nerdexam
Amazon

SAA-C03 · Question #311

A company uses AWS Organizations to manage multiple AWS accounts. Each department in the company has its own AWS account. A security team needs to implement centralized governance and control to enfor

The correct answer is B. Use AWS Control Tower to establish a multi-account environment. Use service control policies. AWS Control Tower provides a straightforward way to set up and govern a secure, multi-account AWS environment based on AWS best practices. It automates the setup of a baseline environment, or landing zone, that includes: Service Control Policies (SCPs): These are used to manage p

Submitted by layla.eg· Mar 4, 2026Design Secure Architectures

Question

A company uses AWS Organizations to manage multiple AWS accounts. Each department in the company has its own AWS account. A security team needs to implement centralized governance and control to enforce security best practices across all accounts. The team wants to have control over which AWS services each account can use. The team needs to restrict access to sensitive resources based on IP addresses or geographic regions. The root user must be protected with multi-factor authentication (MFA) across all accounts. Which solution will meet these requirements?

Options

  • AUse AWS Identity and Access Management (IAM) to manage IAM users and IAM roles in each
  • BUse AWS Control Tower to establish a multi-account environment. Use service control policies
  • CUse AWS Systems Manager to enforce service restrictions across multiple accounts. Use IAM
  • DUse AWS IAM Identity Center to manage user access and to enforce service restrictions by using

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    62% (26)
  • C
    21% (9)
  • D
    12% (5)

Explanation

AWS Control Tower provides a straightforward way to set up and govern a secure, multi-account AWS environment based on AWS best practices. It automates the setup of a baseline environment, or landing zone, that includes: Service Control Policies (SCPs): These are used to manage permissions across AWS Organizations, allowing you to set permission guardrails. SCPs can restrict access to specific AWS services and actions, helping enforce security best practices. Multi-Factor Authentication (MFA): AWS Control Tower can enforce MFA for the root user across all accounts, enhancing security. Centralized Governance: It offers centralized logging and monitoring, making it easier to manage and audit multiple AWS accounts.

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice