A company needs a multi-account AWS environment that enforces a consistent baseline for management and security while allowing account-level flexibility for different compliance needs. The environment must integrate with the existing on-premises AD FS for federation and minimize operational overhead. Which approach meets these requirements with the LEAST operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AWS Organization. Enable AWS Control Tower for the organization. Review included controls (guardrails) and SCPs, and adjust AWS Config where needed. Add Organizational Units as necessary. Integrate AWS IAM Identity Center (AWS Single Sign-On) with the on-premises AD FS server..
Why this is the answer
The correct answer leverages AWS Control Tower, which automates the setup of a multi-account AWS environment with best practices, including pre-configured SCPs (guardrails), a well-architected OU structure, and centralized logging, significantly reducing operational overhead. Integrating AWS IAM Identity Center (AWS Single Sign-On) with on-premises AD FS provides seamless federation. The other options involve more manual configuration of SCPs, OUs, logging, and identity providers, increasing operational overhead. Specifically, using a single SCP for all accounts (option 1) lacks the flexibility needed for different compliance needs. Manually configuring SCPs and logging (option 3) is more complex than Control Tower's automated approach. Using an IAM identity provider instead of IAM Identity Center (option 4) for federation is less integrated and scalable in an AWS Organization context.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed