An organization uses AWS Organizations in a single Region. The management account is management-01. AWS Config is enabled in all accounts, and security-01 is the delegated administrator for AWS Config. All accounts report compliance status to the delegated administrator account through an AWS Config aggregator. Account administrators can manage their own AWS Config rules. A security engineer must automatically deploy a standard set of 10 AWS Config rules to all current and future accounts in the organization and ensure AWS Config is enabled automatically for new accounts. Which combination of steps will meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a conformance pack that includes the 10 AWS Config rules. Deploy the conformance pack from the security-01 account., Create an AWS CloudFormation template that enables AWS Config. Deploy it with CloudFormation StackSets from the management-01 account..
Why this is the answer
To deploy a standard set of 10 AWS Config rules across all current and future accounts, a conformance pack is the most efficient solution. Conformance packs allow you to package a collection of AWS Config rules and remediation actions into a single entity, which can then be deployed to multiple accounts and Regions. Deploying it from the security-01 account is appropriate because it is the delegated administrator for AWS Config, giving it the necessary permissions. To ensure AWS Config is enabled automatically for new accounts, CloudFormation StackSets deployed from the management account (management-01) are ideal. The management account has the permissions to deploy resources across all accounts in the organization, including new ones. A CloudFormation template can define the necessary resources to enable AWS Config. Creating an AWS CloudFormation template for the 10 Config rules and deploying it with StackSets is less efficient than a conformance pack, as conformance packs are specifically designed for managing collections of Config rules. Deploying the conformance pack from the management account is not necessary, as the delegated administrator account (security-01) has the required permissions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed