DOP-C02 · Question #407
A company is implementing a standardized security baseline across its AWS accounts. The accounts are in an organization in AWS Organizations. The company must deploy consistent IAM roles and…
The correct answer is B. Activate trusted access for AWS CloudFormation StackSets in Organizations. In the management. By activating trusted access for AWS CloudFormation StackSets in AWS Organizations and using a service-managed StackSet with automatic deployment, you can centrally define your IAM roles and policies once in the management account and have them propagated to all current and…
Question
A company is implementing a standardized security baseline across its AWS accounts. The accounts are in an organization in AWS Organizations. The company must deploy consistent IAM roles and policies across all existing and future accounts in the organization. Which solution will meet these requirements with the MOST operational efficiency?
Options
- AEnable AWS Control Tower in the management account. Configure AWS Control Tower Account
- BActivate trusted access for AWS CloudFormation StackSets in Organizations. In the management
- CIn each member account, create IAM roles that have permissions to create and manage
- DIn the management account, create an AWS CodePipeline pipeline. Configure the pipeline to use
How the community answered
(40 responses)- A15% (6)
- B50% (20)
- C28% (11)
- D8% (3)
Explanation
By activating trusted access for AWS CloudFormation StackSets in AWS Organizations and using a service-managed StackSet with automatic deployment, you can centrally define your IAM roles and policies once in the management account and have them propagated to all current and future member accounts without having to manage cross-account roles or pipelines. This delivers the most operationally efficient, turnkey solution.
Topics
Community Discussion
No community discussion yet for this question.