A company wants a multi-account AWS structure with centralized access and private-network traffic. MFA is required at login, and specific roles map to user groups. Separate accounts required: development, staging, production, and shared-network. Production and shared-network must have connectivity to all accounts. Development and staging must only have access to each other. Which combination of steps should a solutions architect take to meet these requirements? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy a landing zone environment by using AWS Control Tower. Enroll accounts and invite existing accounts into the resulting organization in AWS Organizations., Create transit gateways and transit gateway VPC attachments in each account. Configure appropriate route tables., Set up and enable AWS IAM Identity Center (AWS Single Sign-On). Create appropriate permission sets with required MFA for existing accounts..
Why this is the answer
AWS Control Tower establishes a multi-account landing zone, integrating AWS Organizations for account management and providing a foundational structure for the required environment. This addresses the need for a multi-account structure. AWS IAM Identity Center (AWS Single Sign-On) centralizes access management across accounts, allowing for the creation of permission sets mapped to user groups and enforcing MFA at login. Transit Gateways provide centralized network connectivity, enabling the required private-network traffic and specific connectivity patterns between production/shared-network and other accounts, and between development and staging. Incorrect options: Enabling AWS Security Hub is for security posture management, not for managing cross-account access or forcing MFA login via CloudTrail. Enabling Control Tower in all accounts to manage routing is incorrect; Control Tower manages the landing zone, and routing is handled by Transit Gateway. Creating IAM users/groups and Amazon Cognito pools directly in each account is less scalable and centralized than using IAM Identity Center for a multi-account setup.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed