Your organization manages multiple AWS accounts with AWS Organizations and currently creates IAM roles manually. You want an automated, scalable way to create and manage IAM roles across the accounts. What is the MOST operationally efficient solution?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS CloudFormation StackSets with AWS Organizations to deploy and manage IAM roles across the accounts..
Why this is the answer
AWS CloudFormation StackSets allow you to deploy and manage CloudFormation stacks across multiple AWS accounts and Regions from a single CloudFormation template. This is the most operationally efficient solution because it automates the creation and management of IAM roles across all accounts within your AWS Organizations structure from a central point, ensuring consistency and reducing manual effort. Creating reusable CloudFormation templates and running them in each account manually is less efficient as it still requires individual execution per account. Integrating AWS Directory Service with AWS Organizations is for identity management and user authentication, not for provisioning IAM roles themselves. AWS Resource Access Manager (RAM) is used for sharing resources like subnets or transit gateways, not for deploying and managing IAM roles.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed