Your organization manages multiple AWS accounts with AWS Organizations. The infrastructure team owns a dedicated infrastructure account that contains a VPC to serve as the common network. Individual accounts must not manage their own networks, but they must be able to create resources inside subnets provided by the shared network. Which combination of actions should you perform to meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable resource sharing from the AWS Organizations management account., In the infrastructure account, create a resource share in AWS Resource Access Manager (RAM). Select the specific AWS Organizations organizational unit (OU) that will use the shared network and choose each subnet to include in the resource share..
Why this is the answer
The correct combination involves enabling resource sharing and creating a RAM resource share. First, resource sharing must be enabled from the AWS Organizations management account to allow sharing resources like subnets across accounts in the organization. Second, in the infrastructure account, a resource share is created in AWS Resource Access Manager (RAM). This share specifies the subnets to be shared and targets the relevant AWS Organizations OU, granting member accounts within that OU permission to create resources in those shared subnets. Creating a Transit Gateway is not directly required for sharing subnets; it's used for connecting multiple VPCs. Creating VPCs in each member account and peering them with the infrastructure account VPC would violate the requirement that individual accounts must not manage their own networks. Sharing prefix lists via RAM is incorrect because the requirement is to share subnets, not prefix lists.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed