QuestionQ11

Security and Compliance

A DevOps engineer must apply a core set of security controls to an existing collection of AWS accounts. The accounts belong to an organization in AWS Organizations. Individual teams will manage individual accounts by using the AdministratorAccess AWS managed policy. AWS CloudTrail and AWS Config must be enabled in every available AWS Region for all accounts. Individual account administrators must not be able to modify or delete any baseline resources. However, those administrators must be able to modify or delete their own CloudTrail trails and AWS Config rules.

Which solution meets these requirements in the MOST operationally efficient manner?

Explanation

AWS Control Tower can enroll existing accounts and centrally apply a governed landing-zone baseline. Its preventive controls protect AWS Control Tower-managed AWS Config resources and AWS Config rules, while the protections are scoped to the Control Tower-managed baseline so account administrators can still manage their own CloudTrail trails and AWS Config rules. This avoids maintaining custom StackSets and SCP exception logic across all accounts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!