SOA-C02 Question 195
Single answerYour organization has multiple AWS accounts used for different business units. The security team mandates that all accounts must adhere to a centralized security baseline, including mandatory logging of API activities, consolidated billing, and restricting access to certain AWS services. Which of the following would you use to implement this requirement?
- A
AWS Control Tower
- B
AWS IAM Access Analyzer
- C
AWS CloudFormation StackSets
- D
AWS Trusted Advisor
Show answer and explanation
Correct answer: A
Explanation
AWS Control Tower is specifically designed to manage and secure multi-account environments. It enables you to enforce security baselines, consolidate billing, and implement guardrails across accounts, making it the ideal choice for this scenario. The other options focus on different aspects of AWS management but lack the comprehensive multi-account governance capabilities required.
- A. Correct.
AWS Control Tower is designed to set up and govern a secure multi-account environment. It provides centralized governance, logging, and service control policies to enforce security baselines and restrict access to specific AWS services.
- B. Incorrect.
AWS IAM Access Analyzer is used to analyze and validate IAM policies for resource access, but it does not provide centralized governance or multi-account management.
- C. Incorrect.
AWS CloudFormation StackSets can deploy CloudFormation templates across multiple accounts, but it is not a comprehensive multi-account governance solution.
- D. Incorrect.
AWS Trusted Advisor provides recommendations for cost optimization, security, and performance, but it does not help in implementing centralized multi-account strategies.