exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 168 discussion

A company has a few AWS accounts for development and wants to move its production application to AWS. The company needs to enforce Amazon Elastic Block Store (Amazon EBS) encryption at rest current production accounts and future production accounts only. The company needs a solution that includes built-in blueprints and guardrails.

Which combination of steps will meet these requirements? (Choose three.)

  • A. Use AWS CloudFormation StackSets to deploy AWS Config rules on production accounts.
  • B. Create a new AWS Control Tower landing zone in an existing developer account. Create OUs for accounts. Add production and development accounts to production and development OUs, respectively.
  • C. Create a new AWS Control Tower landing zone in the company’s management account. Add production and development accounts to production and development OUs. respectively.
  • D. Invite existing accounts to join the organization in AWS Organizations. Create SCPs to ensure compliance.
  • E. Create a guardrail from the management account to detect EBS encryption.
  • F. Create a guardrail for the production OU to detect EBS encryption.
Show Suggested Answer Hide Answer
Suggested Answer: CDF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
God_Is_Love
Highly Voted 1 year, 9 months ago
Selected Answer: CDF
When you enable controls on an organizational unit (OU) that is registered with AWS Control Tower, preventive controls apply to all member accounts under the OU, enrolled and unenrolled. Detective controls apply to enrolled accounts only. https://docs.aws.amazon.com/controltower/latest/userguide/controls.html
upvoted 13 times
...
Untamables
Highly Voted 1 year, 10 months ago
Selected Answer: CDF
https://docs.aws.amazon.com/controltower/latest/userguide/controls.html https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#ebs-enable-encryption AWS is now transitioning the previous term 'guardrail' new term 'control'.
upvoted 5 times
...
BelloMio
Most Recent 2 months, 3 weeks ago
Selected Answer: CDE
I mean E is technically correct. The guardrail is created FROM the management account in Control Tower. Even tho I would select F as well during the exam
upvoted 1 times
...
career360guru
1 year ago
Selected Answer: CDF
C, D, F are the right choices.
upvoted 1 times
...
career360guru
1 year, 1 month ago
Selected Answer: CDF
C, D, F
upvoted 1 times
...
bur4an
1 year, 3 months ago
Basically order is DCF of the setup
upvoted 1 times
...
NikkyDicky
1 year, 5 months ago
Selected Answer: CDF
CDF for sure
upvoted 1 times
...
SkyZeroZx
1 year, 6 months ago
Selected Answer: BCF
CEF A ) AWS Config not enforce rule B) Why developer account ? is incorrect is management account C ) Sounds good D) SCP for enforce sounds good E ) EBS encryption in managament account ? not only required in production F ) encryption in production OU sounds great
upvoted 3 times
SkyZeroZx
1 year, 6 months ago
CDF is correct
upvoted 1 times
...
...
SkyZeroZx
1 year, 6 months ago
Selected Answer: BCF
https://www.examtopics.com/discussions/amazon/view/97939-exam-aws-certified-solutions-architect-professional-sap-c02/
upvoted 1 times
...
SkyZeroZx
1 year, 6 months ago
Selected Answer: BCF
https://www.examtopics.com/discussions/amazon/view/97939-exam-aws-certified-solutions-architect-professional-sap-c02/
upvoted 1 times
...
Windows98
1 year, 6 months ago
Selected Answer: ACF
C because we want to use Control Tower A and C because we're going to use Controls and Config Not D because Control Tower is a parallel product to Organisations and it doesn't use SCPs although it can import existing OUs.
upvoted 3 times
Windows98
1 year, 6 months ago
I meant to say A and F because we're going to use Controls and Config
upvoted 1 times
...
...
Roontha
1 year, 7 months ago
Answer : C,D,F
upvoted 1 times
...
DWsk
1 year, 8 months ago
Selected Answer: ACF
I think the answer is ACF. I don't think you need D once you have C. Also, control tower uses config rules to set up guardrails. See the link below: https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#:~:text=isn%27t%20enabled%20on%20any%20OUs.-,The%20artifact%20for%20this%20control%20is%20the%20following%20AWS%20Config%20rule.,-AWSTemplateFormatVersion%3A%202010%2D09%2D09
upvoted 2 times
xenodamus
1 year, 7 months ago
You still need to invite accounts before you can organize them in OUs. All steps are needed. I don't like the way they scatter between answers though.
upvoted 2 times
...
...
mfsec
1 year, 9 months ago
Selected Answer: CDF
CDF seems the best choice
upvoted 1 times
...
dummy1777
1 year, 10 months ago
B. Create a new AWS Control Tower landing zone in an existing developer account. Create OUs for accounts. Add production and development accounts to production and development OUs, respectively. D. Invite existing accounts to join the organization in AWS Organizations. Create SCPs to ensure compliance. F. Create a control for the production OU to detect EBS encryption. By creating a new AWS Control Tower landing zone, the company can create OUs for accounts and add them to the appropriate production and development OUs. This will enable centralized governance and enforce consistent policies and best practices. The company can then invite existing accounts to join the organization in AWS Organizations and create SCPs to ensure compliance. Finally, the company can create a control for the production OU to detect EBS encryption, ensuring that encryption at rest is enforced in production accounts.
upvoted 2 times
...
spd
1 year, 10 months ago
Selected Answer: CDF
Answer is CDF https://docs.aws.amazon.com/controltower/latest/userguide/controls.html https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#ebs-enable-encryption
upvoted 1 times
c73bf38
1 year, 10 months ago
The artifact for this control is AWS Config rule and AWS Config rules cannot be deployed using AWS CloudFormation StackSets.
upvoted 1 times
c73bf38
1 year, 10 months ago
moderator, delete above as the statement is incorrect that I posted, don't approve post.
upvoted 1 times
...
...
...
Musk
1 year, 10 months ago
Selected Answer: ABD
In F, guardrails are proposed to detect. Guardrails don't detect but prevent.
upvoted 1 times
Musk
1 year, 10 months ago
I found this, and after further reading I vote for CDF: https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#ebs-enable-encryption
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...