FinServe Bank operates 200 AWS accounts in AWS Organizations across multiple OUs. The CISO wants to enforce a consistent compliance baseline with automatic remediation for common findings (for example, unencrypted EBS volumes) and to view organization-wide compliance in one place. What is the MOST efficient approach?
Choose an answer
Tap an option to check your answer.
Correct answer: From the AWS Config delegated administrator account, deploy an organization conformance pack to targeted OUs with SSM Automation remediation, and create an AWS Config aggregator for org-wide visibility..
Why this is the answer
Deploying an organization conformance pack from a delegated administrator account is the most efficient solution because it allows for centralized, consistent deployment of AWS Config rules and remediation actions (via SSM Automation) across multiple accounts and OUs, addressing the need for a compliance baseline and automatic remediation. An AWS Config aggregator then provides the desired organization-wide compliance view. AWS Control Tower is for new account provisioning and governance, not primarily for retrofitting compliance across existing, complex organizational structures. AWS Security Hub focuses on aggregating security findings, not directly on deploying and enforcing compliance rules with automatic remediation. CloudFormation StackSets would require manual deployment of individual rules, which is less efficient and scalable than a conformance pack for a large number of accounts and rules.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed