SAP-C02 · Question #336
A company is migrating its infrastructure to the AW5 Cloud. The company must comply with a variety of regulatory standards for different projects. The company needs a multi-account environment. A…
The correct answer is B. Create an organization In AWS Organizations. To prepare a multi-account baseline with consistent security, flexible compliance, and AD FS integration with least operational overhead, the company should create an AWS Organization, use OUs and SCPs, and configure AWS IAM Identity Center.
Question
A company is migrating its infrastructure to the AW5 Cloud. The company must comply with a variety of regulatory standards for different projects. The company needs a multi-account environment. A solutions architect needs to prepare the baseline infrastructure The solution must provide a consistent baseline of management and security but it must allow flexibility for different compliance requirements within various AWS accounts. The solution also needs to integrate with the existing on-premises Active Directory Federation Services (AD FS) server. Which solution meets these requirements with the LEAST amount of operational overhead?
Options
- ACreate an organization In AWS Organizations.
- BCreate an organization In AWS Organizations.
- CCreate an organization in AWS Organizations.
- DCreate an organization in AWS Organizations.
How the community answered
(44 responses)- A23% (10)
- B57% (25)
- C14% (6)
- D7% (3)
Why each option
To prepare a multi-account baseline with consistent security, flexible compliance, and AD FS integration with least operational overhead, the company should create an AWS Organization, use OUs and SCPs, and configure AWS IAM Identity Center.
While creating an AWS Organization is the first step, this option, being truncated, doesn't describe the full solution including OUs, SCPs, and AD FS integration required to meet all the specified requirements.
Creating an AWS Organization is foundational for a multi-account strategy, and combining it with Organizational Units, Service Control Policies (SCPs), and AWS IAM Identity Center (for AD FS integration) provides the desired baseline, flexibility, and centralized access management with minimal operational overhead.
Similar to A, this truncated option does not provide the complete solution involving OUs, SCPs, and AD FS integration, which are crucial for meeting compliance flexibility and identity requirements.
Similar to A and C, this truncated option lacks the necessary details regarding OUs, SCPs, and AD FS integration via AWS IAM Identity Center to fully address the complex requirements.
Concept tested: AWS Organizations, SCPs, IAM Identity Center, AD FS integration
Source: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_introduction.html
Community Discussion
No community discussion yet for this question.