exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 495 discussion

A large company is migrating its entire IT portfolio to AWS. Each business unit in the company has a standalone AWS account that supports both development and test environments. New accounts to support production workloads will be needed soon.
The Finance department requires a centralized method for payment but must maintain visibility into each group's spending to allocate costs.
The Security team requires a centralized mechanism to control IAM usage in all the company's accounts.
What combination of the following options meet the company's needs with the LEAST effort? (Choose two.)

  • A. Use a collection of parameterized AWS CloudFormation templates defining common IAM permissions that are launched into each account. Require all new and existing accounts to launch the appropriate stacks to enforce the least privilege model.
  • B. Use AWS Organizations to create a new organization from a chosen payer account and define an organizational unit hierarchy. Invite the existing accounts to join the organization and create new accounts using Organizations.
  • C. Require each business unit to use its own AWS accounts. Tag each AWS account appropriately and enable Cost Explorer to administer chargebacks.
  • D. Enable all features of AWS Organizations and establish appropriate service control policies that filter IAM permissions for sub-accounts.
  • E. Consolidate all of the company's AWS accounts into a single AWS account. Use tags for billing purposes and IAM's Access Advisor feature to enforce the least privilege model.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️
Reference:
https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/ce-what-is.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
donathon
Highly Voted 3 years, 8 months ago
BD A: While CloudFormation is a good start, remember this does not prevent changes after the stack has been deployed. B: This looks likely. C: This does not allow Finance to view the bill in a centralized manner which is a requirement. D: This is the best way to meet the security requirements. SCPs offer central control over the maximum available permissions for all accounts in your organization, allowing you to ensure your accounts stay within your organization’s access control guidelines. E: It’s best to use different accounts for dev\test and prod.
upvoted 29 times
...
huhupai
Highly Voted 3 years, 8 months ago
I would go for B, D.
upvoted 10 times
...
SkyZeroZx
Most Recent 1 year, 11 months ago
Selected Answer: BD
The combination of options that meet the company's needs with the least effort is B and D. Option B suggests using AWS Organizations to create a new organization from a chosen payer account, establish an organizational unit hierarchy, and invite existing accounts to join the organization. This will provide centralized billing and payment while maintaining visibility into each group's spending. Option D suggests enabling all features of AWS Organizations and establishing appropriate service control policies (SCPs) that filter IAM permissions for sub-accounts. This will provide centralized control over IAM usage in all the company's accounts. By implementing both options B and D, the company can achieve centralized payment and cost allocation through AWS Organizations, while also maintaining centralized control over IAM usage through service control policies.
upvoted 1 times
...
Ni_yot
2 years, 7 months ago
B and D are correct ans
upvoted 1 times
...
Rocketeer
2 years, 9 months ago
B,D https://aws.amazon.com/organizations/faqs/
upvoted 1 times
...
chatvinoth
3 years, 4 months ago
There are two requirements here - 1. Finance needs [ B ] 2. Security Teams needs [ D ]
upvoted 1 times
...
cldy
3 years, 5 months ago
B. Use AWS Organizations to create a new organization from a chosen payer account and define an organizational unit hierarchy. Invite the existing accounts to join the organization and create new accounts using Organizations. D. Enable all features of AWS Organizations and establish appropriate service control policies that filter IAM permissions for sub-accounts.
upvoted 1 times
...
AzureDP900
3 years, 5 months ago
B,D is right
upvoted 1 times
...
DerekKey
3 years, 6 months ago
B correct - you will see cost allocated for each connected account D correct - "centralized mechanism to control IAM usage in all the company's accounts"
upvoted 3 times
...
WhyIronMan
3 years, 6 months ago
I'll go for B,D
upvoted 1 times
...
Waiweng
3 years, 6 months ago
It's B and D
upvoted 2 times
...
Kian1
3 years, 6 months ago
Will go with C,D Tags, Cost Explorer and SCP
upvoted 2 times
Kian1
3 years, 6 months ago
I read thr all the comments but my second thought is also CD..
upvoted 2 times
...
...
tipzzz
3 years, 6 months ago
AWS Organization is ok for consolidated billing (https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/useconsolidatedbilling-procedure.html), it's at account level but finance department need maintain visibility into each GROUP’s spending. That's why we need tag to solve this, also tag is a best pratices for cost allocation (https://d1.awsstatic.com/whitepapers/aws-tagging-best-practices.pdf#:~:text=Amazon%20Web%20Services%20allows%20customers,search%20for%2C%20and%20filter%20resources.)
upvoted 1 times
tipzzz
3 years, 6 months ago
Answers : CD
upvoted 1 times
...
...
Ebi
3 years, 6 months ago
I go with BD
upvoted 4 times
...
T14102020
3 years, 7 months ago
Correct answer BD. Organization and SCP
upvoted 1 times
...
RLai
3 years, 7 months ago
https://aws.amazon.com/premiumsupport/knowledge-center/consolidated-linked-billing-report/ Show individual account usage in the organization... therefore C & D
upvoted 1 times
...
Bulti
3 years, 7 months ago
B And D are the answers.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...