exam questions

Exam AWS Certified DevOps Engineer - Professional DOP-C02 All Questions

View all questions & answers for the AWS Certified DevOps Engineer - Professional DOP-C02 exam

Exam AWS Certified DevOps Engineer - Professional DOP-C02 topic 1 question 67 discussion

A company has its AWS accounts in an organization in AWS Organizations. AWS Config is manually configured in each AWS account. The company needs to implement a solution to centrally configure AWS Config for all accounts in the organization The solution also must record resource changes to a central account.
Which combination of actions should a DevOps engineer perform to meet these requirements? (Choose two.)

  • A. Configure a delegated administrator account for AWS Config. Enable trusted access for AWS Config in the organization.
  • B. Configure a delegated administrator account for AWS Config. Create a service-linked role for AWS Config in the organization’s management account.
  • C. Create an AWS CloudFormation template to create an AWS Config aggregator. Configure a CloudFormation stack set to deploy the template to all accounts in the organization.
  • D. Create an AWS Config organization aggregator in the organization's management account. Configure data collection from all AWS accounts in the organization and from all AWS Regions.
  • E. Create an AWS Config organization aggregator in the delegated administrator account. Configure data collection from all AWS accounts in the organization and from all AWS Regions.
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
asfsdfsdf
Highly Voted 2 years ago
Selected Answer: AE
AE https://aws.amazon.com/blogs/mt/org-aggregator-delegated-admin/ A - When enabling trust - the service-linked role will be created but not the other way around. E - the delegated account will be the account that manages AWS config so it should collect all data centrally.
upvoted 18 times
...
jamesf
Most Recent 9 months, 2 weeks ago
Selected Answer: AE
A - You can enable trusted access using either the AWS Config console or the AWS Organizations console. https://docs.aws.amazon.com/organizations/latest/userguide/services-that-can-integrate-config.html
upvoted 2 times
...
zijo
1 year, 1 month ago
AE is the answer AWS Config offers an organization-wide data aggregation capability called the Config organization aggregator. It allows you to collect and view configuration data from all member accounts within your AWS Organization in a single location. This centralizes your view of resource configurations and compliance posture across your entire AWS environment.
upvoted 1 times
...
thanhnv142
1 year, 3 months ago
A and E are correct: <AWS Config is manually configured in each AWS account> means we dont need ACF (only used for the deployment of AWS config). <centrally configure AWS Config for all accounts> means we need to allow a central account to control AWS config in all member accounts. - <record resource changes to a central account> means we need to collect data from all member accounts and push to the central account B: service-linked role only used for interacting with other AWS services C: no need ACF D: we need AWS Config organization aggregator in the delegated administrator account, not the organization's management account
upvoted 1 times
...
hoaile257
1 year, 7 months ago
Selected Answer: AE
AE is most correct
upvoted 2 times
...
Just_Ninja
1 year, 10 months ago
Selected Answer: AE
Here you have the Tutorial :) https://aws.amazon.com/blogs/mt/org-aggregator-delegated-admin/
upvoted 3 times
...
rhinozD
1 year, 11 months ago
Selected Answer: AE
https://aws.amazon.com/blogs/mt/org-aggregator-delegated-admin/ https://docs.aws.amazon.com/organizations/latest/userguide/services-that-can-integrate-config.html
upvoted 3 times
...
Kodoma
1 year, 11 months ago
BE is the most efficient
upvoted 3 times
...
ParagSanyashiv
2 years ago
Selected Answer: BD
BD is most suitable in this case
upvoted 3 times
2pk
1 year, 6 months ago
Why ? it says setup service linked role in management account not in Delegated account?
upvoted 1 times
...
...
jqso234
2 years ago
Selected Answer: BD
The correct answers are B and D. Option B is correct because it suggests configuring a delegated administrator account for AWS Config and creating a service-linked role for AWS Config in the organization’s management account. This allows AWS Config to perform supported operations within the accounts in the organization, and enables trusted access. Option D is correct because it suggests creating an AWS Config organization aggregator in the organization's management account and configuring data collection from all AWS accounts in the organization and from all AWS Regions, which enables multi-account, multi-region data aggregation. Options A and E are not correct because they do not suggest using a service-linked role for AWS Config or creating an AWS Config organization aggregator in the organization's management account.
upvoted 2 times
...
Dimidrol
2 years, 1 month ago
Selected Answer: AE
AE . https://docs.aws.amazon.com/organizations/latest/userguide/services-that-can-integrate-config.html
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago