All accounts in an organization have AWS Config configured manually. The company wants a centralized configuration so AWS Config is set up for all organization accounts and resource changes are recorded to a central account. Which actions should you take? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Configure a delegated administrator account for AWS Config. Enable trusted access for AWS Config in the organization., Create an AWS Config organization aggregator in the delegated administrator account. Configure data collection from all AWS accounts in the organization and from all AWS Regions..
Why this is the answer
To centralize AWS Config across an organization, you first need to enable trusted access for AWS Config with AWS Organizations. This allows AWS Config to manage resources across accounts. Then, you designate a delegated administrator account. This account will manage AWS Config for the entire organization, including creating aggregators. Finally, you create an AWS Config organization aggregator within this delegated administrator account. This aggregator collects configuration data from all specified accounts and Regions, providing the desired centralized view. Incorrect options: Creating a service-linked role in the management account is not the primary step for centralizing Config; the delegated administrator and aggregator are key. While CloudFormation can automate deployments, an organization aggregator is a native AWS Config feature designed for this purpose and is more direct. Creating the aggregator in the management account is not ideal once a delegated administrator is established, as the delegated administrator should manage organizational Config settings.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed