Question 1 · choose 1
A company uses AWS Organizations without AWS Control Tower. Every account in its workloads OU must receive the same baseline: three IAM roles, an AWS Config recorder and a set of Config rules. Accounts created in or moved into the OU later must receive the baseline automatically, and it must be removed from accounts that leave the OU. Which solution requires the LEAST ongoing effort?
- AShare a Service Catalog portfolio with the OU so that each account administrator can launch the baseline product
- BRun a pipeline that assumes a role in each account listed in the OU and deploys a CloudFormation stack there every night
- CCreate a service-managed CloudFormation StackSet that targets the OU with automatic deployment turned on
- DCreate an organization conformance pack that contains the Config rules, the configuration recorder and the IAM roles
Show the answer and why
AShare a Service Catalog portfolio with the OU so that each account administrator can launch the baseline product
Incorrect
Service Catalog lets users launch approved products themselves, so the baseline would depend on someone launching it in each new account, and it would not be removed automatically when an account leaves the OU.
BRun a pipeline that assumes a role in each account listed in the OU and deploys a CloudFormation stack there every night
Incorrect
This can work, but the company would build and run the pipeline, discover new accounts itself and write its own clean-up for accounts that leave.
CCreate a service-managed CloudFormation StackSet that targets the OU with automatic deployment turned on
Correct
With service-managed permissions and automatic deployment, StackSets deploys stack instances to accounts added to the target OU and can remove them from accounts that are removed from it.
DCreate an organization conformance pack that contains the Config rules, the configuration recorder and the IAM roles
Incorrect
A conformance pack is a collection of AWS Config rules and remediation actions. It is not a way to deploy IAM roles or other baseline resources.
"Same stack in every account of an OU, including future ones" is what StackSets with service-managed permissions and automatic deployment is for.
AWS documentation