An organization in AWS Organizations uses all-features and a hierarchy of OUs under the root. All OUs and accounts have been registered and enrolled in AWS Control Tower. The company must apply custom changes to the AWS Config configuration recorder in every current account and ensure the same customizations are applied automatically to any accounts enrolled into Control Tower in the future. Which set of steps meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new AWS account. In that account, create an AWS Lambda function that applies the AWS Config configuration-recorder customizations across each account in the organization., Create an IAM role in the AWS Control Tower management account that an AWS Lambda function will assume. Grant that role permission to assume the AWSControlTowerExecution role in any account in the organization. Configure the Lambda function to run using this new IAM role., In the AWS Control Tower management account, configure an Amazon EventBridge rule to invoke an AWS Lambda function when an AWS account is updated or enrolled in AWS Control Tower or when the landing zone is updated. Then re-register each Organizations OU..
Why this is the answer
The correct options involve using a centralized Lambda function to apply customizations. The first correct option describes creating a new account with a Lambda function that applies the customizations across all accounts. This is a valid approach for centralized management. The second correct option describes creating an IAM role in the Control Tower management account that a Lambda function can assume. This role is granted permissions to assume the AWSControlTowerExecution role in other accounts, allowing the Lambda function to perform actions across the organization. This is a secure and scalable way to manage cross-account access. The third correct option describes using an EventBridge rule in the Control Tower management account to trigger a Lambda function when accounts are enrolled or updated. This ensures that new accounts automatically receive the customizations. Re-registering OUs or updating the landing zone can also trigger this for existing accounts. The incorrect options are flawed because: Making an account an AWS Config delegated administrator only centralizes Config data, not the ability to customize recorders across accounts. Configuring AWSControlTowerExecution directly in each account for a Lambda function is not a scalable or centralized approach.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed