The company wants to require Amazon EBS encryption at rest for existing production accounts and for any production accounts created in the future. They want a solution that includes built-in blueprints and guardrails. Which combination of steps will achieve this? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new AWS Control Tower landing zone in the organization’s management account, and create separate OUs for production and development, adding accounts to the correct OUs., Invite existing accounts into AWS Organizations and create Service Control Policies (SCPs) to enforce compliance., Create a guardrail scoped to the production OU to detect EBS encryption..
Why this is the answer
The correct options leverage AWS Control Tower for its built-in blueprints and guardrails, and AWS Organizations for centralized management. Creating a new AWS Control Tower landing zone in the organization’s management account (not a developer account) and organizing accounts into OUs (e.g., production and development) establishes a well-architected multi-account environment. Inviting existing accounts into AWS Organizations is necessary to manage them centrally. Creating a guardrail scoped to the production OU to detect EBS encryption ensures that EBS encryption at rest is enforced specifically for production accounts, aligning with the requirement for built-in blueprints and guardrails. AWS CloudFormation StackSets could deploy AWS Config rules, but Control Tower guardrails are a more integrated solution for this requirement. Creating a guardrail from the management account would apply broadly, not specifically to production.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed