Courseiva

CCNA Org Complexity Questions

75 of 200 questions · Page 1/3 · Org Complexity topic · Answers revealed

1
MCQeasy

Refer to the exhibit. A company runs the AWS CLI command to list accounts in AWS Organizations. The company wants to remove the account '444444444444' from the organization. What must the company do first before it can remove this account?

A.Close the AWS account from the management account.
B.Create a support ticket to AWS to remove the account.
C.Remove the account's payment method.
D.The management account can directly remove the account without any prerequisites.
AnswerA

Correct. Closing the AWS account from the management account is the prerequisite for removing a member account that was created within the organization.

Why this answer

To remove a member account that was created within AWS Organizations, the management account must first close the account. This is a prerequisite because accounts created via Organizations cannot be removed directly; only invited accounts can be removed without closing. Closing the account suspends it; after closure, the management account can then remove it from the organization.

The account remains closed and is not converted into an active standalone account.

Exam trap

The trap is that candidates might think removing the payment method (Option C) is sufficient, but AWS requires the account to be closed when it was created within the organization. Also, some may assume the management account can remove it directly (Option D), which only applies to invited accounts.

How to eliminate wrong answers

Option A is wrong because closing the AWS account from the management account is not a prerequisite for removal; closing an account is a separate action that permanently terminates the account, whereas removal from the organization simply detaches it. Option B is wrong because AWS does not require a support ticket to remove an account from an organization; the management account can remove accounts programmatically via the AWS Organizations API or CLI without contacting support. Option D is wrong because the management account cannot directly remove an account without prerequisites; the account must have its payment method removed first, as per AWS Organizations requirements.

2
MCQeasy

A company wants to centralize management of IAM users and groups across multiple AWS accounts. The solution should allow users to access resources in any account without needing separate credentials. Which AWS service should be used?

A.AWS Identity and Access Management (IAM)
B.AWS Organizations
C.AWS IAM Identity Center (AWS SSO)
D.AWS Directory Service for Microsoft Active Directory
AnswerC

IAM Identity Center provides a single directory-backed sign-in and issues temporary credentials per account through permission sets, so users reach resources in any account without separate IAM users. This satisfies the constraint of centralised identity with no per-account credentials.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized identity source that allows users to sign in once with a single set of credentials and then access multiple AWS accounts and applications. It integrates with AWS Organizations to manage user and group permissions across accounts, eliminating the need for separate IAM users in each account.

Exam trap

The trap here is that candidates often confuse AWS Organizations with a user management service, but Organizations only manages accounts and policies, not user identities or authentication.

How to eliminate wrong answers

Option A is wrong because IAM is account-scoped and cannot centralize user management across multiple AWS accounts; it requires creating separate IAM users in each account, which defeats the goal of single sign-on. Option B is wrong because AWS Organizations provides policy-based management and consolidated billing but does not itself offer a user directory or authentication mechanism; it relies on IAM Identity Center or other identity providers for user access. Option D is wrong because AWS Directory Service for Microsoft Active Directory is a managed AD service that can be used as an identity source, but it is not the AWS-native service for centralizing IAM user and group management across accounts; IAM Identity Center is the recommended service for this purpose.

3
MCQmedium

A company has a multi-account AWS environment with a central security account. They want to enable Amazon GuardDuty in all accounts and centrally view findings. The security team has already enabled GuardDuty in the security account and invited all member accounts. However, the security account is not receiving findings from all member accounts. Upon investigation, some member accounts show that GuardDuty is not enabled, and some show that they have not accepted the invitation. The team needs a scalable solution to enable GuardDuty across all accounts and ensure findings are sent to the security account. What should the team do?

A.Use AWS Config rules to detect accounts without GuardDuty and send alerts.
B.Use AWS CloudFormation StackSets to deploy GuardDuty resources in each account.
C.Use AWS Control Tower to enable GuardDuty in all accounts via a custom blueprint.
D.Use the GuardDuty delegated administrator feature with AWS Organizations to automatically enable GuardDuty in all accounts and centralize findings.
AnswerD

The delegated administrator integrates GuardDuty with AWS Organizations, automatically enabling the service in every member account and routing findings to the security account. This replaces the manual invite-and-accept model that left some accounts unenrolled, satisfying the scalable centralised-findings requirement.

Why this answer

The GuardDuty delegated administrator feature integrated with AWS Organizations allows the security account to be designated as the GuardDuty administrator, which can then automatically enable GuardDuty for all existing and future member accounts in the organization. This eliminates the need for manual invitations and acceptances, ensuring that findings are centrally aggregated in the security account without requiring per-account configuration.

Exam trap

The trap here is that candidates may choose CloudFormation StackSets (Option B) thinking it can deploy GuardDuty resources across accounts, but they overlook that StackSets cannot automatically accept GuardDuty invitations or leverage the Organizations delegated administrator model to bypass the manual acceptance step.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect noncompliant resources and trigger alerts or remediation actions, but they cannot automatically enable GuardDuty across accounts or manage the invitation/acceptance workflow required for centralized findings. Option B is wrong because CloudFormation StackSets can deploy resources across accounts, but they require the member accounts to already have accepted the GuardDuty invitation or be part of the same organization; they do not automate the invitation acceptance process or leverage the delegated administrator model to bypass manual steps. Option C is wrong because AWS Control Tower custom blueprints are used to deploy additional governance controls or resources, but they do not natively support the GuardDuty delegated administrator feature; enabling GuardDuty across all accounts in Control Tower is better achieved through Organizations integration, not a custom blueprint.

4
Drag & Dropmedium

Drag and drop the steps to set up AWS CloudTrail for logging API activity in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create the S3 bucket, then create the trail, configure events, enable security features, and verify delivery.

5
Multi-Selecthard

A company uses AWS Organizations with a dedicated security account. They want to centralize the management of AWS Config rules and ensure that all accounts are compliant with the same set of rules. Which THREE steps should they take?

Select 3 answers
A.Apply a service control policy (SCP) that requires AWS Config to be enabled.
B.Create an AWS Config aggregator in the security account to view compliance status across accounts.
C.Use AWS CloudFormation StackSets to deploy the desired AWS Config rules to all accounts.
D.Enable AWS Config in all accounts across the organization.
E.Use AWS CloudTrail to monitor compliance status.
AnswersB, C, D

An aggregator in the security account collects configuration and compliance data from all member accounts, giving centralised visibility across the organization. It satisfies the requirement to view compliance status centrally, though it does not itself deploy rules. Aggregators are read-only; rule deployment needs Organizations-level Config conformance packs or delegated administrator.

Why this answer

Option B is correct because an AWS Config aggregator in the security account collects configuration and compliance data from multiple accounts and Regions, giving a centralized view of compliance status across the organization. Option C is correct because CloudFormation StackSets deploy the same AWS Config rules (and related resources) consistently to all target accounts and Regions in the organization. Option D is correct because AWS Config must be enabled in each account and Region before rules can evaluate resources and report compliance there.

Option A is not correct because an SCP can restrict or require actions but does not itself enable AWS Config or enforce rule compliance. Option E is not correct because AWS CloudTrail records API activity and does not evaluate resource configuration compliance against Config rules.

Exam trap

The trap here is confusing service control policies (SCPs) with service enablement; SCPs restrict permissions but cannot automatically enable AWS Config, leading candidates to incorrectly select option A as a way to enforce compliance.

6
MCQhard

Refer to the exhibit. An SCP is attached to an OU. A developer in an account under this OU tries to launch a t3.large EC2 instance. What will happen?

A.The instance launch is allowed because the condition uses StringNotEquals, which is not evaluated correctly.
B.The instance launch is denied because the SCP denies any instance type not in the allowed list.
C.The instance launch is denied, but only if the account's IAM policy also denies it.
D.The instance launch is allowed because the SCP has an explicit deny, but it only applies to certain instance types.
AnswerB

SCPs define a permissions boundary that filters every API action in member accounts, and a Deny statement overrides any IAM allow. Because t3.large is absent from the allowed instance-type list, the ec2:RunInstances call fails authorisation, so the launch is blocked.

Why this answer

The SCP explicitly denies any EC2 instance launch where the instance type does not match the allowed list using `StringNotEquals`. Since `t3.large` is not in the allowed list (`t2.micro`, `t2.small`, `t2.medium`), the condition evaluates to true, triggering the explicit deny. SCPs act as a guardrail that overrides any IAM permissions, so the launch is denied regardless of the account's IAM policies.

Exam trap

The trap here is that candidates may think `StringNotEquals` is a misconfiguration or that SCPs only apply if the IAM policy also denies, but in reality, an explicit deny in an SCP is absolute and cannot be bypassed by IAM allows.

How to eliminate wrong answers

Option A is wrong because `StringNotEquals` is evaluated correctly by AWS; it denies actions when the specified value does not match the allowed list, not the other way around. Option C is wrong because SCPs are evaluated before IAM policies and can deny actions even if the IAM policy allows them; an explicit deny in an SCP cannot be overridden by an IAM allow. Option D is wrong because the SCP's explicit deny applies to all instance types not in the allowed list, and `t3.large` is not in that list, so the deny is triggered.

7
MCQmedium

A financial services company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that member accounts cannot modify or delete these roles, and that new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS CloudFormation StackSets with service-managed permissions to deploy IAM roles to all accounts in the organization, and enable automatic deployment to new accounts.
B.Use AWS Organizations service control policies (SCPs) to deny all IAM actions in member accounts except for a specific role, and manually create that role in each account.
C.Implement a custom AWS Lambda function that assumes a role in each member account and creates the necessary IAM roles, triggered by an Amazon EventBridge rule for new account creation.
D.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share the role with all member accounts.
AnswerA

AWS CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to deploy IAM roles across all accounts automatically. By enabling automatic deployments, new accounts receive the roles upon creation. Member accounts cannot modify or delete the StackSet-managed roles because the StackSet retains control, and updates are centralized. This approach minimizes operational overhead by eliminating manual role creation and ensuring consistency across the organization.

Why this answer

AWS CloudFormation StackSets with service-managed permissions is designed for centralized deployment across AWS Organizations. It automatically deploys to new accounts when configured, and the StackSet maintains control, preventing member accounts from altering the deployed IAM roles. This reduces operational overhead and ensures consistent cross-account access.

Other options either do not provide automatic provisioning or lack the necessary control to prevent modifications.

Exam trap

The trap here is assuming that AWS Resource Access Manager (RAM) can share IAM roles, or that SCPs can create roles, when in fact RAM does not support IAM roles and SCPs only set permission boundaries.

8
MCQeasy

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users are created in member accounts. All access must be through federated roles. Which approach should they use?

A.Apply an SCP to the root OU that denies the iam:CreateUser action.
B.Set an IAM password policy in each account that requires strong passwords.
C.Use AWS Config rules to detect IAM users and automatically delete them.
D.Use AWS CloudTrail to monitor for CreateUser and alert the security team.
AnswerA

An SCP attached at the root OU is inherited by every member account and denies iam:CreateUser at the API level, regardless of identity-based policies. This enforces federated-only access across the organisation, satisfying the requirement that no IAM users exist in member accounts.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow the security team to centrally restrict permissions across all member accounts. By applying an SCP to the root organizational unit (OU) that denies the `iam:CreateUser` action, no IAM users can be created in any member account, ensuring all access must come from federated roles. SCPs are evaluated before IAM policies and cannot be overridden by account administrators, making them the most effective preventive control.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config or CloudTrail) with preventive controls (like SCPs), assuming that monitoring or alerting can effectively enforce a policy, whereas only SCPs can proactively block the action across all accounts in an organization.

How to eliminate wrong answers

Option B is wrong because setting an IAM password policy does not prevent the creation of IAM users; it only enforces password complexity requirements for existing users, so it fails to meet the goal of blocking user creation entirely. Option C is wrong because AWS Config rules are detective, not preventive; they can detect IAM users after creation but cannot automatically delete them without custom remediation actions, and even then, there is a window where users exist. Option D is wrong because AWS CloudTrail monitoring is also detective; it can alert on `CreateUser` events but does not prevent the action from occurring, so users could still be created before the security team responds.

9
MCQhard

A healthcare company has a multi-account AWS environment with a central audit account. Compliance requires that all access to Amazon S3 buckets containing protected health information be logged and that logs be immutable for seven years. The company wants to centralize log storage and prevent any account, including the management account, from deleting or modifying the logs. Which combination of steps should a solutions architect take?

A.Enable AWS CloudTrail data events for S3 in all accounts, deliver logs to a central S3 bucket in the audit account, and enable S3 Object Lock in compliance mode on that bucket with a seven-year retention period.
B.Use AWS Config to record S3 bucket changes, store the configuration history in the audit account, and enable S3 Object Lock in governance mode for seven years.
C.Enable AWS CloudTrail management events only, deliver logs to a central S3 bucket, and configure a bucket policy that denies s3:DeleteObject for all principals.
D.Enable S3 server access logging on each bucket, deliver the logs to a central bucket, and use an S3 Lifecycle policy to transition logs to S3 Glacier Deep Archive after 90 days.
AnswerA

CloudTrail data events capture object-level S3 access, and delivering them to a central bucket in the audit account meets the centralized logging requirement. S3 Object Lock in compliance mode prevents any user, including the root user and the management account, from deleting or altering objects for the retention period, satisfying the seven-year immutability requirement.

Why this answer

CloudTrail data events capture object-level S3 operations, and delivering them to a central audit account bucket centralizes storage. S3 Object Lock in compliance mode enforces a write-once-read-many model that no principal, including the management account root user, can override during the retention period, which meets the seven-year immutability requirement.

Exam trap

The trap here is confusing CloudTrail management events with data events, or assuming a bucket policy or governance mode provides the same immutability as compliance mode Object Lock.

10
Multi-Selectmedium

A company wants to implement a cost allocation strategy using tags across multiple accounts in AWS Organizations. Which TWO practices should be followed?

Select 2 answers
A.Define a standardized set of tags (e.g., CostCenter, Owner, Project) and enforce them using AWS Config rules.
B.Enable AWS-generated tags automatically for all resources.
C.Use service control policies (SCPs) to require tags on all resources.
D.Apply tags only at the resource creation time; they cannot be added later.
E.Use AWS Cost Explorer to filter costs by tags across accounts.
AnswersA, E

A standardised tag schema applied consistently across all accounts is the prerequisite for any tag-based allocation; AWS Config rules enforce compliance so untagged or mis-tagged resources are detected. Without this governance, Cost Explorer grouping produces incomplete, unreliable cost attribution across the organisation.

Why this answer

Option A is correct because a cost allocation strategy requires a consistent, standardized tagging schema (such as CostCenter, Owner, and Project) so that costs can be grouped reliably, and AWS Config rules (e.g., required-tags managed rules) can detect and flag non-compliant resources to enforce that schema across accounts. Option E is correct because AWS Cost Explorer can filter and group costs by activated cost allocation tags, and when combined with AWS Organizations it provides cross-account visibility into tagged spend, which is essential for allocating costs across multiple accounts. Option B is wrong because AWS-generated tags are limited to specific service-created metadata and cannot substitute for a deliberate, standardized cost allocation tagging scheme.

Option C is wrong because SCPs control which API actions and services principals may use; they cannot require that a resource carry specific tag keys or values. Option D is wrong because tags can be added, modified, or removed at any time after resource creation, not only at creation time.

Exam trap

The trap here is confusing service control policies (SCPs) with tag enforcement mechanisms; SCPs control permissions, not resource configurations, so candidates often incorrectly select SCPs for tagging requirements instead of AWS Config rules or tag policies.

11
MCQmedium

A financial services company has an AWS Organizations structure with production and development OUs. The security team wants to prevent any IAM principal in the development OU from disabling AWS CloudTrail logging, even if an account administrator attempts it. They need a solution that applies automatically to all existing and future accounts in the development OU. What should they do?

A.Attach an IAM policy to each account's administrator role that denies CloudTrail stop and delete actions, and use AWS CloudFormation StackSets to deploy it.
B.Create an SCP that denies the cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail actions, and attach it to the development OU.
C.Enable AWS CloudTrail organization trail in the management account and configure S3 bucket policies to deny trail modifications.
D.Use AWS Config rules in each account to detect when CloudTrail is disabled and trigger an AWS Lambda function to re-enable it.
AnswerB

SCPs attached to an OU apply to all member accounts, including future ones, and restrict the maximum permissions for all principals in those accounts. Denying StopLogging, DeleteTrail, and UpdateTrail prevents any IAM principal, including account administrators, from disabling or altering CloudTrail, satisfying the requirement without per-account changes.

Why this answer

Service control policies (SCPs) are the only AWS Organizations mechanism that can enforce preventive guardrails across all accounts in an OU, including future accounts. By denying the specific CloudTrail actions that stop, delete, or modify a trail, the SCP ensures that even account administrators cannot disable logging. This meets the requirement for automatic, centralized enforcement without per-account configuration.

Exam trap

The trap here is assuming that an organization trail alone prevents disabling, when in fact it only centralizes logging and does not block account-level trail modifications.

12
MCQmedium

A company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to prevent any member account from disabling AWS CloudTrail or deleting the organization trail. They also want to ensure that only the management account can create new trails. Which solution meets these requirements with the least operational overhead?

A.Use AWS Organizations service control policies (SCPs) to deny cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:CreateTrail in all member accounts, while allowing these actions in the management account.
B.Use AWS CloudFormation StackSets to deploy a trail in each member account and set the trail to use an S3 bucket in the management account.
C.Create an IAM policy in each member account that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail, and attach it to all IAM roles.
D.Enable AWS Config in all member accounts with a managed rule that checks for CloudTrail logging and automatically remediates with a Lambda function.
AnswerA

SCPs applied at the organization or OU level centrally restrict actions in all member accounts, including the root user, and automatically apply to new accounts. Denying StopLogging and DeleteTrail protects the trail, and denying CreateTrail ensures only the management account can create trails, with minimal ongoing effort.

Why this answer

Service control policies in AWS Organizations provide centralized, preventive control over member accounts, including the root user, and automatically apply to new accounts. Denying StopLogging and DeleteTrail protects the organization trail, while denying CreateTrail ensures trail creation is limited to the management account, meeting the requirements with minimal operational effort.

Exam trap

The trap here is relying on detective controls such as AWS Config or per-account IAM policies, which do not prevent the action before it occurs and do not cover the account root user.

13
MCQhard

A global company uses AWS Organizations with many OUs and accounts. The finance team needs to track costs by cost center, which is tagged on each resource. However, some resources are not tagged. Which solution will provide the MOST accurate cost allocation?

A.Enable cost allocation tags and use AWS Cost Explorer to filter by tag.
B.Create AWS Budgets reports for each cost center using tag filters.
C.Export AWS Cost and Usage Reports to Amazon QuickSight and use tag-based filtering.
D.Use AWS Cost Categories to group costs by tag value and set a default rule for untagged resources.
AnswerD

Cost Categories group costs by tag value and support a default rule that captures untagged resources, so spend without the cost centre tag is still allocated rather than omitted. This directly addresses the stem's constraint that some resources lack tags, giving the most accurate allocation.

Why this answer

AWS Cost Categories allow you to group costs by tag values and, crucially, set a default rule for untagged resources. This ensures that all resources—tagged or not—are assigned to a cost center, providing the most accurate cost allocation across the entire organization. Other options only filter or report on tagged resources, leaving untagged costs unallocated.

Exam trap

The trap here is that candidates assume tag-based filtering or reporting tools (Cost Explorer, Budgets, QuickSight) can handle untagged resources, but they cannot—only Cost Categories with a default rule can allocate costs for untagged resources.

How to eliminate wrong answers

Option A is wrong because enabling cost allocation tags and using Cost Explorer to filter by tag only reports on resources that already have the tag; untagged resources are excluded, leading to incomplete cost allocation. Option B is wrong because AWS Budgets reports with tag filters also only apply to tagged resources; they do not handle untagged resources, so costs from untagged resources are not tracked by cost center. Option C is wrong because exporting CUR to QuickSight and using tag-based filtering still requires tags to be present on resources; untagged resources are not assigned to any cost center, resulting in inaccurate allocation.

14
Multi-Selectmedium

A company is designing a multi-account AWS Organizations architecture. Which TWO considerations should be taken into account when designing the organizational structure?

Select 2 answers
A.Accounts cannot be moved between OUs once created.
B.Each organizational unit (OU) should contain only one account for security isolation.
C.AWS CloudTrail can be configured to log management events across all accounts from the management account.
D.Service control policies (SCPs) can be used to centrally restrict permissions across accounts.
E.SCPs can only be applied to root accounts, not OUs.
AnswersC, D

CloudTrail organisation trails let the management account aggregate management events from every member account into one destination bucket, satisfying the centralised auditing constraint of a multi-account structure. This removes per-account trail configuration and preserves a single immutable log archive, which is essential when accounts are created and removed dynamically.

Why this answer

Option C is correct because AWS CloudTrail supports organization trails: when created in the management account (or a delegated administrator) with the organization setting enabled, it automatically logs management events for all member accounts and delivers them to a central S3 bucket. Option D is correct because service control policies (SCPs) are a core AWS Organizations feature that let you centrally set permission guardrails (allow lists or deny lists) that apply to all IAM principals in the accounts attached to the OU or root, restricting what member accounts can do. Option A is wrong because accounts can be moved between OUs at any time (though each account can belong to only one OU at a time).

Option B is wrong because OUs are meant to group multiple accounts with similar policy needs, and isolation is achieved through separate accounts and SCPs, not by limiting an OU to a single account. Option E is wrong because SCPs can be attached to the organization root, OUs, and individual member accounts — not only to root accounts.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking SCPs can only be applied to the root account, when in fact they can be attached to any OU or account within the organization.

15
MCQhard

A company uses AWS Organizations and wants to delegate administration of a specific service to a member account. The service must be able to perform actions across all accounts in the organization. Which steps should the company take?

A.Use AWS Organizations to register the member account as a delegated administrator for the service.
B.Create a service-linked role in each account to allow the service to perform actions.
C.Grant the member account IAM permissions to assume the OrganizationAccountAccessRole in all accounts.
D.Create an IAM role in each account with a trust policy that allows the service to assume it.
AnswerA

Registering a member account as a delegated administrator via AWS Organizations grants that account's service the permissions to operate across every account in the organization, satisfying the cross-account requirement without sharing root credentials or building custom IAM roles.

Why this answer

AWS Organizations allows you to designate a member account as a delegated administrator for a specific AWS service. Once registered, that account can perform administrative actions (e.g., creating resources, managing policies) across all accounts in the organization on behalf of that service, without needing individual IAM roles or permissions in each account.

Exam trap

The trap here is that candidates often confuse delegated administration with creating cross-account IAM roles or using the OrganizationAccountAccessRole, not realizing that AWS Organizations provides a native, centralized registration mechanism for service-level delegation.

How to eliminate wrong answers

Option B is wrong because service-linked roles are automatically created by AWS services for their own use, not for delegating administration to a member account; they do not grant cross-account administrative capabilities. Option C is wrong because the OrganizationAccountAccessRole is designed for human administrators to access member accounts via the AWS Management Console or API, not for a service to perform actions programmatically across all accounts. Option D is wrong because creating an IAM role in each account with a trust policy for the service would require manual setup and maintenance in every account, which is not the intended mechanism for delegated administration; AWS Organizations provides a centralized registration process instead.

16
MCQhard

A company has a multi-account AWS environment and uses AWS Organizations. The security team wants to automatically remediate non-compliant resources, such as S3 buckets that are publicly accessible. Which design should they implement?

A.Use Amazon Inspector to scan for public buckets.
B.Use an SCP to deny making buckets public.
C.Use AWS Config rules to detect public buckets and trigger an AWS Lambda function to make them private.
D.Use AWS CloudTrail to send alerts when a bucket becomes public.
AnswerC

AWS Config rules detect publicly accessible S3 buckets and can invoke an AWS Lambda function as a remediation action, automatically making them private. This provides continuous detection and automated response across all accounts in the organisation.

Why this answer

AWS Config rules can continuously evaluate S3 bucket configurations against a custom or managed rule (e.g., 's3-bucket-public-read-prohibited'). When a bucket is detected as publicly accessible, the rule can invoke an AWS Lambda function via an Amazon CloudWatch Events event to automatically apply a bucket policy that removes public access, achieving automated remediation.

Exam trap

The trap here is that candidates often confuse preventive controls (SCPs) with detective and corrective controls (AWS Config + Lambda), assuming SCPs can automatically fix existing non-compliant resources, when in reality SCPs only block future API actions and do not remediate current state.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is designed for vulnerability management and network accessibility assessments of EC2 instances, containers, and Lambda functions, not for scanning S3 bucket public access configurations. Option B is wrong because Service Control Policies (SCPs) can only deny or allow API actions at the account level (e.g., s3:PutBucketPolicy), but they cannot remediate already-public buckets; they prevent future changes but do not fix existing non-compliant resources. Option D is wrong because AWS CloudTrail logs API calls and can send alerts via CloudWatch alarms when a bucket becomes public, but it does not provide automated remediation; it only notifies, leaving the security team to manually fix the issue.

17
MCQmedium

Refer to the exhibit. An administrator runs this command and sees the output. Which statement about the accounts is correct?

A.The Suspended account was invited to the organization.
B.The Production account is the management account.
C.The Suspended account cannot be used until it is reactivated.
D.The Management account was created directly.
AnswerC

A suspended account is disabled at the directory level, so authentication attempts fail until an administrator reactivates it. This satisfies the stem's constraint that the account's current state determines usability: suspension blocks sign-in entirely, unlike a locked or expired-password state, which the user can often resolve themselves.

Why this answer

The command output shows the account status as 'SUSPENDED'. In AWS Organizations, a suspended account cannot be used for any AWS operations until it is reactivated by the management account. This is a hard state enforced by the service, regardless of how the account was added to the organization.

Exam trap

The trap here is that candidates often confuse account status (SUSPENDED) with the method of account creation (invited vs. created), leading them to incorrectly infer that a suspended account must have been invited, when in fact suspension is independent of how the account joined the organization.

How to eliminate wrong answers

Option A is wrong because a suspended account is not necessarily one that was invited; it could have been created directly or invited and then suspended. The status alone does not indicate the invitation method. Option B is wrong because the 'Production' account is listed as a member account (not the management account), as the management account is the one that initiated the organization and is not shown in the list of member accounts.

Option D is wrong because the management account is the original account that created the organization; it is not 'created directly' within the organization — it is the root account that already existed before the organization was formed.

18
MCQmedium

A company has a centralized networking team that manages a shared VPC with multiple AWS Transit Gateway attachments. Application teams create VPCs in separate AWS accounts and want to connect to the shared VPC. The networking team needs to ensure that only authorized VPCs can connect to the shared VPC. What is the MOST secure and scalable way to manage this?

A.Use a VPN connection from each application VPC to the shared VPC.
B.Use AWS Resource Access Manager to share the Transit Gateway with the application accounts.
C.Use VPC peering between the shared VPC and each application VPC.
D.Create IAM roles in each application account that allow the networking team to create VPC attachments.
AnswerB

AWS Resource Access Manager shares the Transit Gateway with specific application accounts, so only those accounts can create attachments. This satisfies the requirement that only authorised VPCs connect, and scales without manual peering or per-VPC approval workflows.

Why this answer

AWS Resource Access Manager (RAM) allows the centralized networking team to share the Transit Gateway with specific application accounts, enabling authorized VPCs to create attachments without exposing the resource to all accounts. This approach is secure because it uses resource-based policies to grant access only to designated accounts, and scalable because it avoids the administrative overhead of managing individual VPNs or VPC peering connections as the number of application VPCs grows.

Exam trap

The trap here is that candidates often confuse IAM permissions (Option D) with resource-based sharing via RAM, thinking that granting IAM roles to create attachments is sufficient, but RAM provides explicit authorization at the resource level, which is more secure and scalable for cross-account access.

How to eliminate wrong answers

Option A is wrong because using a VPN connection from each application VPC to the shared VPC introduces unnecessary complexity, latency, and bandwidth limitations compared to using a Transit Gateway, and it does not scale well as the number of VPCs increases. Option C is wrong because VPC peering requires a one-to-one connection between each application VPC and the shared VPC, which does not scale and creates a mesh of connections that is difficult to manage, and it also does not provide centralized routing or transitive connectivity. Option D is wrong because creating IAM roles in each application account that allow the networking team to create VPC attachments does not control which VPCs can connect; it only grants permission to create attachments, but any VPC in the application account could potentially attach, and it does not enforce authorization at the resource level like RAM does.

19
MCQhard

A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that when a new member account is added, the required IAM role is automatically created with a trust policy that allows the security account to assume it. The solution must minimize manual steps and work across all current and future accounts. Which approach should be used?

A.Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack set that creates the IAM role in all accounts in the organization, and configure automatic deployment to new accounts.
B.Use AWS Resource Access Manager to share an IAM role from the security account with all member accounts.
C.Implement a solution using AWS Service Catalog to share a portfolio containing the IAM role with all accounts, and require users to provision it manually.
D.Create an IAM role in each member account manually and use an AWS Lambda function triggered by AWS Organizations events to create the role in new accounts.
AnswerA

CloudFormation StackSets with service-managed permissions integrate with AWS Organizations to deploy stacks across all accounts. You can enable automatic deployment so that when a new account is added to the organization, the stack set is automatically deployed, creating the IAM role. This minimizes manual effort and ensures consistency.

Why this answer

CloudFormation StackSets with service-managed permissions are designed to deploy resources across an organization. By enabling automatic deployment, new accounts automatically receive the stack set, creating the required IAM role. This approach is scalable, requires no custom code, and ensures consistent configuration across all accounts.

Exam trap

The trap here is assuming that AWS RAM can share IAM roles or that manual or custom solutions are needed, when StackSets with service-managed permissions and automatic deployment is the native, low-effort solution.

20
MCQhard

A healthcare company operates a multi-account AWS environment with a shared services VPC in a central account. Workload accounts need to access a centralized Amazon RDS for MySQL database in the shared services VPC. The security team requires that all database traffic be encrypted in transit and that no workload account can access the database directly from the internet. They also want to minimize administrative overhead. Which solution meets these requirements?

A.Use AWS PrivateLink to create an interface VPC endpoint for RDS in each workload VPC, and enforce SSL/TLS on the RDS instance.
B.Deploy an Application Load Balancer in the shared services VPC, register the RDS instance as a target, and have workload accounts connect through the ALB using SSL/TLS.
C.Create a VPC peering connection between each workload VPC and the shared services VPC, and configure the RDS instance to require SSL/TLS connections.
D.Set up an AWS Transit Gateway with a central attachment in the shared services VPC, attach all workload VPCs, and configure the RDS security group to allow traffic only from the workload CIDR ranges over SSL/TLS.
AnswerD

AWS Transit Gateway provides a hub-and-spoke model that scales to many VPCs and accounts, centralizing connectivity and reducing administrative overhead. By attaching workload VPCs to the transit gateway and routing to the shared services VPC, traffic stays private. Enforcing SSL/TLS on the RDS instance and restricting the security group to workload CIDRs ensures encryption in transit and no internet exposure.

Why this answer

AWS Transit Gateway provides a scalable, centralized hub for connecting many VPCs across accounts, which minimizes administrative overhead compared to a mesh of VPC peering connections. By routing traffic through the transit gateway to the shared services VPC, workload accounts can access the RDS instance privately. Enforcing SSL/TLS on the RDS instance and restricting the security group to workload CIDRs ensures encryption in transit and prevents internet access.

Exam trap

The trap here is assuming that AWS PrivateLink can be used for Amazon RDS, but RDS is not a supported endpoint service for interface VPC endpoints.

21
MCQhard

A company has a multi-account AWS environment. The security team wants to centrally manage VPC flow logs for all accounts. They already have a centralized logging account. What is the MOST scalable solution?

A.Deploy a third-party log collector agent on each EC2 instance.
B.Configure AWS Transit Gateway to aggregate flow logs.
C.Use a CloudFormation StackSet to deploy VPC Flow Logs to an S3 bucket in the central account using bucket policies.
D.Enable VPC Flow Logs in each account and publish to a CloudWatch Logs group in the central account.
AnswerC

StackSets deploy the flow-log configuration across every account and region from one template, while the central bucket policy authorises each account's log-delivery principal. This satisfies the scalability constraint by avoiding per-account manual setup as the organisation grows.

Why this answer

Using a CloudFormation StackSet allows you to deploy VPC Flow Logs consistently across multiple accounts and regions, publishing them to a centralized S3 bucket in the logging account. Bucket policies grant cross-account write access, making this approach highly scalable without per-account agent management or CloudWatch Logs cross-account limitations.

Exam trap

The trap here is that candidates may think CloudWatch Logs can natively publish to a cross-account log group, but it cannot; S3 with bucket policies is the correct scalable approach for multi-account VPC Flow Logs.

How to eliminate wrong answers

Option A is wrong because deploying a third-party log collector agent on each EC2 instance is not scalable, introduces agent management overhead, and does not capture VPC-level network traffic (only instance-level). Option B is wrong because AWS Transit Gateway does not aggregate or generate flow logs; it is a network transit hub, not a logging service. Option D is wrong because CloudWatch Logs does not support publishing directly to a cross-account log group; you would need to use a subscription filter or a separate solution, and this approach does not scale as well as S3-based centralized storage.

22
MCQmedium

A company has 200 AWS accounts in AWS Organizations. The compliance team needs to prove that all Amazon S3 buckets across every account have server-side encryption enabled and block public access, and they want a single dashboard showing compliance status. Which solution should they implement?

A.Enable AWS Config in each account with an aggregator in the compliance account and deploy managed rules for S3 encryption and public access using AWS CloudFormation StackSets.
B.Use Amazon Macie in the compliance account to inventory all S3 buckets across the organization and report encryption status.
C.Create an AWS Lambda function in each account that calls the S3 API and writes results to a central Amazon DynamoDB table.
D.Enable AWS Trusted Advisor in the management account and review the S3 bucket permissions checks for all accounts.
AnswerA

AWS Config aggregators collect configuration and compliance data from multiple accounts and Regions into one view. Deploying the managed rules with StackSets ensures consistent evaluation across all 200 accounts, giving the compliance team a centralized dashboard that reflects each bucket's encryption and public access state.

Why this answer

AWS Config aggregators consolidate configuration and compliance data from all accounts and Regions into an administrator account, and managed rules can evaluate S3 encryption and public access settings. Using CloudFormation StackSets to deploy the rules ensures uniform coverage across 200 accounts, and the aggregator supplies the single compliance dashboard the team needs.

Exam trap

The trap here is substituting a data-classification service such as Amazon Macie, or a custom Lambda pipeline, for the configuration compliance capability that AWS Config aggregators provide.

23
MCQmedium

A company has a multi-account AWS environment with AWS Organizations. They use AWS IAM Identity Center (successor to AWS Single Sign-On) for workforce access. The security team wants to ensure that all federated users from the corporate identity provider (IdP) are automatically assigned to the appropriate permission sets based on their group membership in the IdP. The company uses SAML 2.0 federation with IAM Identity Center. Which configuration should the solutions architect implement to achieve automatic group-based permission set assignments?

A.Configure IAM Identity Center to use an external identity provider only for authentication, and use AWS Lambda functions triggered by IdP events to call the IAM Identity Center API to assign permission sets.
B.Configure SCIM synchronization between the IdP and IAM Identity Center, and map IdP groups to IAM Identity Center groups. Then assign permission sets to those groups.
C.Use SAML attribute mappings in IAM Identity Center to pass group names as session tags, and create IAM roles with trust policies that conditionally allow access based on those tags.
D.Manually create IAM Identity Center groups that match the IdP group names, and assign permission sets to those groups. Update memberships manually when IdP groups change.
AnswerB

SCIM (System for Cross-domain Identity Management) automatically synchronizes users and groups from the IdP to IAM Identity Center. Once groups are synchronized, you can assign permission sets to those groups, and users inherit access based on group membership. This provides automatic provisioning and deprovisioning, meeting the requirement with minimal manual effort.

Why this answer

SCIM synchronization automatically provisions users and groups from the corporate IdP into IAM Identity Center. By mapping IdP groups to IAM Identity Center groups and assigning permission sets to those groups, users receive the correct permissions based on their group membership without manual intervention.

Exam trap

The trap here is assuming that SAML attribute mappings alone can drive permission set assignments, when in fact SCIM is required for automatic group synchronization and assignment.

24
Multi-Selectmedium

A company wants to implement AWS Organizations with multiple OUs to isolate development, testing, and production workloads. The company needs to ensure that production workloads are not impacted by changes in other OUs. Which TWO practices should the company follow? (Choose two.)

Select 2 answers
A.Allow all users to assume cross-account roles for easier management.
B.Share the same VPC across all OUs to simplify networking.
C.Use separate AWS accounts for each environment to provide strong isolation.
D.Use resource tagging to isolate environments instead of accounts.
E.Apply separate SCPs to each OU to enforce different security policies.
AnswersC, E

Separate AWS accounts create hard security and blast-radius boundaries: IAM, quotas, and service limits are per-account, so a misconfiguration or quota exhaustion in development cannot affect production. This satisfies the stem's requirement that production workloads remain unaffected by changes in other OUs.

Why this answer

Option C is correct because using separate AWS accounts for each environment (development, testing, production) provides the strongest isolation boundary in AWS Organizations, since accounts are the primary security and billing boundary and prevent changes in one environment from affecting another. Option E is correct because Service Control Policies (SCPs) applied at the OU level let the company enforce distinct permission guardrails per OU, ensuring that actions allowed in development or testing OUs cannot be applied to production accounts. Options A and B are incorrect because sharing cross-account role assumptions broadly or sharing a single VPC across all OUs weakens isolation and increases the blast radius of misconfigurations.

Option D is incorrect because resource tagging is only a labeling and governance mechanism, not a security boundary, so it cannot provide the strong isolation that separate accounts and SCPs deliver.

Exam trap

The trap here is that candidates often confuse logical isolation (like tagging or VPC sharing) with the strong, account-level isolation required for production workloads, and may overlook that SCPs are the correct mechanism to enforce different security policies per OU.

25
MCQmedium

A company is using AWS Organizations and wants to centralize the management of Amazon EC2 instance security groups. The security team needs to enforce that certain ports are not open to the internet across all accounts. The company currently uses AWS Firewall Manager. Which approach should the security team use to enforce this policy?

A.Use AWS Config rules to detect non-compliant security groups and trigger a Lambda function to remediate.
B.Use AWS Firewall Manager to create a security group policy that defines rules, and apply it across all accounts. Firewall Manager will automatically create and manage security groups.
C.Use AWS Firewall Manager to audit security groups against a baseline policy and generate reports.
D.Use an SCP to deny ec2:AuthorizeSecurityGroupIngress for ports that should not be open.
AnswerB

Firewall Manager security group policies define the permitted rules once and enforce them across all accounts in the organisation, automatically creating and remediating security groups. This centrally blocks the specified internet-facing ports, meeting the cross-account enforcement requirement without per-account scripting.

Why this answer

AWS Firewall Manager can centrally create, apply, and manage security group policies across all accounts in an AWS Organization. By defining a security group policy with rules that block specific ports from 0.0.0.0/0, Firewall Manager automatically creates the required security groups and attaches them to the designated resources, ensuring compliance without manual intervention. This approach directly enforces the policy rather than just detecting or reporting violations.

Exam trap

The trap here is that candidates often confuse AWS Firewall Manager's audit-only mode (which generates reports) with its enforcement mode (which automatically creates and manages security groups), leading them to choose the reporting option instead of the correct enforcement option.

How to eliminate wrong answers

Option A is wrong because AWS Config rules with Lambda remediation are reactive—they detect non-compliant resources after creation and then attempt to fix them, which is not a preventive enforcement mechanism and can introduce latency or race conditions. Option C is wrong because auditing and generating reports only provides visibility into non-compliance but does not actively enforce the policy or prevent insecure security groups from being used. Option D is wrong because SCPs cannot deny specific API actions like ec2:AuthorizeSecurityGroupIngress based on port numbers or IP ranges; SCPs operate at the API action level and cannot inspect the parameters of the request, so they cannot block opening a specific port to the internet.

26
MCQmedium

A company has a multi-account AWS environment with a central shared services account. The company wants to provide a self-service portal for developers to request temporary AWS credentials for specific roles in various accounts. The credentials must be generated without creating IAM users and must be auditable. Which solution meets these requirements?

A.Create IAM users in each account and use AWS STS AssumeRole to obtain temporary credentials.
B.Use AWS IAM Identity Center (successor to AWS Single Sign-On) to assign users to permission sets that map to IAM roles in target accounts.
C.Use AWS Cognito user pools to authenticate developers and issue temporary AWS credentials via Cognito identity pools.
D.Deploy a custom portal that uses AWS Lambda to call sts:AssumeRole and returns credentials to the developer.
AnswerB

IAM Identity Center allows centralized management of user access and generates temporary credentials for IAM roles in target accounts without creating IAM users. It provides an audit trail through AWS CloudTrail and integrates with external identity providers, meeting the self-service and auditable requirements.

Why this answer

AWS IAM Identity Center is designed to centrally manage access to multiple AWS accounts and provides temporary credentials for IAM roles without IAM users. It supports self-service via the AWS access portal and logs all access in CloudTrail, meeting the auditable requirement with minimal operational overhead.

Exam trap

The trap here is assuming that Cognito identity pools are suitable for developer access to AWS accounts, when they are primarily for customer-facing applications.

27
MCQmedium

A company wants to centralize access control for multiple AWS accounts using AWS Organizations. They need to allow developers in a specific account to launch EC2 instances only in certain regions. What is the most scalable solution?

A.Create an IAM role in each account with a policy to deny non-compliant regions.
B.Use AWS Config rules to detect and terminate instances in non-compliant regions.
C.Use an SCP attached to the organizational unit to deny EC2 actions in non-compliant regions.
D.Create an IAM policy in each account to deny non-compliant regions.
AnswerC

SCPs set the maximum permissions for every principal in an organisational unit, so one deny on EC2 actions outside approved regions applies automatically to all current and future accounts in that OU. This satisfies the centralised, scalable control requirement without per-account IAM edits.

Why this answer

Service control policies (SCPs) in AWS Organizations allow you to centrally define the maximum permissions for all accounts in an organizational unit (OU). By attaching an SCP that denies EC2 actions in non-compliant regions, you enforce the restriction across multiple accounts without needing to manage individual IAM policies or roles, making it the most scalable solution.

Exam trap

The trap here is that candidates often choose detective solutions like AWS Config (Option B) or per-account IAM policies (Options A and D) because they are familiar, but they miss that SCPs provide a centralized, preventive, and scalable control that applies to all principals, including the root user.

How to eliminate wrong answers

Option A is wrong because creating an IAM role in each account still requires per-account management and does not prevent the root user or other principals from launching instances in non-compliant regions; SCPs apply to all principals including the root user. Option B is wrong because AWS Config rules are detective, not preventive; they can detect and terminate instances after launch, but this is reactive and does not prevent the initial launch, leading to potential cost and security exposure. Option D is wrong because creating an IAM policy in each account requires manual per-account configuration and does not scale; it also cannot restrict the root user, whereas SCPs apply to all principals in the account.

28
MCQeasy

A company has an AWS Organizations setup with a management account and several member accounts. The finance team needs to receive a consolidated bill for all accounts and wants to apply volume discounts across the organization. The company also wants to prevent member accounts from leaving the organization without approval. Which action should the company take?

A.Enable all features in AWS Organizations and configure a service control policy that denies organizations:LeaveOrganization in member accounts.
B.Create an organization trail in AWS CloudTrail and configure an Amazon EventBridge rule to notify the finance team when an account leaves.
C.Use AWS Resource Access Manager to share the billing account with member accounts and restrict the organizations:LeaveOrganization action with an IAM policy in each member account.
D.Enable consolidated billing only, and use AWS Budgets to alert the finance team when a member account attempts to leave.
AnswerA

Enabling all features allows consolidated billing and volume discounts across the organization, and it also enables service control policies. A service control policy denying organizations:LeaveOrganization in member accounts prevents them from leaving without approval. This combination meets both the billing and the membership control requirements.

Why this answer

Enabling all features in AWS Organizations provides consolidated billing and volume discounts, and it is a prerequisite for service control policies. A service control policy that denies organizations:LeaveOrganization in member accounts prevents them from leaving without approval. This is the only option that both delivers the billing benefits and enforces the membership restriction.

Exam trap

The trap here is relying on monitoring tools like AWS Budgets or CloudTrail to prevent an action, when only a service control policy can actually block a member account from leaving the organization.

29
MCQhard

A company has 200 AWS accounts in AWS Organizations and a shared services VPC in a central networking account. Each workload account needs to reach an on-premises data center over a single AWS Direct Connect connection that terminates in the networking account. The company wants to minimize cost and avoid managing individual VPC peering connections. Which solution should a solutions architect recommend?

A.Deploy an AWS Site-to-Site VPN over the Direct Connect connection in each workload account and configure BGP to advertise the on-premises routes.
B.Create a VPC peering connection between the shared services VPC and each workload VPC, and propagate the Direct Connect routes through a static route in each workload VPC route table.
C.Create a transit gateway in the networking account, attach the Direct Connect gateway and all workload VPCs to it, and share the transit gateway using AWS Resource Access Manager.
D.Use AWS PrivateLink to create interface VPC endpoints in each workload VPC that point to the on-premises services in the networking account.
AnswerC

A transit gateway in the networking account can attach the Direct Connect gateway and all workload VPCs, and AWS Resource Access Manager lets other accounts in the organization attach their VPCs to the shared transit gateway. This centralizes connectivity, avoids a full mesh of peering connections, and scales to hundreds of accounts at lower operational cost.

Why this answer

A transit gateway in the networking account acts as a regional hub that connects the Direct Connect gateway and all workload VPCs. AWS Resource Access Manager shares the transit gateway with other accounts in the organization, so workload accounts attach their VPCs without creating peering meshes or per-account VPNs. This scales cleanly and reduces cost and operational overhead.

Exam trap

The trap here is assuming VPC peering is transitive or that PrivateLink provides general on-premises routing, when only a transit gateway shared through AWS Resource Access Manager centralizes connectivity at scale.

30
MCQeasy

A company uses AWS Organizations with consolidated billing. The finance team wants to track costs by department. Each department has its own AWS account. Which feature should be used to map costs to departments?

A.Use cost allocation tags to tag resources with a department tag.
B.Use Amazon CloudWatch custom metrics to record department IDs.
C.Use service control policies (SCPs) to restrict costs per account.
D.Use AWS Budgets to create budgets per department.
AnswerA

Cost allocation tags attach department metadata to resources, and once activated in the billing console they appear as a dimension in Cost Explorer and Cost and Usage Reports, letting finance group spend by department across the linked accounts under consolidated billing.

Why this answer

Cost allocation tags allow you to tag AWS resources with metadata (e.g., department name) and then activate those tags in the AWS Billing and Cost Management console. Once activated, AWS generates cost reports that break down spending by those tags, enabling the finance team to map costs to each department's account. This is the native, recommended approach for cost attribution across accounts in AWS Organizations.

Exam trap

The trap here is that candidates confuse cost allocation tags with AWS Budgets or SCPs, mistakenly thinking that SCPs can limit costs or that Budgets can map costs, when in fact only tags provide the granular, reportable metadata needed for cost attribution.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch custom metrics are designed for monitoring operational performance (e.g., CPU utilization), not for tracking or attributing costs; they cannot be used to generate cost allocation reports. Option C is wrong because service control policies (SCPs) are used to centrally control permissions and enforce guardrails across accounts, not to restrict or track costs; they do not provide cost mapping or reporting capabilities. Option D is wrong because AWS Budgets allow you to set cost thresholds and receive alerts, but they do not provide a mechanism to map historical or granular costs to specific departments; they are a monitoring tool, not a cost attribution feature.

31
MCQhard

A company has a multi-account AWS environment with a central network account that hosts a shared AWS Transit Gateway. The company wants to implement a hub-and-spoke network topology where all inter-VPC traffic between workload VPCs must be inspected by a central security VPC before reaching its destination. The security VPC contains an AWS Network Firewall. The company needs to ensure that traffic between any two workload VPCs is routed through the security VPC. Which configuration should a solutions architect implement?

A.Create a single Transit Gateway route table, associate all workload VPC attachments and the security VPC attachment with it, and propagate all attachments. Configure the security VPC attachment as the default route for all traffic.
B.Use AWS Resource Access Manager to share the Transit Gateway with all workload accounts. Configure each workload VPC to have a route to the security VPC's CIDR through a peering connection, and use the Transit Gateway for all other traffic.
C.Create two Transit Gateway route tables: one for workload VPCs and one for the security VPC. Associate each workload VPC attachment with the workload route table and propagate the security VPC attachment into it. Associate the security VPC attachment with the security route table and propagate all workload VPC attachments into it. Configure the workload route table to have a default route to the security VPC attachment.
D.Create a separate Transit Gateway route table for each workload VPC, associate the VPC attachment with its own route table, and propagate all other workload VPC attachments into that route table. Configure the security VPC attachment to be the next hop for all traffic.
AnswerC

This configuration isolates workload VPCs from each other by placing them in a route table that only has routes to the security VPC (via propagation of the security attachment) and a default route to the security VPC. The security VPC route table has routes to all workload VPCs, allowing return traffic. This forces all inter-VPC traffic through the security VPC for inspection.

Why this answer

To force all inter-VPC traffic through a central security VPC, you must prevent direct routing between workload VPCs on the Transit Gateway. Using separate route tables for workload and security attachments, with the workload route table having only a default route to the security VPC, ensures that all traffic from a workload VPC goes to the security VPC first. The security VPC route table then routes to the destination workload VPC.

Exam trap

The trap here is assuming that a single Transit Gateway route table with a default route to the security VPC will force all traffic through it, when propagated routes create more specific paths that bypass the default.

32
MCQeasy

A company uses AWS Organizations and wants to allow a development account to assume a role in the production account for deployment purposes. Which component is necessary for this cross-account access?

A.A VPC peering connection between the accounts
B.An IAM role in the production account with a trust policy allowing the development account
C.A service control policy (SCP) that permits AssumeRole
D.An AWS Config rule to validate the role
AnswerB

The trust policy on the production role names the development account as principal, which is what permits the cross-account sts:AssumeRole call. Without that trust relationship, the development account's identity cannot obtain temporary credentials, so the deployment access fails.

Why this answer

Cross-account IAM access requires a role in the target (production) account with a trust policy that explicitly lists the source (development) account as a trusted principal. The development account then uses the STS AssumeRole API to obtain temporary credentials for that role. Without this trust policy, the role cannot be assumed from another account.

Exam trap

The trap here is confusing network connectivity (VPC peering) with IAM authorization, or assuming that an SCP alone can enable cross-account access when SCPs only act as a permission guardrail within an organization.

How to eliminate wrong answers

Option A is wrong because VPC peering connects networks at Layer 3 and does not provide any IAM-based authentication or authorization for cross-account role assumption. Option C is wrong because SCPs can only deny or allow permissions for principals within the same organization; they cannot grant cross-account access or replace the need for a trust policy on the target role. Option D is wrong because AWS Config rules evaluate resource compliance after the fact and do not enable or control the ability to assume a role across accounts.

33
Multi-Selecteasy

Which TWO AWS services can be used to automate the enforcement of compliance policies across multiple AWS accounts? (Choose TWO.)

Select 2 answers
A.AWS CloudTrail
B.AWS Organizations SCPs
C.AWS CloudFormation StackSets
D.Amazon VPC Flow Logs
E.AWS Config rules
AnswersB, E

AWS Organizations service control policies centrally restrict the maximum available permissions across every member account, satisfying the multi-account enforcement constraint. Attaching an SCP to an organisational unit or the root immediately denies non-compliant actions organisation-wide, regardless of each account's own IAM policies, giving automated, preventive governance rather than detective-only monitoring.

Why this answer

AWS Organizations Service Control Policies (SCPs) are correct because they attach at the OU or account level and set the maximum available permissions for member accounts, thereby automatically enforcing compliance guardrails (e.g., denying use of unapproved regions or services) across many accounts at once. AWS Config rules are correct because they continuously evaluate resource configurations against desired compliance policies and can trigger automatic remediation (via SSM Automation documents) across accounts when aggregated with a Config aggregator, enabling automated enforcement. AWS CloudTrail only records API activity for auditing and does not enforce policy, so it is not correct.

AWS CloudFormation StackSets deploys resources across accounts but does not itself enforce compliance policies, so it is not correct. Amazon VPC Flow Logs capture IP traffic metadata for monitoring and troubleshooting, not policy enforcement, so it is not correct.

Exam trap

The trap here is that candidates often confuse monitoring services (CloudTrail, VPC Flow Logs) with enforcement services, or assume that infrastructure deployment tools (CloudFormation StackSets) inherently enforce compliance, when in fact they only provision resources without policy enforcement.

34
MCQmedium

A company has a centralized security account and wants to enable AWS Config in all accounts. They want to centrally manage Config rules and view compliance. What should they do?

A.Apply an SCP to enable AWS Config in all accounts.
B.Use CloudFormation StackSets to deploy Config rules, then view in each account.
C.Enable AWS Config in the security account only and use cross-account roles.
D.Enable AWS Config in each account and use an aggregator in the security account.
AnswerD

An aggregator in the security account collects configuration and compliance data from every source account, satisfying the centralised visibility requirement. AWS Config must still be enabled per account and Region, since the aggregator only gathers existing data rather than activating recording. This delivers central rule management and compliance viewing across the organisation.

Why this answer

AWS Config must be enabled in each individual account to record resource configurations and evaluate rules. An aggregator in the security account can then collect compliance data from all accounts, enabling centralized viewing and management of Config rules without needing to log into each account separately.

Exam trap

The trap here is that candidates assume a single Config instance in a central account can monitor all other accounts via cross-account roles, but AWS Config is account-scoped and must be enabled in each account to record its own resources.

How to eliminate wrong answers

Option A is wrong because SCPs (Service Control Policies) can only restrict or deny permissions; they cannot enable a service like AWS Config in accounts. Option B is wrong because CloudFormation StackSets can deploy Config rules across accounts, but without Config being enabled in each account first, the rules have no configuration recorder to evaluate against, and compliance cannot be viewed centrally without an aggregator. Option C is wrong because enabling AWS Config only in the security account would only record resources in that account; cross-account roles allow access but do not enable Config recording or rule evaluation in other accounts.

35
MCQeasy

A company wants to centrally manage backups for Amazon EBS volumes across multiple AWS accounts. They need a solution that can automatically back up volumes based on tags, retain backups according to a policy, and send notifications on failures. Which AWS service should they use?

A.AWS CloudFormation StackSets
B.Amazon RDS automated backups
C.AWS Backup
D.Amazon S3 lifecycle policies
AnswerC

AWS Backup satisfies the cross-account, tag-driven requirement through backup policies applied at the organisation level, with lifecycle rules governing retention and Amazon EventBridge delivering failure notifications. Unlike EBS snapshots managed per-account, it centralises governance across accounts, meeting the centralised management constraint in the stem.

Why this answer

AWS Backup is the correct service because it provides a centralized, policy-based backup solution for Amazon EBS volumes across multiple AWS accounts. It supports tag-based backup policies, retention rules, and integrates with Amazon CloudWatch Events and Amazon SNS to send notifications on failures, meeting all the stated requirements.

Exam trap

The trap here is that candidates might confuse AWS Backup with native snapshot management or assume that a service like CloudFormation StackSets can handle backup automation, but only AWS Backup provides the centralized, policy-driven, cross-account backup management with notification capabilities required by the scenario.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation StackSets is used to deploy infrastructure as code across multiple accounts and regions, not for managing backups or retention policies. Option B is wrong because Amazon RDS automated backups are specific to RDS databases and cannot back up EBS volumes or operate across multiple accounts. Option D is wrong because Amazon S3 lifecycle policies manage the transition and expiration of objects within S3 buckets, not the backup of EBS volumes.

36
MCQhard

A global company uses AWS Organizations with hundreds of accounts. The networking team needs to allow VPCs in different accounts to communicate privately using AWS Transit Gateway. The company wants to centralize management while allowing individual account owners to create and attach VPCs. Which solution meets these requirements?

A.Create a VPN connection from each VPC to a central network appliance.
B.Use AWS PrivateLink to connect each VPC to a central VPC endpoint service.
C.Create a Transit Gateway in the networking account and share it with other accounts using AWS Resource Access Manager.
D.Create VPC peering connections between each VPC and a central VPC.
AnswerC

AWS Resource Access Manager shares the Transit Gateway from the networking account to other accounts or the organisation, letting individual owners create and attach their own VPC attachments while the networking team retains central ownership and management.

Why this answer

AWS Transit Gateway allows you to centralize network connectivity across multiple VPCs and accounts. By creating the Transit Gateway in the networking account and sharing it via AWS Resource Access Manager (RAM), you enable individual account owners to attach their VPCs to the shared Transit Gateway, achieving private communication while maintaining centralized management.

Exam trap

The trap here is that candidates often confuse AWS PrivateLink (which is for service exposure, not general routing) with Transit Gateway, or assume VPC peering can be scaled via a central VPC, failing to recognize that peering is non-transitive and requires a full mesh for multi-VPC connectivity.

How to eliminate wrong answers

Option A is wrong because VPN connections from each VPC to a central network appliance introduce significant complexity, bandwidth limitations, and operational overhead; they do not leverage native AWS transit capabilities and are not designed for scalable inter-VPC communication across hundreds of accounts. Option B is wrong because AWS PrivateLink is used to expose services privately from a VPC to other VPCs, not to enable general VPC-to-VPC routing; it requires creating endpoint services and does not provide a hub-and-spoke transit architecture for arbitrary VPC connectivity. Option D is wrong because VPC peering connections are one-to-one and do not scale to hundreds of accounts; they require full mesh or star topology with manual peering for each pair, and they do not support transitive routing, making centralized management impractical.

37
MCQmedium

A company uses AWS Organizations with a management account and 40 member accounts. The security team needs to centrally manage IAM roles that grant cross-account access to a shared services account. They want to deploy the roles to all member accounts and ensure new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?

A.Create an AWS CloudFormation StackSet with service-managed permissions in the management account, and configure automatic deployment to all accounts in the organization.
B.Use AWS Systems Manager Automation to run a script in each member account that creates the required IAM roles.
C.Enable AWS Control Tower and use its Account Factory to provision new accounts with a custom blueprint that includes the IAM roles.
D.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share it with all member accounts.
AnswerA

CloudFormation StackSets with service-managed permissions integrate directly with AWS Organizations, allowing automatic deployment of IAM roles to all existing and future accounts. This eliminates manual per-account deployment and ensures new accounts receive the roles automatically, meeting the least operational overhead requirement.

Why this answer

CloudFormation StackSets with service-managed permissions is the native AWS Organizations-integrated solution for deploying a common stack to many accounts. It automatically targets existing accounts and new accounts as they join the organization, and it can be configured to deploy to specific OUs. This provides centralized management with minimal ongoing effort, unlike manual or script-based approaches.

Exam trap

The trap here is assuming that AWS RAM can share IAM roles across accounts, when RAM only supports specific resource types like subnets, transit gateways, and license configurations.

38
MCQhard

A multinational company has a multi-account AWS environment with a central network account. They use AWS Transit Gateway to connect all VPCs. The company wants to implement centralized inspection of all traffic between VPCs using a third-party firewall appliance running on EC2 instances in a dedicated inspection VPC. Traffic must be inspected without modifying workload VPC route tables when new VPCs are added. What should the solutions architect recommend?

A.Deploy the firewall instances in the central network account and use AWS Resource Access Manager to share them with all workload accounts, then update each workload VPC's route tables to point to the firewall ENIs.
B.Use AWS PrivateLink to connect each workload VPC to the inspection VPC, and configure endpoint policies to redirect traffic.
C.Use AWS Transit Gateway with a separate route table for the inspection VPC, and configure the firewall instances as appliances in the inspection VPC. Use Transit Gateway route table associations and propagations to direct traffic through the inspection VPC.
D.Create a VPC peering connection between each workload VPC and the inspection VPC, and update each workload VPC's route tables to point to the inspection VPC for inter-VPC traffic.
AnswerC

Transit Gateway route tables can be used to isolate and direct traffic. By associating workload VPC attachments with a route table that points to the inspection VPC attachment, and associating the inspection VPC attachment with a route table that points to workload VPCs, you can force traffic through the firewall without modifying workload VPC route tables. New VPCs can be associated with the appropriate route table centrally.

Why this answer

Transit Gateway route tables allow centralized traffic steering. By associating workload VPC attachments with a route table that routes to the inspection VPC, and the inspection VPC attachment with a route table that routes back, traffic is forced through the firewall. New VPCs only need to be associated with the correct route table, avoiding workload VPC route table changes.

Exam trap

The trap here is thinking that VPC peering or PrivateLink can provide centralized inspection without modifying workload VPC route tables, when they actually require per-VPC route changes or do not support arbitrary traffic inspection.

39
MCQeasy

A company is migrating to AWS and wants to use AWS CloudFormation to manage infrastructure as code. The DevOps team needs to ensure that stack updates are reviewed and approved before execution. Which feature should they use?

A.AWS CloudFormation Drift Detection
B.AWS CloudFormation StackSets
C.AWS CloudFormation Change Sets
D.AWS CloudFormation Nested Stacks
AnswerC

CloudFormation change sets generate a preview of proposed resource modifications before execution, letting reviewers inspect additions, deletions and replacements. This directly satisfies the stem's requirement that stack updates be reviewed and approved prior to execution, since the change set must be explicitly executed after inspection.

Why this answer

AWS CloudFormation Change Sets allow you to preview how proposed changes to a stack will impact your running resources before you apply them. This enables the DevOps team to review and approve stack updates by generating a summary of the changes (additions, modifications, deletions) without executing them immediately, meeting the requirement for a review-and-approval workflow.

Exam trap

The trap here is that candidates may confuse Drift Detection (which detects post-deployment configuration drift) with Change Sets (which preview intended changes before deployment), leading them to select Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because Drift Detection is used to detect whether a stack's actual resources have deviated from the expected template configuration, not to review or approve updates before execution. Option B is wrong because StackSets enable you to deploy stacks across multiple accounts and regions from a single template, but they do not provide a mechanism to preview or approve changes before applying them. Option D is wrong because Nested Stacks allow you to compose stacks from other stacks for modularity, but they do not offer a change review or approval process for updates.

40
MCQmedium

A company is migrating its on-premises Active Directory to AWS Managed Microsoft AD. The company has multiple VPCs across different accounts that need to authenticate against the same directory. What is the MOST scalable and secure way to provide this access?

A.Set up a VPN connection from each VPC to the on-premises AD.
B.Deploy AWS Managed Microsoft AD in a central account and share it with other accounts using AWS Resource Access Manager.
C.Clone the directory and deploy it in each account.
D.Deploy an AD Connector in each VPC pointing to the on-premises AD.
AnswerB

AWS Resource Access Manager shares a single AWS Managed Microsoft AD directory across accounts and VPCs, avoiding duplicate directories. This centralises authentication, satisfies the multi-VPC requirement, and scales without per-account directory deployments or exposed credentials.

Why this answer

AWS Resource Access Manager (RAM) allows you to share AWS Managed Microsoft AD directories across accounts without duplicating the directory or managing multiple trust relationships. This provides a single, centrally managed directory that multiple VPCs in different accounts can authenticate against, ensuring scalability and security by avoiding cross-account credential replication or complex VPN meshes.

Exam trap

The trap here is that candidates often assume each VPC needs its own directory or AD Connector, but AWS RAM enables secure, scalable sharing of a single Managed AD across accounts without additional infrastructure.

How to eliminate wrong answers

Option A is wrong because setting up a VPN from each VPC to on-premises AD does not leverage AWS Managed Microsoft AD and introduces latency, single points of failure, and management overhead for multiple VPN tunnels; it also fails to migrate the directory to AWS as required. Option C is wrong because cloning the directory and deploying it in each account creates multiple independent directories that require complex cross-forest trusts or replication, breaking the requirement for a single shared directory and increasing administrative burden. Option D is wrong because deploying an AD Connector in each VPC points back to the on-premises AD, which does not migrate the directory to AWS Managed Microsoft AD and still relies on on-premises infrastructure, defeating the purpose of the migration.

41
MCQeasy

A company is using AWS Organizations with multiple organizational units (OUs). The security team needs to enforce that all newly created S3 buckets in the production OU have versioning enabled and are encrypted with AWS KMS. Which solution meets these requirements with minimal operational overhead?

A.Apply a service control policy (SCP) at the production OU level that denies s3:CreateBucket unless versioning and KMS encryption are specified in the request.
B.Use AWS CloudTrail to monitor bucket creation and send alerts to the security team.
C.Create an IAM policy that requires versioning and KMS encryption when creating buckets, and attach it to all users.
D.Use AWS Config rules to detect noncompliant buckets and auto-remediate with Lambda.
AnswerD

Correct. AWS Config evaluates bucket configurations and uses custom Lambda functions to auto-remediate, enabling versioning and KMS encryption for any noncompliant bucket. This provides automated enforcement with acceptable operational overhead.

Why this answer

It uses AWS Config rules to detect noncompliant S3 buckets (e.g., missing versioning or KMS encryption) and triggers an automated Lambda remediation to enable versioning and encryption. This ensures compliance with minimal manual intervention, though it does incur some operational overhead for Lambda maintenance. Option A is incorrect because SCPs cannot enforce versioning at bucket creation—versioning is enabled after creation via PutBucketVersioning, and the headers mentioned in the explanation do not exist.

Option B only alerts and does not enforce. Option C is not scalable for OU-level enforcement and can be bypassed.

Exam trap

The trap is that candidates assume SCPs can enforce versioning at bucket creation because they are familiar with SCPs for preventive controls. However, versioning cannot be specified in the CreateBucket request; it must be enabled separately. Thus, the only viable option is AWS Config with auto-remediation (Option D), which is reactive but enforceable.

How to eliminate wrong answers

Option B is wrong because CloudTrail monitoring only alerts after the bucket is created, not preventing noncompliant buckets, and requires manual or automated follow-up, adding operational overhead. Option C is wrong because an IAM policy attached to users does not prevent creation by roles, services (e.g., CloudFormation), or cross-account access, and it cannot enforce compliance across all principals in the OU. Option D is wrong because AWS Config rules detect noncompliant buckets after creation and auto-remediate with Lambda, which is reactive and incurs overhead for remediation logic and potential race conditions, whereas SCPs prevent the violation proactively.

42
MCQhard

A company uses AWS Organizations with 100 accounts. The security team wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. They create an SCP that denies all actions if MFA is not present. However, some users report that they cannot access the console even with MFA. What is the most likely reason?

A.The SCP does not include an explicit allow for the sts:GetSessionToken action.
B.The IAM policy attached to the users does not allow any actions.
C.The SCP does not apply to users who have administrative privileges.
D.The SCP also denies access to the root user of each account.
AnswerA

Without allowing STS:GetSessionToken, the MFA challenge cannot be completed.

Why this answer

When users authenticate with MFA, the AWS Management Console calls the STS GetSessionToken API to obtain temporary credentials that include the MFA session. If the SCP denies all actions, including sts:GetSessionToken, then even with valid MFA the user cannot obtain the necessary temporary credentials, resulting in access denial. The SCP must explicitly allow the sts:GetSessionToken action for users who authenticate with MFA.

Option B is incorrect because the issue is not about the users' IAM policies but about the SCP. Option C is incorrect because SCPs apply to all principals in the account, including administrators. Option D is incorrect because the SCP does not inherently affect the root user differently; root user is not affected by SCPs in the management account.

43
MCQeasy

A company uses AWS Organizations with a management account and several member accounts. The security team needs to centrally manage IAM users and roles across all accounts. Which AWS service should the company use?

A.AWS Directory Service for Microsoft Active Directory.
B.AWS Identity and Access Management (IAM) in the management account.
C.AWS IAM Identity Center (AWS SSO).
D.Amazon Cognito user pools.
AnswerC

IAM Identity Center provides centralised management of users, groups and permission sets, then federates access into member accounts via IAM roles. This satisfies the requirement to manage identities centrally across all accounts without creating separate IAM users in each.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized place to manage user identities and permissions across multiple AWS accounts within an AWS Organization. It allows the security team to create or connect users and groups, and assign them fine-grained permissions to accounts, roles, and applications from a single pane of glass, eliminating the need to create IAM users in each account.

Exam trap

The trap here is that candidates often confuse IAM Identity Center with simply using IAM in the management account, failing to realize that IAM is account-scoped and cannot centrally manage identities across multiple accounts without additional federation or automation.

How to eliminate wrong answers

Option A is wrong because AWS Directory Service for Microsoft Active Directory is a managed Microsoft AD service used for identity federation and directory-aware workloads, not for centrally managing IAM users and roles across AWS accounts. Option B is wrong because IAM in the management account can only manage users and roles within that single account; it cannot natively manage identities across member accounts without complex cross-account role assumptions and manual duplication. Option D is wrong because Amazon Cognito user pools are designed for customer-facing identity and access management for web and mobile applications, not for managing workforce identities or AWS account access.

44
Drag & Dropmedium

Drag and drop the steps to restore an Amazon RDS DB instance from a snapshot in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First navigate to snapshots, restore, configure settings, wait for completion, then update application endpoint.

45
Multi-Selectmedium

A company is designing a multi-account strategy using AWS Organizations. The security team requires that all API calls to create or modify IAM roles are logged and alerted. Which TWO steps should be taken to meet this requirement?

Select 2 answers
A.Use AWS Config to record IAM role changes and stream to CloudWatch Logs.
B.Create a CloudWatch Logs metric filter and alarm to detect IAM role creation/modification events.
C.Create an SCP that denies IAM role creation and modification.
D.Enable CloudTrail management events with CloudWatch Logs integration in all accounts.
E.Enable IAM Access Analyzer to monitor IAM role usage.
AnswersB, D

CloudTrail delivers IAM role creation and modification events to CloudWatch Logs, where a metric filter matches the specific API calls (CreateRole, UpdateAssumeRolePolicy, AttachRolePolicy). The alarm then alerts the security team, satisfying the requirement to both log and alert on these events across the organisation's accounts.

Why this answer

Option D is correct because CloudTrail management events capture IAM API calls such as CreateRole, UpdateRole, and PutRolePolicy, and integrating CloudTrail with CloudWatch Logs in every account (or via an organization trail) delivers those events to a central place for monitoring. Option B is correct because a CloudWatch Logs metric filter matches patterns for IAM role creation/modification events in the delivered CloudTrail logs, and an associated CloudWatch alarm triggers the required alerting. Together, D provides the logging pipeline and B provides detection and alerting.

Option A is not appropriate because AWS Config records resource configuration changes and compliance, not the API call events needed for real-time alerting on IAM role creation/modification. Option C is wrong because an SCP that denies IAM role creation/modification would block the activity rather than log and alert on it. Option E is wrong because IAM Access Analyzer identifies resource access and permissions issues, not API call logging or alerting.

Exam trap

The trap here is that candidates often confuse AWS Config (which records configuration changes) with CloudTrail (which records API calls), leading them to select Option A instead of the correct combination of CloudTrail and CloudWatch Logs metric filters.

46
Multi-Selecteasy

A company uses AWS Organizations to manage multiple accounts. The central team wants to deploy a CloudFormation template that creates an S3 bucket with default encryption in every member account. Which THREE steps are required to accomplish this?

Select 3 answers
A.Create an IAM role in each member account that allows CloudFormation to create resources.
B.Create an SCP that allows CloudFormation to create S3 buckets.
C.Write a CloudFormation template that includes an S3 bucket resource with default encryption enabled.
D.Create a CloudFormation StackSet in the management account.
E.Configure the StackSet with the target accounts and regions, and specify an IAM role for execution.
AnswersC, D, E

The template must define the S3 bucket resource with default encryption configured, since StackSets deploy whatever the template declares. Without this resource and its encryption property, no bucket with default encryption would be created in member accounts, so this step is essential.

Why this answer

Option C is correct because the template itself must define the AWS::S3::Bucket resource with encryption enabled (for example, BucketEncryption with SSE-S3 or SSE-KMS) so that every deployed bucket has default encryption. Option D is correct because CloudFormation StackSets are the AWS Organizations-integrated mechanism for deploying a single template across many accounts from the management account. Option E is correct because a StackSet requires you to specify the target accounts (or organizational units) and regions, and to supply an IAM execution role that CloudFormation assumes in each target account to create the resources.

Option A is not required as a separate step because StackSets use a single execution role (often created automatically or supplied via the StackSet configuration) rather than manually creating a role in each member account. Option B is not required because an SCP is a permissions guardrail, not a deployment mechanism; CloudFormation StackSets handle the cross-account deployment, and no SCP specifically allowing S3 bucket creation is needed.

Exam trap

The trap here is that candidates confuse SCPs with IAM policies, assuming SCPs can grant permissions to CloudFormation, when in fact SCPs only restrict permissions and the actual execution relies on an IAM role assumed by StackSets.

47
Multi-Selectmedium

A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all newly created Amazon S3 buckets are encrypted with AWS KMS keys managed by the security account, and that any attempts to create unencrypted buckets are denied. The company also wants to ensure that existing buckets are remediated. Which two actions should the security team take to meet these requirements? (Choose two.)

Select 2 answers
A.Use AWS CloudFormation StackSets to deploy a custom resource that scans all buckets and enables encryption, and use an SCP to deny s3:CreateBucket without encryption.
B.Attach a service control policy to the root of the organization that denies s3:CreateBucket unless the request includes the s3:x-amz-server-side-encryption condition key with value aws:kms and the s3:x-amz-server-side-encryption-aws-kms-key-id condition key with the security account's KMS key ARN.
C.Use AWS Config with a conformance pack that includes the s3-bucket-server-side-encryption-enabled rule and an automatic remediation action that enables default encryption with a KMS key from the security account.
D.Attach a service control policy to the root of the organization that denies s3:CreateBucket unless the request includes the s3:x-amz-server-side-encryption header with value aws:kms.
E.Use an SCP that denies s3:PutBucketEncryption if the request does not specify a KMS key ARN from the security account, and use AWS Config to remediate existing buckets.
AnswersB, C

This SCP enforces that any s3:CreateBucket request must include both the encryption header and the specific KMS key ARN from the security account. This prevents the creation of unencrypted buckets and ensures the use of the security account's KMS key, meeting the requirement for centralized key management.

Why this answer

The SCP with conditions on s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id ensures that new buckets are created with the correct encryption and key. AWS Config conformance packs with automatic remediation detect and fix existing unencrypted buckets, providing ongoing compliance. Together, these actions enforce encryption at creation and remediate existing buckets.

Exam trap

The trap here is assuming that SCPs alone can remediate existing resources, when in fact SCPs only affect new API calls and do not change existing configurations.

48
MCQeasy

A company has a decentralized IT structure where each business unit manages its own AWS account. The central security team needs visibility into all IAM user activities across accounts. What is the MOST scalable solution to aggregate CloudTrail logs?

A.Enable CloudTrail Insights in each account and review separately.
B.Use AWS Config aggregator to collect IAM user activity.
C.Set up Amazon Kinesis Data Streams in each account and stream to a central Kinesis Data Firehose.
D.Configure CloudTrail in each account to deliver logs to a single S3 bucket in the security account.
AnswerD

CloudTrail delivers logs to a central S3 bucket via a bucket policy granting each account's trail write access, satisfying the multi-account aggregation requirement without per-account tooling. This scales to any number of business units, unlike manual consolidation, and preserves a single queryable log repository for the central security team.

Why this answer

CloudTrail can be configured in each account to deliver log files to a centralized S3 bucket in the security account. This approach aggregates all IAM user activities into a single location without requiring additional streaming infrastructure, and it scales automatically as new accounts are added. The central security team can then use Amazon Athena or AWS Lake Formation to query the logs across all accounts efficiently.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Kinesis (Option C) because they assume streaming is required for scalability, but CloudTrail's native S3 delivery is the most scalable and cost-effective aggregation method for IAM user activity logs.

How to eliminate wrong answers

Option A is wrong because reviewing CloudTrail Insights separately in each account does not aggregate logs; it requires manual per-account access and lacks a centralized view, making it unscalable for decentralized IT structures. Option B is wrong because AWS Config aggregator is designed to collect resource configuration changes and compliance history, not IAM user activity logs; CloudTrail is the service that records API activity, not AWS Config. Option C is wrong because setting up Kinesis Data Streams in each account and streaming to a central Kinesis Data Firehose introduces unnecessary complexity, cost, and operational overhead compared to the simpler S3 bucket delivery method; CloudTrail can directly deliver to S3 without needing Kinesis.

49
MCQeasy

A company has an AWS Organization with multiple accounts. The central IT team wants to deploy a common set of AWS Config rules across all accounts in the production OU. Which approach is the MOST scalable and maintainable?

A.Use an AWS Config aggregator to deploy rules across accounts.
B.Use AWS CloudFormation StackSets to deploy an AWS Config rule template to each account.
C.Use AWS Config conformance packs and deploy them using AWS CloudFormation StackSets.
D.Use AWS Config to create a custom rule in each account manually.
AnswerC

Conformance packs bundle Config rules as a single deployable entity, and StackSets pushes that pack into every account in the production OU automatically, including new accounts. This satisfies the scalability and maintainability requirement without per-account manual rule creation.

Why this answer

AWS Config conformance packs provide a collection of AWS Config rules and remediation actions that can be deployed consistently across accounts and Regions. Using AWS CloudFormation StackSets to deploy conformance packs is the most scalable and maintainable approach because StackSets automates the deployment to multiple accounts in an AWS Organization, and conformance packs allow centralized management of rule sets, including parameterization and remediation, without requiring per-account manual effort.

Exam trap

The trap here is that candidates confuse the purpose of an AWS Config aggregator (which only aggregates compliance data) with the ability to deploy rules, leading them to select Option A, while Option B seems plausible but misses that conformance packs are the purpose-built, more maintainable solution for deploying a common set of rules at scale.

How to eliminate wrong answers

Option A is wrong because an AWS Config aggregator is used to aggregate compliance data from multiple accounts and Regions into a single view; it does not deploy or manage Config rules across accounts. Option B is wrong because while CloudFormation StackSets can deploy individual Config rules, conformance packs are the recommended service for deploying a common set of rules with built-in support for organization-wide management, parameterization, and remediation actions, making them more maintainable than deploying individual rules. Option D is wrong because manually creating custom rules in each account is not scalable, introduces human error, and violates the principle of infrastructure as code and centralized management.

50
MCQmedium

A company wants to implement a multi-account strategy using AWS Organizations. The security team requires that all new accounts added to the organization automatically inherit a baseline set of security controls, such as AWS CloudTrail and AWS Config rules. Which approach should the company use?

A.Use AWS Organizations Service Control Policies (SCPs) to enforce the baseline controls.
B.Use AWS Systems Manager Automation to apply the baseline to new accounts.
C.Use AWS CloudFormation StackSets to deploy the baseline stack to new accounts automatically.
D.Use AWS Config aggregators to apply the baseline controls to new accounts.
AnswerC

CloudFormation StackSets with service-managed permissions deploy stacks automatically to accounts as AWS Organizations adds them, satisfying the requirement that new accounts inherit baseline controls without manual intervention. Unlike account-creation triggers or Control Tower, StackSets directly targets the organisational unit, ensuring CloudTrail and Config rules land immediately on joining.

Why this answer

AWS CloudFormation StackSets can automatically deploy a common baseline stack (containing CloudTrail, AWS Config rules, and other security controls) to all accounts in an AWS Organization, including new accounts as they are added. This approach ensures consistent, automated deployment of infrastructure-as-code across the entire organization without manual intervention.

Exam trap

The trap here is confusing SCPs (which only restrict permissions) with actual resource deployment mechanisms, leading candidates to incorrectly choose Option A because they think SCPs can 'enforce' the presence of services like CloudTrail.

How to eliminate wrong answers

Option A is wrong because Service Control Policies (SCPs) are used to define permission boundaries and restrict actions, not to deploy or enable services like CloudTrail or AWS Config rules; SCPs cannot create resources or enable services. Option B is wrong because AWS Systems Manager Automation is designed for operational tasks on existing instances or accounts, not for automatically provisioning baseline resources across new accounts as they join an organization. Option D is wrong because AWS Config aggregators only collect and aggregate compliance data from multiple accounts and regions; they do not deploy or enable Config rules or other security controls.

51
MCQmedium

A company has a centralized logging account that receives VPC flow logs from all accounts. The logs are stored in an S3 bucket. The security team needs to analyze these logs to detect anomalous traffic patterns. Which solution provides the most cost-effective and scalable analysis?

A.Use Amazon QuickSight to create dashboards from the flow logs.
B.Use Amazon Athena to run SQL queries directly on the S3 bucket containing the flow logs.
C.Set up Amazon Kinesis Data Analytics to process the flow logs in real time.
D.Load the flow logs into Amazon Redshift and run SQL queries.
AnswerB

Athena is serverless and queries data in place in Amazon S3, so there is no cluster to provision or data to load. Cost scales with bytes scanned, making it both scalable and cost-effective for analysing accumulated VPC flow logs.

Why this answer

Amazon Athena is the most cost-effective and scalable solution because it allows querying VPC flow logs directly in S3 using standard SQL without requiring data loading or infrastructure management. Athena's serverless, pay-per-query model eliminates idle costs and scales automatically to handle any volume of log data, making it ideal for ad-hoc security analysis of historical logs.

Exam trap

The trap here is that candidates may choose Redshift or Kinesis because they associate 'analysis' with traditional data warehouses or real-time processing, overlooking that Athena's serverless, pay-per-query model is the most cost-effective and scalable for ad-hoc SQL analysis of data already in S3.

How to eliminate wrong answers

Option A is wrong because Amazon QuickSight is a visualization tool that requires a data source; it cannot directly analyze raw VPC flow logs in S3 without an intermediate query engine like Athena, and it incurs per-session costs that are not optimal for ad-hoc analysis. Option C is wrong because Amazon Kinesis Data Analytics processes streaming data in real time, which is unnecessary and more expensive for analyzing historical VPC flow logs already stored in S3; the requirement is for batch analysis of stored logs, not real-time processing. Option D is wrong because loading VPC flow logs into Amazon Redshift involves data ingestion, storage, and compute costs even when not querying, and it requires cluster management, making it less cost-effective and more complex than Athena's serverless approach for this use case.

52
MCQhard

A multinational corporation uses AWS Organizations to manage multiple accounts across different geographic regions. The company needs to ensure that all data residing in AWS accounts for a specific country remains within that country's boundaries. Which combination of AWS services and features should the company use to enforce this data residency requirement?

A.Use AWS PrivateLink and VPC endpoints to keep traffic within the country's region.
B.Use service control policies (SCPs) to deny actions in non-approved regions and AWS Config rules to audit compliance.
C.Use resource-based policies on all AWS resources to deny access from other regions.
D.Use AWS WAF and AWS Shield to protect data and enforce geographic restrictions.
AnswerB

SCPs deny API actions in non-approved regions, preventing data from being created or stored outside the country's boundary. AWS Config rules continuously audit resource placement for compliance. This combination enforces residency preventively and detectively, satisfying the geographic restriction requirement.

Why this answer

Service control policies (SCPs) in AWS Organizations allow you to centrally control the maximum available permissions for all accounts in the organization. By creating an SCP that explicitly denies all actions in non-approved regions, you can enforce that no resources can be created or modified outside the allowed region. AWS Config rules then provide ongoing compliance auditing by detecting and reporting any resources that violate the data residency policy, ensuring continuous enforcement and visibility.

Exam trap

The trap here is that candidates often confuse network-level controls (like PrivateLink or VPC endpoints) with governance-level controls (like SCPs), mistakenly believing that restricting network traffic is sufficient to enforce data residency, when in fact only SCPs can prevent resource creation in disallowed regions at the API level.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink and VPC endpoints keep network traffic within the AWS network and can restrict traffic to a specific region, but they do not prevent users or services from creating resources in other regions; they only control data plane traffic, not the control plane actions that create resources. Option C is wrong because resource-based policies (e.g., S3 bucket policies, IAM role trust policies) can restrict access based on source IP or VPC endpoint, but they cannot deny the creation of resources in other regions; they only control access to existing resources, not the provisioning of new ones. Option D is wrong because AWS WAF and AWS Shield are security services focused on protecting web applications from common exploits and DDoS attacks; they do not provide any mechanism to enforce geographic data residency or restrict resource creation to specific regions.

53
MCQmedium

A company has a centralized network account that hosts a transit gateway with attachments to multiple VPCs in different accounts. The security team needs to ensure that all traffic between VPCs is inspected by a centralized NGFW appliance in the network account. What is the MOST efficient solution?

A.Use AWS PrivateLink to route traffic through the NGFW.
B.Create a transit gateway with a route table that includes a blackhole route for inter-VPC traffic, and attach an inspection VPC with the NGFW.
C.Establish VPC peering connections between all VPCs and route traffic through the inspection VPC.
D.Set up AWS Direct Connect between all VPCs and the inspection VPC.
AnswerB

This forces all inter-VPC traffic to go through the inspection VPC.

Why this answer

It uses a transit gateway with a centralized inspection VPC, which allows all inter-VPC traffic to be routed through the NGFW appliance. By attaching the inspection VPC to the transit gateway and configuring route tables with blackhole routes for direct inter-VPC traffic, traffic is forced to traverse the NGFW for inspection. This is the most efficient and scalable solution for centralized traffic inspection across multiple VPCs in different accounts.

Exam trap

The trap here is that candidates often assume VPC peering (Option C) can be used for transitive routing, but VPC peering does not support transitive routing, making it impossible to route traffic through an inspection VPC to other VPCs.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink is designed for private connectivity to services via Network Load Balancers, not for routing inter-VPC traffic through a centralized NGFW; it does not support transitive routing or traffic inspection between VPCs. Option C is wrong because VPC peering does not support transitive routing, so you cannot route traffic from one peered VPC through another VPC to reach a third VPC; this would require a full mesh of peering connections and complex route tables, which is inefficient and not scalable. Option D is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not a solution for routing traffic between VPCs; it does not provide inter-VPC routing capabilities and would add unnecessary cost and complexity.

54
Multi-Selecthard

A company is designing a multi-account strategy for its development teams. Each team needs to have its own isolated environment with VPCs, subnets, and security groups. The company wants to centralize network administration and ensure that all VPCs use a common set of security rules. Which THREE steps should the company take? (Choose THREE.)

Select 3 answers
A.Allow each team to create their own VPCs and use VPC Peering to connect them.
B.Deploy a centralized inspection VPC with AWS Network Firewall and use Transit Gateway to route traffic.
C.Create a dedicated network account and use AWS Resource Access Manager to share subnets with other accounts.
D.Use AWS CloudFormation StackSets to deploy identical VPCs to each account.
E.Use AWS Firewall Manager to apply common security group rules across all accounts.
AnswersB, C, E

A centralised inspection VPC with AWS Network Firewall enforces one common rule set across every team's VPC, satisfying the requirement for shared security rules. Transit Gateway hubs the isolated VPCs together, letting traffic route through that inspection point while network administration stays centralised.

Why this answer

Option B is correct because a centralized inspection VPC with AWS Network Firewall, combined with AWS Transit Gateway for routing, provides centralized traffic inspection and a hub-and-spoke topology that enforces common security policy across all team VPCs. Option C is correct because a dedicated network account using AWS Resource Access Manager (RAM) to share subnets lets teams consume centrally managed VPC networking while keeping network administration centralized. Option E is correct because AWS Firewall Manager applies common security group rules (and other policies) across all accounts in AWS Organizations, ensuring uniform security rules.

Option A is not correct because VPC Peering is a point-to-point connection that does not scale for centralized administration or common security enforcement across many accounts. Option D is not correct because CloudFormation StackSets deploys identical VPCs per account, which duplicates network administration rather than centralizing it and does not enforce common security rules.

Exam trap

The trap here is that candidates may confuse AWS CloudFormation StackSets (which only automates resource deployment) with centralized security enforcement, overlooking the need for a hub-and-spoke architecture with a centralized inspection point like AWS Network Firewall and Transit Gateway.

55
MCQmedium

A company manages multiple AWS accounts using AWS Organizations. The security team needs to enforce that all newly created accounts automatically have a specific set of security controls, including AWS Config rules and an AWS CloudTrail trail. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS Config conformance packs to deploy rules across accounts.
B.Use AWS Lambda functions triggered by AWS CloudTrail events to create a new stack in each new account.
C.Use AWS Organizations with AWS CloudFormation StackSets to automatically deploy the security stack to new accounts.
D.Use AWS Service Catalog to create a portfolio that includes the security stack and grant access to new accounts.
AnswerC

StackSets with service-managed permissions automatically deploys the CloudFormation template containing Config rules and the CloudTrail trail to each new account as it joins the organisation. This satisfies the automatic enforcement requirement with minimal ongoing manual effort.

Why this answer

AWS Organizations integrates directly with AWS CloudFormation StackSets to automatically deploy stacks across accounts in an organization. By configuring StackSets with automatic deployment enabled, any new account added to the organization will automatically receive the specified security stack (including AWS Config rules and CloudTrail trail) without any manual intervention or additional orchestration. This approach minimizes operational overhead by leveraging native AWS automation.

Exam trap

The trap here is that candidates often confuse AWS Config conformance packs (which only handle Config rules) with the broader infrastructure deployment capability of CloudFormation StackSets, leading them to choose Option A even though it cannot deploy CloudTrail trails.

How to eliminate wrong answers

Option A is wrong because AWS Config conformance packs only deploy AWS Config rules and remediation actions, but they cannot deploy an AWS CloudTrail trail, which is a separate service requiring a stack or custom resource. Option B is wrong because using Lambda functions triggered by CloudTrail events to create stacks introduces additional complexity, latency, and potential failure points compared to the native StackSets automatic deployment feature; it also requires managing Lambda code, IAM roles, and event rules. Option D is wrong because AWS Service Catalog portfolios require users to manually launch products from the portfolio; they do not automatically deploy stacks to new accounts, so this would not meet the requirement for automatic enforcement.

56
MCQmedium

A company manages multiple AWS accounts and wants to centralize billing and cost tracking. They have enabled AWS Organizations and consolidated billing. Which additional step should they take to gain granular visibility into costs per department?

A.Enable AWS Cost Explorer and use default groupings
B.Create AWS Budgets for each department
C.Implement cost allocation tags for resources and use AWS Cost Explorer to filter by tags
D.Use the consolidated billing feature to view costs per account
AnswerC

Cost allocation tags attach department metadata to resources, letting AWS Cost Explorer group and filter spend by that dimension. This satisfies the granular per-department visibility requirement, which consolidated billing alone cannot provide, since it aggregates charges at the account level rather than by organisational unit.

Why this answer

Cost allocation tags allow you to tag AWS resources with department-specific metadata (e.g., 'Department: Engineering'). Once enabled and activated in the Billing and Cost Management console, AWS Cost Explorer can filter and group costs by these tags, providing granular visibility into per-department spending across multiple accounts in an AWS Organization. This approach directly addresses the need for department-level cost tracking beyond the account-level view provided by consolidated billing.

Exam trap

The trap here is that candidates often confuse the account-level aggregation of consolidated billing (Option D) with the resource-level granularity needed for department tracking, or they assume AWS Budgets (Option B) provide visibility rather than just alerts.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer's default groupings (e.g., by service or linked account) do not provide department-level granularity unless custom tags or cost categories are used; relying on default groupings alone cannot break down costs by department. Option B is wrong because AWS Budgets are used to set spending thresholds and send alerts, not to provide granular visibility into historical or current cost breakdowns by department; they are a cost control mechanism, not a reporting or analysis tool. Option D is wrong because the consolidated billing feature aggregates costs at the account level, not at the department level; it cannot distinguish costs for resources within a single account that belong to different departments.

57
MCQhard

A healthcare company has 200 AWS accounts in AWS Organizations. The security team wants to prevent any principal in member accounts from disabling AWS CloudTrail or deleting the organization trail, even if they have administrator permissions in their own account. The solution must be centrally managed and apply to all existing and future accounts. Which approach should a solutions architect recommend?

A.Create an IAM permission boundary in each member account that denies CloudTrail management actions for all IAM principals.
B.Use AWS CloudTrail Lake in the management account and grant member accounts read-only access to the event data store.
C.Create an organization trail in the management account and attach a service control policy that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail to all member accounts.
D.Enable CloudTrail in each member account and use AWS Config rules to detect and remediate trails that are stopped or deleted.
AnswerC

An organization trail applies to all accounts in the organization and cannot be modified by member accounts. Pairing it with an SCP that denies the destructive CloudTrail actions ensures that even account administrators cannot stop or delete logging. This combination provides centralized, tamper-resistant logging across current and future accounts.

Why this answer

The most reliable way to prevent CloudTrail tampering across an organization is to use an organization trail, which member accounts cannot alter, combined with an SCP that denies the specific destructive CloudTrail API actions. This is preventive and applies uniformly to all accounts. Detective Config rules, CloudTrail Lake analytics, and per-account permission boundaries do not provide the same centralized prevention.

Exam trap

The trap here is choosing a detective control such as AWS Config remediation when the requirement explicitly asks to prevent administrators from disabling logging, which demands a preventive control like an SCP plus an organization trail.

58
MCQmedium

A multinational corporation is migrating its on-premises Active Directory (AD) to AWS Managed Microsoft AD. The company has a hub-and-spoke VPC topology with a central transit gateway. The AD domain controllers must be deployed in two different AWS Regions for disaster recovery. The corporate security policy requires that all AD traffic between Regions must traverse the transit gateway and be inspected by a third-party firewall appliance deployed in the inspection VPC. Which architecture meets these requirements?

A.Deploy AD in two Regions and use a VPN connection between the VPCs to replicate data.
B.Deploy a single AD domain in one Region and use AD replication over a VPC peering connection to a second Region.
C.Deploy AD in two Regions, attach both VPCs to the transit gateway, and enable cross-Region transit gateway peering. Use route tables to direct AD traffic through the inspection VPC.
D.Deploy AD in two Regions, attach both VPCs to a transit gateway in the primary Region, and use a transit gateway inter-Region peering attachment. Configure route tables to force traffic through the inspection VPC in the primary Region.
AnswerC

Cross-Region transit gateway peering carries AD replication traffic between the two Regional directories, while transit gateway route tables in each Region force that traffic through the inspection VPC attachment, satisfying the security policy's inspection mandate. AWS Managed Microsoft AD domain controllers stay Regional, so DR is met without exposing replication to the public internet.

Why this answer

It uses cross-Region transit gateway peering, which allows VPCs in different Regions to communicate through their respective transit gateways. By attaching both VPCs to their local transit gateways and peering those gateways, you can configure route tables to force AD traffic through the inspection VPC in one Region, satisfying the firewall inspection requirement. Option D is incorrect because you cannot attach a VPC in a secondary Region to a transit gateway in the primary Region; transit gateway attachments are regional.

Exam trap

The trap is that candidates may think you can attach VPCs from different Regions to a single transit gateway, but in reality, transit gateway attachments are regional. Cross-Region connectivity requires transit gateway peering.

How to eliminate wrong answers

Option A is wrong because a VPN connection between VPCs does not provide the required transit gateway routing or inspection VPC integration; it also introduces additional latency and complexity without meeting the inspection requirement. Option B is wrong because a single AD domain with VPC peering does not support cross-Region AD replication natively (AD replication requires direct connectivity or VPN, and VPC peering alone cannot enforce inspection by a third-party firewall in a separate inspection VPC). Option C is wrong because attaching both VPCs to the transit gateway and enabling cross-Region transit gateway peering does not force AD traffic through the inspection VPC; route tables must be explicitly configured to direct traffic through the inspection VPC, and the description in C lacks the necessary detail about routing through the inspection VPC in the primary Region.

59
Multi-Selectmedium

A company uses AWS Organizations and wants to centrally manage Amazon GuardDuty across all accounts. Which TWO steps are required to enable GuardDuty in all accounts from a single management account?

Select 2 answers
A.Use AWS CloudFormation StackSets to deploy GuardDuty in each account
B.Enable GuardDuty manually in each member account by logging into each account
C.Create a service control policy to force GuardDuty to be enabled
D.Use the GuardDuty delegated administrator account to enable GuardDuty for all accounts in the organization
E.Designate a member account as the GuardDuty delegated administrator
AnswersD, E

Designating a delegated administrator in GuardDuty lets that account enable and manage the service across every member account via AWS Organizations integration, satisfying the centralised single-account management constraint. The management account itself cannot serve as the GuardDuty delegated administrator, so a member account must be registered first.

Why this answer

The correct answers are E and D. First, you must designate a member account as the GuardDuty delegated administrator (option E) using the Organizations management account, which grants that account administrative authority over GuardDuty for the entire organization. Then, from that delegated administrator account, you enable GuardDuty for all accounts in the organization (option D), which automatically enables GuardDuty in every existing and newly added member account.

Option A is incorrect because CloudFormation StackSets is not the mechanism GuardDuty uses for organization-wide enablement. Option B is incorrect because manual per-account enablement defeats the purpose of centralized management. Option C is incorrect because service control policies restrict permissions and cannot force a service like GuardDuty to be enabled.

Exam trap

The trap here is that candidates often confuse service control policies (SCPs) with proactive enforcement, but SCPs only restrict permissions and cannot automatically enable a service; they also overlook that CloudFormation StackSets cannot enable a service like GuardDuty, which requires a specific API action rather than resource deployment.

60
MCQeasy

A company has a multi-account AWS environment managed with AWS Organizations. The finance team wants to consolidate billing and receive a single bill for all accounts, while still allowing each account to have its own service usage and cost allocation tags. The company also wants to apply volume discounts across accounts. Which AWS Organizations feature should the solutions architect enable?

A.Enable consolidated billing for the organization so that all accounts are billed through the management account and share volume pricing benefits.
B.Create a separate AWS account for each business unit and use AWS Cost Explorer to manually combine the bills each month.
C.Enable AWS Budgets in each account and configure budget alerts to be sent to the finance team for a unified view.
D.Use AWS Cost and Usage Reports delivered to a central S3 bucket to generate a single invoice for all accounts.
AnswerA

Consolidated billing is an AWS Organizations feature that rolls all member account charges into a single bill paid by the management account. It also aggregates usage for volume discounts and Reserved Instance and Savings Plans sharing. This directly meets the requirements for a single bill, per-account usage tracking, and shared discounts.

Why this answer

Consolidated billing in AWS Organizations aggregates all member account charges into one bill paid by the management account. It also shares volume pricing, Reserved Instance, and Savings Plans benefits across accounts. This satisfies the requirements for a single bill, per-account usage visibility, and cross-account discounts with minimal effort.

Exam trap

The trap here is confusing cost visibility tools such as AWS Cost Explorer, AWS Budgets, or Cost and Usage Reports with consolidated billing, which is the Organizations feature that actually produces one bill and shares discounts.

61
Multi-Selectmedium

A company is managing multiple AWS accounts using AWS Organizations. They want to centralize the management of EC2 instances and enforce tagging standards across all accounts. Which TWO approaches should they use?

Select 2 answers
A.Use AWS CloudFormation StackSets to deploy AWS Config rules across all accounts to check for required tags.
B.Use AWS Service Catalog to enforce tagging on EC2 products.
C.Use AWS Resource Access Manager to share a tagging policy across accounts.
D.Apply a service control policy (SCP) that denies ec2:RunInstances if the required tags are not specified.
E.Use EC2 Auto Scaling lifecycle hooks to add tags automatically.
AnswersA, D

AWS Config rules deployed via CloudFormation StackSets provide continuous, account-wide tag compliance evaluation, satisfying the requirement to enforce tagging standards centrally. StackSets handle cross-account deployment through AWS Organizations, while Config detects non-compliant EC2 instances and can trigger remediation, giving the governance mechanism the scenario demands.

Why this answer

Option A is correct because CloudFormation StackSets can deploy AWS Config rules (e.g., required-tags) across all accounts in an AWS Organization from a single administrator account, providing centralized, continuous detection of non-compliant EC2 instances and their tags. Option D is correct because an SCP attached to the organization's root or OUs can enforce tagging standards preventively by denying ec2:RunInstances when the required tag keys/values are absent (using conditions such as aws:RequestTag and aws:TagKeys), blocking non-compliant launches across all member accounts. Option B is not correct because Service Catalog constraints (e.g., TagOptions) only apply to products launched through the catalog, not to all EC2 instances across accounts.

Option C is not correct because AWS Resource Access Manager shares resources such as subnets, Transit Gateways, and Route 53 Resolver rules, not tagging policies. Option E is not correct because Auto Scaling lifecycle hooks pause instances during launch/termination for custom actions and do not enforce or automatically add tags to meet organization-wide tagging standards.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog's tagging enforcement as a global solution, not realizing it only applies to products launched through the catalog, not to direct EC2 API calls across accounts.

62
MCQmedium

A company has multiple AWS accounts and wants to centrally manage VPC flow logs for all accounts. The flow logs should be sent to a central S3 bucket in the logging account. The solution must be automated for new accounts added to the organization. What should the team do?

A.Use AWS Config rules to detect missing flow logs and send alerts to the security team.
B.Use AWS CloudFormation StackSets to deploy a VPC flow log configuration to all accounts and regions, and configure the S3 bucket policy to allow cross-account delivery from all accounts.
C.Use an SCP to require that VPC flow logs be enabled.
D.Manually enable VPC flow logs in each account and region, and specify the central S3 bucket as the destination.
AnswerB

StackSets deploys the flow log configuration across every account and Region from one administration account, and automatically targets accounts newly added to the organisation. The central S3 bucket policy grants cross-account delivery, meeting the automation requirement without per-account manual setup.

Why this answer

AWS CloudFormation StackSets can deploy a VPC flow log configuration across multiple accounts and regions in an AWS Organization, and the central S3 bucket policy must allow cross-account delivery from all accounts. This approach automates the deployment for new accounts as they are added to the organization, meeting the requirement for centralized management and automation.

Exam trap

The trap here is that candidates may think SCPs can enforce resource configurations like enabling flow logs, but SCPs only control permissions and cannot create or configure resources; they must be combined with automation tools like StackSets or AWS Config rules with auto-remediation.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect missing flow logs and send alerts, but they do not automatically enable flow logs or deliver them to a central S3 bucket; they only provide compliance monitoring and notifications. Option C is wrong because Service Control Policies (SCPs) can restrict actions but cannot directly enable VPC flow logs or configure their delivery to a central S3 bucket; SCPs are for permission boundaries, not resource configuration. Option D is wrong because manually enabling flow logs in each account and region is not automated and does not scale for new accounts added to the organization, violating the automation requirement.

63
Multi-Selectmedium

A company is designing a centralized logging solution for multiple AWS accounts. The solution must meet compliance requirements that logs be immutable and stored for 7 years. Which THREE services should be combined to achieve this?

Select 3 answers
A.AWS Glue
B.S3 Object Lock
C.AWS CloudTrail
D.Amazon S3
E.Amazon Kinesis Data Streams
AnswersB, C, D

S3 Object Lock in compliance mode prevents any user, including the root account, from deleting or overwriting objects for a defined retention period. This directly satisfies the immutability requirement, and combined with lifecycle policies it enforces the seven-year retention window.

Why this answer

Amazon S3 (D) is the correct storage foundation because it provides durable, highly available object storage where the aggregated logs from all accounts can reside for the 7-year retention period. S3 Object Lock (B) is correct because it enforces WORM (write once, read many) immutability, using retention modes such as Compliance mode to prevent deletion or modification of log objects for the required duration. AWS CloudTrail (C) is correct because it captures API activity and account events across multiple AWS accounts, and with an organization trail it can deliver those logs centrally to the S3 bucket for compliance auditing.

AWS Glue (A) is a serverless ETL/catalog service used for data preparation and transformation, not for immutable log retention, so it does not satisfy the requirement. Amazon Kinesis Data Streams (E) is a real-time streaming ingestion service and does not itself provide immutable, 7-year storage, so it is not part of the required combination.

Exam trap

The trap here is that candidates may confuse Kinesis Data Streams as a storage service for logs, but it is a streaming ingestion layer with no built-in immutability or long-term retention, while Glue is mistakenly chosen for its data cataloging capabilities rather than for log storage.

64
MCQeasy

A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to prevent member accounts from disabling AWS CloudTrail or modifying its configuration. They also want to ensure that all CloudTrail logs are stored in a central S3 bucket in the management account. Which combination of actions should be taken?

A.Create an IAM policy in each member account that denies CloudTrail modification actions to all users, and enable CloudTrail in each account with a trail that delivers to a central S3 bucket.
B.Use AWS Config rules in each member account to detect and remediate any changes to CloudTrail configuration. Store logs in a central S3 bucket by configuring each account's trail to deliver to the bucket.
C.Enable AWS CloudTrail in the management account with organization trail, and use AWS Organizations to apply a tag policy that prevents member accounts from modifying CloudTrail.
D.Apply a service control policy (SCP) to all member accounts that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail. Configure CloudTrail in the management account to log all accounts and deliver to a central S3 bucket.
AnswerD

SCPs can deny specific CloudTrail actions in member accounts, preventing them from stopping or modifying trails. By configuring an organization trail in the management account, CloudTrail logs from all accounts are automatically delivered to a central S3 bucket. This meets the requirements for centralized logging and protection against tampering, with minimal operational overhead.

Why this answer

Service control policies (SCPs) in AWS Organizations can deny CloudTrail modification actions across member accounts, providing a preventive control. An organization trail created in the management account automatically logs activity in all accounts and delivers to a central S3 bucket. This combination ensures centralized, tamper-resistant logging without per-account configuration.

Exam trap

The trap here is assuming that AWS Config rules or IAM policies can prevent CloudTrail modifications, but only SCPs provide centralized, preventive control that member accounts cannot override.

65
Multi-Selectmedium

Which TWO actions should a company take to implement a least-privilege access model across multiple AWS accounts? (Choose TWO.)

Select 2 answers
A.Use IAM roles in each account with cross-account trust from a central identity provider, granting only required permissions.
B.Apply SCPs to deny high-risk actions across all accounts.
C.Generate long-term access keys for each user in the central account.
D.Share the root user credentials of each account with the central team.
E.Create IAM users in each account with full administrator access for all users.
AnswersA, B

Cross-account IAM roles with trust policies let identities federate from a central provider and assume only scoped permissions in each account, eliminating long-lived credentials. This directly enforces least privilege across accounts by granting the minimum required permissions per role.

Why this answer

Option A is correct because IAM roles with cross-account trust let users assume temporary credentials from a central identity provider (e.g., AWS IAM Identity Center or an external IdP via STS AssumeRole), so each account grants only the specific permissions the role needs, which is the essence of least privilege. Option B is correct because AWS Organizations service control policies (SCPs) set a permissions guardrail that denies high-risk actions (such as disabling CloudTrail or leaving the organization) across all member accounts, preventing privilege escalation even if an identity policy would otherwise allow it. Option C is wrong because generating long-term access keys for every user violates least privilege and key-rotation best practices; temporary credentials via roles are preferred.

Option D is wrong because sharing root user credentials is a severe security anti-pattern—root has unrestricted access and should be protected with MFA and never shared. Option E is wrong because creating IAM users with full administrator access in every account grants excessive permissions and directly contradicts a least-privilege model.

Exam trap

The trap here is that candidates often confuse SCPs with IAM permissions policies, thinking SCPs grant access rather than acting as a deny-only guardrail, or they mistakenly believe long-term access keys or shared root credentials are acceptable for cross-account access when they are explicitly anti-patterns for least-privilege.

66
MCQeasy

A company has a single AWS account and wants to implement a multi-account strategy using AWS Organizations. They need to centrally manage billing and apply policies to restrict which AWS services can be used in each account. The company also wants to ensure that new accounts automatically inherit these restrictions. Which step should they take first to set up AWS Organizations with these capabilities?

A.Create an organization from the management account, then create organizational units (OUs) and service control policies (SCPs) that define the allowed services, and attach the SCPs to the OUs.
B.Enable AWS Control Tower in the management account, which automatically creates OUs and SCPs. Then, customize the SCPs to restrict services.
C.Use AWS Resource Access Manager to share resources between accounts, and use AWS Config rules to enforce service restrictions.
D.Create a new AWS account for each business unit, then use AWS IAM policies in each account to restrict services. Link the accounts for consolidated billing.
AnswerA

Creating an organization from the management account is the foundational step. Then, organizing accounts into OUs and attaching SCPs to those OUs allows centralized policy enforcement. New accounts placed in an OU automatically inherit the SCPs, meeting the requirement for automatic restriction.

Why this answer

To set up AWS Organizations with centralized policy enforcement, the first step is to create the organization from the management account. Then, define OUs and SCPs to restrict services, and attach SCPs to OUs so that accounts inherit them automatically. This provides the required billing consolidation and policy control.

Exam trap

The trap here is thinking that AWS Control Tower must be used to create an organization, when in fact AWS Organizations can be created directly and SCPs applied without Control Tower.

67
MCQhard

A company has a multi-account AWS environment with a central security account. The security team needs to audit all API activity across all accounts and retain the logs for 7 years in a tamper-evident manner. They also need to ensure that no account administrator can disable or modify the logging configuration. Which solution meets these requirements?

A.Use AWS CloudTrail Lake to aggregate all events, set a retention period of 7 years, and use AWS KMS to encrypt the event data store.
B.Enable AWS Config in all accounts to record API activity, deliver snapshots to a central S3 bucket, and use AWS Config rules to monitor changes.
C.Create individual trails in each account, deliver logs to a central S3 bucket, enable versioning and MFA delete on the bucket, and use IAM policies to restrict access to the bucket.
D.Create an organization trail in AWS CloudTrail that applies to all accounts, deliver logs to a central S3 bucket in the security account, enable S3 Object Lock in compliance mode, and use SCPs to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail.
AnswerD

An organization trail automatically applies to all accounts in the organization and delivers logs to a central S3 bucket. S3 Object Lock in compliance mode prevents deletion or modification of log objects for the retention period. SCPs deny actions that could disable logging. This combination provides centralized, tamper-evident logging with long-term retention and protection against administrative interference.

Why this answer

An organization trail in CloudTrail centralizes logging across all accounts, delivering to a central S3 bucket. S3 Object Lock in compliance mode ensures logs cannot be deleted or altered for the retention period, meeting tamper-evident requirements. SCPs prevent member accounts from stopping or deleting the trail.

This solution provides the necessary audit coverage, retention, and protection against administrative tampering.

Exam trap

The trap here is assuming that CloudTrail Lake or AWS Config can replace a properly configured organization trail with S3 Object Lock for tamper-evident auditing.

68
MCQhard

A company is using AWS Organizations with a set of member accounts that need to access a shared Amazon S3 bucket in the master account. The bucket policy allows access only from the member accounts' root user. However, developers in member accounts are unable to access the bucket even when they assume an IAM role. What is the most likely cause?

A.The bucket is encrypted with an AWS KMS key that the role does not have permissions to use.
B.The bucket policy requires an explicit Deny for all principals except the root user.
C.A service control policy (SCP) is denying access to the S3 bucket.
D.The bucket policy grants access to the member account root user ARN, but the role session has a different ARN.
AnswerD

Resource-based policies match the exact principal ARN. Granting access to the account root ARN does not cover an assumed role session, whose ARN is arn:aws:sts::account:assumed-role/role/session. The policy must name the role or account principal explicitly.

Why this answer

The bucket policy explicitly grants access to the member account's root user ARN (e.g., `arn:aws:iam::123456789012:root`). When a developer assumes an IAM role in the member account, the resulting session has a different ARN (e.g., `arn:aws:sts::123456789012:assumed-role/DevRole/session`). Because the bucket policy's Principal is restricted to the root user ARN, the role session is not recognized as a matching principal, and access is denied.

This is a common misconfiguration when mixing root user grants with assumed-role access.

Exam trap

The trap here is that candidates often assume that granting access to a member account's root user automatically grants access to all IAM users and roles in that account, but in reality, root user ARN is a specific principal that does not cover assumed-role sessions or IAM users unless explicitly included.

How to eliminate wrong answers

Option A is wrong because the question states the bucket policy allows access only from the member accounts' root user, and there is no mention of KMS encryption or a KMS key permission issue; the problem is purely about principal matching in the bucket policy. Option B is wrong because an explicit Deny for all principals except the root user would still not allow the role session to access the bucket, but the question describes a bucket policy that 'allows access only from the member accounts' root user' — this is an Allow with a specific principal, not an explicit Deny, and the core issue is the principal mismatch, not an explicit Deny statement. Option C is wrong because while an SCP could deny access, the question asks for the 'most likely cause' given the specific bucket policy configuration; the direct and most common cause is the principal mismatch between the root user ARN in the policy and the assumed-role ARN used by the developers.

69
MCQmedium

A multinational company is adopting AWS Organizations to manage multiple accounts across business units. The security team requires that specific IAM roles be automatically deployed to all existing and future member accounts. Which solution should the company use?

A.Use AWS Config rules to enforce the role creation in each account.
B.Use AWS CloudFormation StackSets with automatic deployment enabled in the organization.
C.Use AWS Service Catalog to create a portfolio with the IAM role product and share it with all accounts.
D.Use AWS Lambda functions triggered by AWS CloudTrail events to create the role in each account.
AnswerB

CloudFormation StackSets with automatic deployment targets an organisation or OU, so the required IAM roles are provisioned into every existing account and any account added later. This satisfies the automatic deployment requirement for both current and future member accounts.

Why this answer

AWS CloudFormation StackSets with automatic deployment enabled allows you to deploy IAM roles across all accounts in an AWS Organization, including future accounts, by specifying the organization root or OUs as targets. This ensures consistent role creation without manual intervention, as StackSets automatically provisions stacks in new accounts as they join the organization.

Exam trap

The trap here is that candidates often confuse AWS Config's remediation actions with direct resource creation, or they assume Service Catalog's sharing mechanism automatically deploys resources, when in fact only CloudFormation StackSets with automatic deployment provides native, organization-wide, and future-proof resource deployment.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are for evaluating resource compliance, not for creating or deploying resources; they can trigger remediation actions via Lambda or Systems Manager, but they do not directly create IAM roles across accounts. Option C is wrong because AWS Service Catalog allows users to provision products from a portfolio, but it does not automatically deploy roles to all accounts; it requires users to manually launch the product in each account. Option D is wrong because while Lambda functions triggered by CloudTrail events could create roles, this approach is event-driven and reactive, requiring custom code and handling for future accounts, and lacks the native, automated, and scalable deployment mechanism that StackSets provides for organizations.

70
Matchingmedium

Match each AWS service to its primary use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Centrally manage multiple AWS accounts

Connect VPCs and on-premises networks

Dedicated private network connection to AWS

Secure connection over the internet to AWS

Privately access services across VPCs

Why these pairings

Correct matches: AWS Organizations for account management, AWS Direct Connect for dedicated private connection, AWS VPN for encrypted internet connection, AWS Transit Gateway for hub-and-spoke network interconnection. Common confusions include swapping Direct Connect and VPN, or misattributing account management to networking services.

71
MCQmedium

A company is deploying a multi-account AWS environment using AWS Organizations. The security team requires that all Amazon S3 buckets in member accounts are encrypted with AWS KMS customer managed keys, and that the keys are created and managed centrally in a security account. Which solution should a solutions architect recommend?

A.Create KMS keys in each member account and use AWS CloudFormation StackSets to deploy bucket policies that enforce their use.
B.Use AWS Secrets Manager to store KMS key material centrally and grant member accounts access to the secret.
C.Enable default encryption on all S3 buckets using SSE-S3 and use AWS Config to monitor compliance.
D.Create KMS keys in the security account and grant member accounts permission to use them via key policies and IAM policies. Use an S3 bucket policy in each member account to enforce encryption with the central key.
AnswerD

Centralizing KMS keys in the security account with cross-account key policies allows member accounts to use the keys for S3 encryption while keeping key management centralized. S3 bucket policies in member accounts can enforce that all PUT requests use the specified KMS key, satisfying the encryption requirement.

Why this answer

Creating KMS keys in a central security account and sharing them with member accounts via key policies and IAM policies keeps key management centralized. Enforcing encryption with those keys through S3 bucket policies in each member account ensures all buckets use the approved keys, meeting both the central management and encryption requirements.

Exam trap

The trap here is confusing SSE-S3 with SSE-KMS, or assuming that default encryption alone enforces the use of a specific customer managed key.

72
MCQmedium

A company has multiple AWS accounts managed via AWS Organizations. The security team requires that all S3 buckets across all accounts must block public access. How can this be enforced centrally with minimal operational overhead?

A.Enable AWS Config in each account and create a rule to mark public buckets as non-compliant.
B.Create an IAM role in each account with a policy that denies public access modifications and assign it to all users.
C.Use a bucket policy on each existing bucket to deny public access and rely on AWS Config to detect new buckets.
D.Create a service control policy (SCP) to deny s3:PutBucketPublicAccessBlock actions with conditions that require public access block settings.
AnswerD

SCPs can centrally enforce restrictions across all accounts in the organization.

Why this answer

An SCP applied at the AWS Organizations root or OU level can centrally deny the `s3:PutBucketPublicAccessBlock` action unless the request includes specific public access block settings. This enforces the security requirement across all accounts without per-account configuration, minimizing operational overhead. SCPs are the only mechanism that can prevent actions at the account level before they occur, making them ideal for mandatory security baselines.

Exam trap

The trap here is that candidates often choose AWS Config (option A) because it is a common detective control, but they overlook that SCPs are the only preventive control that works centrally across all accounts with zero per-account setup.

How to eliminate wrong answers

Option A is wrong because AWS Config rules only detect and report non-compliant resources after they exist; they do not prevent the creation of public buckets, so operational overhead remains for remediation. Option B is wrong because IAM roles assigned to users cannot prevent actions performed by services (e.g., AWS Lambda, CloudFormation) or root users, and managing roles across many accounts adds significant overhead. Option C is wrong because applying bucket policies to existing buckets is a reactive, per-bucket manual process that does not prevent new public buckets from being created, and AWS Config detection still requires remediation effort.

73
MCQhard

A multinational company is implementing a multi-account strategy using AWS Organizations. The security team needs to ensure that all newly created accounts automatically have a specific baseline CloudTrail trail and a set of AWS Config rules applied. The company also wants to enforce that no account can disable these controls. Which solution should be used?

A.Create an SCP that denies actions to disable CloudTrail and AWS Config, and use AWS CloudFormation StackSets to deploy the baseline resources to all accounts in the organization.
B.Use IAM roles with a trust policy that allows the management account to deploy CloudTrail and AWS Config, and use AWS Lambda to monitor for changes.
C.Use AWS Control Tower to set up the baseline and enforce it via preventive guardrails.
D.Use AWS Organizations to create an SCP that deploys AWS Config rules and CloudTrail via AWS CloudFormation StackSets.
AnswerA

SCPs in AWS Organizations deny the `cloudtrail:StopLogging` and `config:DeleteConfigurationRecorder` actions at the organisation root, so member accounts cannot disable the controls regardless of their own IAM permissions. StackSets then deploys the CloudTrail trail and Config rules automatically to every account, including newly created ones.

Why this answer

It combines an SCP that denies actions to disable CloudTrail and AWS Config (e.g., `cloudtrail:StopLogging`, `config:DeleteConfigRule`) with AWS CloudFormation StackSets to deploy the baseline resources across all accounts in the organization. The SCP enforces that no account (including root users) can disable the controls, while StackSets automatically deploy the CloudTrail trail and Config rules to new accounts as they join the organization. This meets both the automatic deployment and enforcement requirements.

Exam trap

The trap here is that candidates confuse SCPs with deployment mechanisms—SCPs only deny or allow actions, they cannot create resources, so StackSets (or similar) are required for deployment, and Control Tower guardrails are often mistaken for being able to deploy custom resources when they only enforce pre-defined policies.

How to eliminate wrong answers

Option B is wrong because IAM roles with a trust policy from the management account can deploy resources, but they do not prevent accounts from disabling CloudTrail or Config; they only allow the management account to deploy, not enforce. Option C is wrong because AWS Control Tower guardrails can enforce preventive controls (e.g., disallow disabling CloudTrail), but Control Tower does not automatically deploy custom CloudTrail trails or custom Config rules; it only provides pre-defined guardrails and cannot deploy arbitrary baseline resources. Option D is wrong because an SCP cannot deploy resources; SCPs only define permission boundaries and cannot create CloudTrail trails or Config rules—StackSets must be used separately, and the option incorrectly states that the SCP itself deploys the resources.

74
MCQmedium

A company has a multi-account AWS environment and wants to centralize the management of IAM roles. The security team needs to ensure that all IAM roles across all accounts trust the same identity provider (IdP) for federated access. The company uses AWS IAM Identity Center (successor to AWS SSO) for user management. Which solution should be implemented?

A.Use AWS IAM Identity Center to create permission sets that grant access to accounts. IAM Identity Center automatically creates and manages the necessary IAM roles with the IdP trust.
B.Use an SCP to require that all IAM roles trust the corporate IdP.
C.Create IAM roles in each account with a trust policy that allows the corporate IdP.
D.Use AWS CloudFormation StackSets to deploy IAM roles with the IdP trust policy to all accounts.
AnswerA

IAM Identity Center permission sets are provisioned into each account as IAM roles whose trust policy references the Identity Center instance, so every account trusts the same IdP automatically. This centralises role management and satisfies the requirement for uniform federated trust across all accounts.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is designed to centralize user access across multiple AWS accounts. When you create permission sets in IAM Identity Center, it automatically provisions the necessary IAM roles in each target account with a trust policy that trusts the IAM Identity Center's own identity provider. This eliminates the need to manually create or manage IAM roles and their trust policies, ensuring all accounts use the same IdP for federated access.

Exam trap

The trap here is that candidates often confuse SCPs as a mechanism to enforce trust policies, but SCPs cannot modify IAM role trust relationships; they only control the maximum permissions for IAM users and roles within an account.

How to eliminate wrong answers

Option B is wrong because Service Control Policies (SCPs) can restrict permissions but cannot enforce trust policy conditions on IAM roles; SCPs operate at the account level to control which AWS services and actions are allowed, not to modify or mandate the content of IAM role trust policies. Option C is wrong because manually creating IAM roles in each account with a trust policy for the corporate IdP is operationally complex, error-prone, and does not leverage the centralized management capabilities of IAM Identity Center; it also does not automatically synchronize role creation across accounts. Option D is wrong because while AWS CloudFormation StackSets can deploy IAM roles with a specific trust policy to multiple accounts, this approach still requires manual definition and maintenance of the trust policy and does not integrate with IAM Identity Center's automatic role provisioning and lifecycle management.

75
MCQhard

A large enterprise is migrating to AWS and wants to implement a multi-account strategy with centralized network connectivity. The company has multiple VPCs in various accounts that need to communicate with each other and with on-premises resources. The solution must be scalable and minimize operational overhead. Which design should be used?

A.Use AWS PrivateLink to connect VPCs via interface endpoints.
B.Create a VPC peering connection between each pair of VPCs that need to communicate.
C.Set up a VPN connection from each VPC to the on-premises network and use routing to enable inter-VPC communication.
D.Use an AWS Transit Gateway in a central network account and attach all VPCs from the various accounts.
AnswerD

A central Transit Gateway in a network account lets VPCs from many accounts attach as spokes, providing scalable transitive routing to each other and to on-premises via VPN or Direct Connect, with far less operational overhead than per-VPC peering meshes.

Why this answer

AWS Transit Gateway acts as a central hub for interconnecting VPCs and on-premises networks, enabling scalable, low-operational-overhead connectivity across multiple accounts. By placing the Transit Gateway in a central network account and using AWS Resource Access Manager to share it with other accounts, the enterprise can avoid the complexity of managing many individual connections while supporting transitive routing and centralized control.

Exam trap

The trap here is that candidates often confuse AWS PrivateLink (which is for service-to-service communication) with a hub-and-spoke solution, or assume VPC peering can scale linearly, ignoring the lack of transitive routing and the operational burden of managing a full mesh.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink is designed for private access to specific services or endpoints, not for transitive routing between multiple VPCs or connecting to on-premises networks; it does not replace a hub-and-spoke architecture. Option B is wrong because VPC peering does not support transitive routing, requiring a full mesh of connections (O(n²)) that becomes unscalable and operationally heavy as the number of VPCs grows. Option C is wrong because establishing individual VPN connections from each VPC to on-premises does not enable inter-VPC communication without additional routing complexity and fails to provide a centralized, scalable hub for multi-account connectivity.

Page 1 of 3 · 200 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Org Complexity questions.