Tüm alıştırma soruları
27 soru
A financial services company manages its multi-account environment using AWS Organizations. The security team mandates that all Amazon EBS volumes across all member accounts must be backed up daily, and the backups must be stored in a central vault. The company wants to delegate the administration of these backup policies to a dedicated backup-admin account, minimizing the use of the Organizations management account.
Arrange the correct sequence of steps to configure this centralized backup governance model across the organization.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is designing a secure multi-account governance strategy using AWS Organizations. The security team wants to establish a secure, managed landing zone with automated account provisioning, centralized logging, and strict service control policies (SCPs) to prevent member accounts from disabling security monitoring. Arrange the following steps in the correct sequence to configure and secure this multi-account environment, ensuring that guardrails are active before member accounts begin deploying workloads.
Öğeleri doğru sıraya koymak için sürükleyin
A financial services corporation is establishing a multi-account compliance auditing architecture using AWS Organizations. The solutions architect needs to configure AWS Config at the organization level to automatically record resource configurations and evaluate compliance using custom rules. The architect decides to delegate administrative capabilities to a dedicated Security tooling account instead of using the Organizations management account for daily compliance management. Arrange the following steps in the correct logical sequence to successfully configure this delegated compliance monitoring setup.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is establishing centralized security monitoring across its multi-account environment using AWS Organizations. A solutions architect needs to configure Amazon GuardDuty so that all security alerts are consolidated into a dedicated Security Tooling member account. The solution must ensure that member accounts cannot disable GuardDuty or modify its configurations, while allowing the Security Tooling account to manage the service.
Arrange the following steps in the correct chronological sequence to implement this governance and security architecture.
Öğeleri doğru sıraya koymak için sürükleyin
A solutions architect is establishing a governed multi-account environment for an enterprise using AWS Control Tower. The architect needs to initialize the landing zone, enforce corporate compliance guardrails, and onboard the first set of application team accounts. Arrange the steps to design and implement this multi-account governance structure in the correct chronological sequence.
Öğeleri doğru sıraya koymak için sürükleyin
A Solutions Architect needs to set up centralized security monitoring across all AWS accounts in an organization using AWS Organizations. The architect wants to delegate security administration to a dedicated Security Tooling account and implement standardized security controls across different Organizational Units (OUs) using AWS Security Hub.
Arrange the steps in the correct order to configure AWS Security Hub with delegated administration and centralized configuration management.
Öğeleri doğru sıraya koymak için sürükleyin
A solutions architect is implementing region-restriction Service Control Policies (SCPs) across an organization in AWS Organizations. The architect needs to ensure that the restrictions do not disrupt existing applications or logging workflows, and that they are applied safely.
Arrange the steps in the correct order to design, test, and safely deploy the SCPs.
Öğeleri doğru sıraya koymak için sürükleyin