correct chronological order to implement this governance solution.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is designing a secure, multi-account governance strategy using AWS Organizations. The security team wants to delegate CloudTrail administration to a dedicated Security Tooling account. All member accounts must have their API activity logged to a centralized Amazon S3 bucket in the Security Tooling account, encrypted with an AWS KMS Customer Managed Key (CMK). The configuration must be enforced across the organization to prevent member accounts from modifying or bypassing the logging structure.
What is the correct sequence of steps to establish this centralized, secure organization trail using the principle of least privilege in the management account?
Öğeleri doğru sıraya koymak için sürükleyin
A solutions architect is tasked with restricting member accounts from performing unauthorized actions across a newly created AWS Organization. The architect decides to use Service Control Policies (SCPs) to enforce these boundaries. To implement this governance control, in what order should the steps be performed?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is establishing a multi-account governance framework using AWS Organizations. To comply with regulatory requirements, the solutions architect must enforce a Service Control Policy (SCP) that restricts resource provisioning to a subset of approved AWS Regions without disrupting essential global services or production workloads. Arrange the following steps in the correct order to design, test, and implement this governance control.
Öğeleri doğru sıraya koymak için sürükleyin
A solutions architect is designing a multi-account environment using AWS Organizations and AWS Control Tower for a large enterprise. The architecture must enforce custom guardrails, structure accounts into business-specific Organizational Units (OUs), and automatically deploy custom local network resources (such as VPCs and security groups) during account onboarding. The solutions architect decided to use AWS Control Tower Lifecycle Events linked to an Amazon EventBridge rule that triggers an AWS Lambda function for post-enrollment customization.
Arrange the steps in the correct chronological order to establish this governed environment and ensure all target accounts are automatically customized upon enrollment.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is establishing a multi-region landing zone using AWS Organizations and AWS Control Tower to govern a rapidly growing portfolio of application accounts. The solutions architect must establish a secure multi-account structure, centralize security operations, apply service control policies (SCPs), and configure automated account provisioning. In what sequence should the solutions architect perform these setup steps to establish the environment while maintaining operational security and ensuring all new accounts are compliant upon creation?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is planning to establish a secure multi-account landing zone. The solutions architect needs to migrate several legacy standalone AWS accounts into a new AWS Organizations structure and implement centralized governance. The goals are to enforce strict preventive guardrails, enable centralized security monitoring, and provide federated access. Arrange the following implementation steps in the correct logical sequence to achieve these goals with the minimum window of security vulnerability.
Öğeleri doğru sıraya koymak için sürükleyin
A company is implementing a multi-account governance framework using AWS Organizations and AWS Control Tower. The solutions architect needs to onboard an existing standalone AWS account that hosts a legacy production workload into the organization. The landing zone must apply the standard enterprise security baselines and detective guardrails without disrupting the legacy workload.
What is the correct sequence of steps to successfully onboard and govern this existing account using AWS Control Tower?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is integrating a newly acquired, standalone AWS account into its AWS Organizations structure managed by AWS Control Tower. The solutions architect must prepare the account for enrollment while preventing errors due to pre-existing resources and ensuring the environment conforms to the landing zone's centralized policies. Arrange the following steps in the correct chronological sequence to successfully onboard and baseline this account in AWS Control Tower.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is establishing a centralized logging architecture across its multi-account environment managed by AWS Organizations. The security team requires that all API activity across all current and future member accounts be logged to a central, read-only Amazon S3 bucket, and that member accounts be prevented from disabling or altering these logging configurations. Arrange the steps in the correct sequence to implement this centralized logging solution in accordance with AWS best practices.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is planning to establish a governed, multi-account AWS environment using AWS Organizations and AWS Control Tower. The strategy requires centralized logging, centralized security operations, environment segregation, and service control guardrails before workloads are deployed. Arrange the following steps in the correct chronological sequence to implement this multi-account governance strategy according to AWS best practices.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is establishing a new multi-account governance strategy using AWS Organizations. The security team requires that all API activity across all accounts is centrally logged to a secure Amazon S3 bucket in a dedicated Log Archive account, encrypted with a customer-managed KMS key, and protected against deletion or modification by any account administrator. What is the correct sequence of steps to configure this centralized logging and governance structure?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is setting up a new multi-account environment using AWS Organizations to support multiple development teams. The security team requires central auditing, compliance guardrails, and centralized network administration. Arrange the steps in the correct logical sequence to establish this governed multi-account structure.
Öğeleri doğru sıraya koymak için sürükleyin