exam questions

Exam AWS Certified DevOps Engineer - Professional DOP-C02 All Questions

View all questions & answers for the AWS Certified DevOps Engineer - Professional DOP-C02 exam

Exam AWS Certified DevOps Engineer - Professional DOP-C02 topic 1 question 334 discussion

A company use an organization in AWS Organizations to manage multiple AWS accounts. The company has enabled all features enabled for the organization. The company configured the organization as a hierarchy of OUs under the root OU. The company recently registered all its OUs and enrolled all its AWS accounts in AWS Control Tower.

The company needs to customize the AWS Control Tower managed AWS Config configuration recorder in each of the company's AWS accounts. The company needs to apply the customizations to both the existing AWS accounts and to any new AWS accounts that the company enrolls in AWS Control Tower in the future.

Which combination of steps will meet these requirements? (Choose three.)

  • A. Create a new AWS account. Create an AWS Lambda function in the new account to apply the customizations to the AWS Config configuration recorder in each AWS account in the organization.
  • B. Create a new AWS account as an AWS Config delegated administrator. Create an AWS Lambda function in the delegated administrator account to apply the customizations to the AWS Config configuration recorder in the delegated administrator account.
  • C. Configure an Amazon EventBridge rule in the AWS Control Tower management account to invoke an AWS Lambda function when the Organizations OU is registered or reregistered. Re-register the root Organizations OU.
  • D. Configure the AWSControlTowerExecution IAM role in each AWS account in the organization to be assumable by an AWS Lambda function. Configure the Lambda function to assume the AWSControlTowerExecution IAM role.
  • E. Create an IAM role in the AWS Control Tower management account that an AWS Lambda function can assume. Grant the IAM role permission to assume the AWSControlTowerExecution IAM role in any account in the organization. Configure the Lambda function to use the new IAM role.
  • F. Configure an Amazon EventBridge rule in the AWS Control Tower management account to invoke an AWS Lambda function when an AWS account is updated or enrolled in AWS Control Tower or when the landing zone is updated. Re-register each Organizations OU in the organization.
Show Suggested Answer Hide Answer
Suggested Answer: AEF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Srikantha
3 weeks, 6 days ago
Selected Answer: BEF
❌ Why not the others? A. While a Lambda in a new account can work, it’s better to use a delegated admin for AWS Config management. C. EventBridge doesn’t emit events when an OU is registered or re-registered. This is not a valid trigger. D. Modifying the AWSControlTowerExecution role in each account breaks the Control Tower managed roles and is not recommended.
upvoted 1 times
...
DKM
1 month, 1 week ago
Selected Answer: BDF
These steps ensure that the customizations are applied consistently across all existing and new AWS accounts, leveraging the delegated administrator account for centralized management and automation123.
upvoted 1 times
...
fcbflo
3 months, 4 weeks ago
Selected Answer: CEF
C covers OU registration/re-registration events⁠ F handles account enrollment, updates, and landing zone changes⁠ ⁠​E's role in providing the necessary IAM permissions structure: Creates proper IAM role in Control Tower management account Enables assumption of AWSControlTowerExecution IAM role across accounts
upvoted 1 times
...
CHRIS12722222
4 months ago
Selected Answer: AEF
https://aws.amazon.com/solutions/guidance/customizing-aws-config-resources-in-aws-control-tower/ - Need eventbridge in CT management acct to react to CT lifecycle events - need CT management acct lambda function to assume AWSControlTowerExecution role and customise config. - If lambda is not in CT management acct then it will need to assume a role in CT management acct which has trust with AWSControlTowerExecution role in member accts
upvoted 3 times
...
teo2157
4 months, 2 weeks ago
Selected Answer: AEF
I think there is a misspelling in the A option as it's said just "Create a new AWS account" when it should said " Create a new AWS account as an AWS Config delegated administrator.", said that, I go for AEF.
upvoted 2 times
...
phu0298
5 months, 1 week ago
B, E, and F. B: AWS Config supports delegated administrators, allowing a central account to manage configurations across the organization. By creating a Lambda function in the delegated administrator account, you can apply the customizations to the AWS Config configuration recorder in all member accounts centrally. E: The AWSControlTowerExecution IAM role exists in each enrolled account and allows centralized operations. The IAM role in the management account needs permissions to assume the AWSControlTowerExecution role in member accounts. F: AWS Control Tower emits events when an account is enrolled or updated, or when the landing zone is updated. An EventBridge rule can trigger the Lambda function to ensure that any new or updated accounts automatically receive the customizations. Re-registering each OU ensures that Control Tower applies its governance to all accounts and OUs consistently.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago