Skip to content
BytePatterns

DOP-C02 · Domain 2: Configuration Management and IaC · 17% of the exam

Task 2.2: Deploy automation to create, onboard, and secure AWS accounts in a multi-account or multi-Region environment.

Accounts as a product: Organizations and Control Tower to create and enroll them, SCPs and cross-account roles to bound them, and guardrails rolled out to every account with AWS Config, Security Hub, GuardDuty and Detective.

Study it

  • Accounts at scale: Organizations, Control Tower and Account Factory

    Lesson coming

  • Guardrails for every account: SCPs, cross-account roles and delegated administrators

    Partly covered by: Shared Responsibility & IAM

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company runs an AWS Control Tower landing zone. Each business unit must be able to request new AWS accounts on its own. New accounts must land in the business unit's organizational unit and be governed by Control Tower, with its baseline and enabled controls, from the start. The platform team wants the least custom tooling. What should the DevOps engineer do?

  1. AHave the business units use Control Tower Account Factory, with their IAM Identity Center users in the AWSAccountFactory group
  2. BGive each business unit a CloudFormation template with an AWS::Organizations::Account resource that creates the account in the right OU
  3. CBuild a request form that invokes a Lambda function, which calls the Organizations CreateAccount API and moves the account to the right OU
  4. DAsk the platform team to create every account by hand in the Organizations console and enroll it into Control Tower afterward
Show the answer and why
  • AHave the business units use Control Tower Account Factory, with their IAM Identity Center users in the AWSAccountFactory group

    Correct

    Account Factory provisions new member accounts in the landing zone, and IAM Identity Center users in the AWSAccountFactory group may provision accounts.

  • BGive each business unit a CloudFormation template with an AWS::Organizations::Account resource that creates the account in the right OU

    Incorrect

    Accounts can be created this way only from the management account, so every business unit would need access to it, and Control Tower governs the new account only once it is enrolled.

  • CBuild a request form that invokes a Lambda function, which calls the Organizations CreateAccount API and moves the account to the right OU

    Incorrect

    This is custom tooling, and an account created outside Account Factory still has to be enrolled before Control Tower baselines it.

  • DAsk the platform team to create every account by hand in the Organizations console and enroll it into Control Tower afterward

    Incorrect

    Enrollment would govern the accounts, but business units could not request accounts on their own.

Account Factory is the Control Tower way to create accounts: the new account is placed in a governed OU and baselined with its controls. Accounts made any other way stay outside that governance until they are enrolled.

Question 2 · choose 2

A company has 300 member accounts in AWS Organizations, and every OU still has the FullAWSAccess policy attached. Security requires that no IAM user or role in any member account can stop or delete the organization's CloudTrail trail, delete Amazon GuardDuty detectors, or leave the organization. A break-glass role named OrgBreakGlass in each account must still be able to perform these actions during an incident. Which actions should the DevOps engineer take? (Choose TWO.)

  1. AAlso move the management account into a protected OU so that the same policy applies to its users and roles
  2. BWrite an SCP that denies the CloudTrail, GuardDuty and LeaveOrganization actions with a condition that excludes the OrgBreakGlass role ARN
  3. CWrite a resource control policy that denies the same actions on the trail and the detectors in every member account
  4. DAttach the SCP to the root of the organization so that it applies to every OU and member account
  5. EDetach FullAWSAccess from the root and rely only on the new Deny SCP to control what member accounts can do
Show the answer and why
  • AAlso move the management account into a protected OU so that the same policy applies to its users and roles

    Incorrect

    SCPs don't affect users or roles in the management account, wherever it sits. They apply only to member accounts.

  • BWrite an SCP that denies the CloudTrail, GuardDuty and LeaveOrganization actions with a condition that excludes the OrgBreakGlass role ARN

    Correct

    A Deny statement with a Condition element is in effect only when the condition matches, so a condition on the principal ARN leaves the break-glass role out.

  • CWrite a resource control policy that denies the same actions on the trail and the detectors in every member account

    Incorrect

    RCPs apply only to the services on their supported list, and CloudTrail trails and GuardDuty are not on it.

  • DAttach the SCP to the root of the organization so that it applies to every OU and member account

    Correct

    A Deny in an SCP is evaluated for every OU and member account below the level it is attached to, so attaching it to the root covers all 300 accounts.

  • EDetach FullAWSAccess from the root and rely only on the new Deny SCP to control what member accounts can do

    Incorrect

    SCPs need an explicit Allow at every level. If FullAWSAccess is removed and not replaced, all OUs and accounts under that level are blocked.

SCPs set the maximum permissions for IAM users and roles in member accounts. A Deny SCP attached at the root, kept alongside FullAWSAccess and with a condition for the break-glass role, blocks the listed actions everywhere else. The management account is never restricted by SCPs.

Question 3 · choose 1

A company uses AWS Organizations and operates workloads in us-east-1 and eu-west-1. Amazon GuardDuty must be turned on in every existing and future member account in both Regions, and a dedicated security account must see and manage the findings of all accounts. Account owners must not need to do anything. What should the DevOps engineer do?

  1. AFrom the management account, designate the security account as the delegated GuardDuty administrator in us-east-1 only, and set auto-enable to ALL there
  2. BFrom the management account, make the security account the delegated GuardDuty administrator in both Regions, with auto-enable set to ALL in each
  3. CDeploy a StackSet that creates a GuardDuty detector in every member account in both Regions, with automatic deployment for new accounts
  4. DFrom the security account, invite every member account by email in each Region and ask the account owners to accept the invitations
Show the answer and why
  • AFrom the management account, designate the security account as the delegated GuardDuty administrator in us-east-1 only, and set auto-enable to ALL there

    Incorrect

    The delegated administrator manages member accounts within the Region where it is designated, so eu-west-1 would not be covered.

  • BFrom the management account, make the security account the delegated GuardDuty administrator in both Regions, with auto-enable set to ALL in each

    Correct

    Designation and auto-enable work per Region. With ALL, GuardDuty is enabled for existing and new member accounts in that Region.

  • CDeploy a StackSet that creates a GuardDuty detector in every member account in both Regions, with automatic deployment for new accounts

    Incorrect

    This turns GuardDuty on, but the accounts are not members of a GuardDuty administrator account, so the security account can neither see nor manage their findings.

  • DFrom the security account, invite every member account by email in each Region and ask the account owners to accept the invitations

    Incorrect

    Invitations need each account owner to act, and new accounts would have to be invited one by one.

GuardDuty's organization integration is Regional: the management account designates a delegated administrator in a Region, and that administrator's auto-enable settings decide whether existing (ALL) or only new (NEW) member accounts are enabled there.

Question 4 · choose 1

A security team must apply the same 20 AWS Config rules, with their remediation actions, to every account in the organization in two AWS Regions, including accounts that join later. Administrators of member accounts must not be able to change or delete the rules, and the team wants to see the compliance of all accounts and both Regions in one place. AWS Config is already recording in every account. What should the DevOps engineer do?

  1. ADeploy the rules with a service-managed StackSet to all accounts in both Regions, and review compliance in each account's AWS Config console
  2. BCreate an organization aggregator in the security account and use its compliance view to find accounts that are missing the rules
  3. CDeploy an organization conformance pack from the management account in us-east-1 only, which also places the rules in every other Region in use
  4. DDeploy an organization conformance pack in each Region from the management account, and create an organization aggregator in the security account
Show the answer and why
  • ADeploy the rules with a service-managed StackSet to all accounts in both Regions, and review compliance in each account's AWS Config console

    Incorrect

    Rules created as ordinary stack resources can be changed by account administrators, and checking each account separately is not one view.

  • BCreate an organization aggregator in the security account and use its compliance view to find accounts that are missing the rules

    Incorrect

    An aggregator collects configuration and compliance data. It does not deploy rules or remediation actions to any account.

  • CDeploy an organization conformance pack from the management account in us-east-1 only, which also places the rules in every other Region in use

    Incorrect

    Deploying rules and conformance packs across accounts is Region specific, so a deployment from one Region does not cover the other.

  • DDeploy an organization conformance pack in each Region from the management account, and create an organization aggregator in the security account

    Correct

    Organization conformance packs reach every member account, also accounts that join later, and cannot be modified by members; the aggregator shows compliance across accounts and Regions.

Organization conformance packs deploy AWS Config rules and remediation actions centrally, Region by Region, and protect them from changes in member accounts. An aggregator is the read side: it collects configuration and compliance data from many accounts and Regions.

Question 5 · choose 1

In a new organization, the platform team plans to run its shared CI/CD tooling, a central logging stack and the security team's GuardDuty administration from the management account, because it already has the broadest access. What should the DevOps engineer recommend instead?

  1. ARun everything in the management account but protect it with a strict SCP
  2. BRun workloads in member accounts, with a security account as delegated administrator
  3. CCreate IAM users for each team in the management account with separate permissions
  4. DMove the management account into an OU so that OU policies apply to its workloads
Show the answer and why
  • ARun everything in the management account but protect it with a strict SCP

    Incorrect

    SCPs do not restrict the management account.

  • BRun workloads in member accounts, with a security account as delegated administrator

    Correct

    AWS recommends using the management account only for tasks that need it and avoiding workloads there.

  • CCreate IAM users for each team in the management account with separate permissions

    Incorrect

    This still places teams and workloads in the management account.

  • DMove the management account into an OU so that OU policies apply to its workloads

    Incorrect

    SCPs do not affect users or roles in the management account, wherever it is placed.

Management account best practices include using it only for tasks that require it, avoiding workloads in it and limiting who can access it. Delegated administrators run services from member accounts.

Question 6 · choose 1

A network account owns a transit gateway that connects the on-premises network over Direct Connect and routes traffic centrally. Workload accounts in the organization must attach their VPCs to this gateway to reach on-premises systems. Accounts that are created later must be able to attach without anyone updating a share, and the network team does not want to operate additional transit gateways. What should the DevOps engineer do?

  1. ACreate a transit gateway in each workload account and peer it with the network account's transit gateway
  2. BPeer every workload VPC with a VPC in the network account that is attached to the transit gateway
  3. CShare the transit gateway with the organization through AWS RAM, with sharing enabled for AWS Organizations
  4. DShare the transit gateway through AWS RAM with each workload account ID as the account is created
Show the answer and why
  • ACreate a transit gateway in each workload account and peer it with the network account's transit gateway

    Incorrect

    Peering connects transit gateways, but every account would then run its own gateway and a peering attachment that supports only static routes.

  • BPeer every workload VPC with a VPC in the network account that is attached to the transit gateway

    Incorrect

    VPC peering is not transitive, and a peer VPC cannot use another VPC's connection to the corporate network.

  • CShare the transit gateway with the organization through AWS RAM, with sharing enabled for AWS Organizations

    Correct

    Accounts that join the organization get access to the share automatically, and accounts with a shared transit gateway can attach their VPCs to it.

  • DShare the transit gateway through AWS RAM with each workload account ID as the account is created

    Incorrect

    This lets each listed account attach, but someone has to add every new account to the share.

A transit gateway works across accounts when it is shared through AWS RAM. Sharing with the organization or an OU, rather than with individual account IDs, gives accounts that join later access without changes to the share.

Question 7 · choose 1

A central cloud team maintains a Service Catalog portfolio of approved products in a delegated administrator account. Developers in every account of the organization sign in with a role named DevOpsUser and must be able to launch these products without a local administrator importing the portfolio or granting access in each account. Product and constraint updates must reach all accounts without copying anything. What should the DevOps engineer do?

  1. AShare the portfolio with the organization through AWS Organizations, with principal name sharing turned on
  2. BShare the portfolio with each account ID through account-to-account sharing in Service Catalog
  3. CCopy the products into a portfolio in every account with the CopyProduct operation after each change
  4. DDeploy the products as stacks in every account with a service-managed StackSet from the admin account
Show the answer and why
  • AShare the portfolio with the organization through AWS Organizations, with principal name sharing turned on

    Correct

    An Organizations share needs no import and stays in sync with the original, and principal name sharing associates the matching role in each recipient account.

  • BShare the portfolio with each account ID through account-to-account sharing in Service Catalog

    Incorrect

    The shared reference stays in sync, but each recipient administrator must import the portfolio and grant access, because principal name sharing is available only through AWS Organizations.

  • CCopy the products into a portfolio in every account with the CopyProduct operation after each change

    Incorrect

    Each copy is a separate product that must be copied again after every change, unlike a shared portfolio, which is a reference.

  • DDeploy the products as stacks in every account with a service-managed StackSet from the admin account

    Incorrect

    StackSets roll out the same resources everywhere, which suits a mandatory baseline but not a catalog that developers launch from on demand.

Sharing through AWS Organizations shares a reference of the portfolio with an account, an OU or the whole organization, without an import step. Principal name sharing, available only for Organizations shares, grants access to principals with matching names in the recipient accounts.

Question 8 · choose 1

An identity team manages permission sets and account assignments in IAM Identity Center every day. Security wants as few people as possible to have access to the management account, where the Identity Center instance lives. What should the DevOps engineer do?

  1. AMove the Identity Center instance to a member account owned by the identity team
  2. BGive the identity team a permission set in the management account that allows only Identity Center actions
  3. CCreate IAM users for the identity team in each member account
  4. DRegister a member account as the Identity Center delegated administrator for the identity team
Show the answer and why
  • AMove the Identity Center instance to a member account owned by the identity team

    Incorrect

    The organization instance always resides in the management account.

  • BGive the identity team a permission set in the management account that allows only Identity Center actions

    Incorrect

    The team would still need access to the management account.

  • CCreate IAM users for the identity team in each member account

    Incorrect

    This does not manage Identity Center from outside the management account.

  • DRegister a member account as the Identity Center delegated administrator for the identity team

    Correct

    Delegated administration lets a member account perform most Identity Center tasks and reduces management account access.

The Identity Center instance stays in the management account, but a delegated administrator account can manage most tasks. Permission sets provisioned in the management account still need its administrators.

Question 9 · choose 1

Account owners have full administrator rights in their member accounts, and some of them can still sign in as the root user of their account. The company must make sure that no member account can remove itself from the organization, not even through its root user, while account owners keep their administrator rights and the cloud team in the management account can still remove an account when it decides to. What should the DevOps engineer do?

  1. AAttach an SCP that denies organizations:LeaveOrganization to the member accounts
  2. BReplace the AdministratorAccess policy of every account owner with narrower policies that omit Organizations actions
  3. CCreate an EventBridge rule that alerts the cloud team when an account leaves the organization
  4. DSet a permissions boundary that denies organizations:LeaveOrganization on every account owner's IAM role
Show the answer and why
  • AAttach an SCP that denies organizations:LeaveOrganization to the member accounts

    Correct

    Leaving requires organizations:LeaveOrganization, and an SCP limits every user and role in a member account, including its root user, but not the management account.

  • BReplace the AdministratorAccess policy of every account owner with narrower policies that omit Organizations actions

    Incorrect

    Least privilege helps in general, but it takes away rights the owners need and does not limit the root user of the account.

  • CCreate an EventBridge rule that alerts the cloud team when an account leaves the organization

    Incorrect

    An alert after the fact does not stop the account from leaving.

  • DSet a permissions boundary that denies organizations:LeaveOrganization on every account owner's IAM role

    Incorrect

    A boundary limits only the users and roles it is attached to, so the root user and any new administrator role without it can still leave.

An account needs organizations:LeaveOrganization to leave. An SCP that denies it applies to all principals in member accounts, including the root user, whatever their IAM policies allow. SCPs do not restrict the management account, which can still remove accounts.

Practise domain 2 →Practise all domains →