A company uses AWS Control Tower with AWS Organizations and wants to restrict development accounts (organized in a specific OU) so that they can only launch burstable EC2 and RDS instance types and cannot use unrelated services. Developers have many individual development accounts. Which approach should a solutions architect recommend to enforce these restrictions?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a custom preventive control (guardrail) in AWS Control Tower that allows only burstable instance types and denies unrelated services. Apply the preventive control to the development OU..
Why this is the answer
The correct answer is to create a custom preventive control (guardrail) in AWS Control Tower. Preventive controls, implemented as Service Control Policies (SCPs) under the hood, proactively prevent actions that violate policies. By applying this preventive control to the development OU, it will restrict all accounts within that OU from launching non-burstable EC2/RDS instances and using unrelated services, ensuring compliance before resources are provisioned. Creating a custom SCP directly is less integrated with Control Tower's guardrail management. A custom detective control would only alert after a non-compliant resource is launched, not prevent it. An AWS Config rule is also a detective control, checking for compliance after deployment, and deploying it via CloudFormation StackSets adds unnecessary complexity compared to Control Tower's native guardrail functionality.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed