AWS SAP-C02 · Question 27 · Domain 1.4: Multi-Account Environment
An enterprise uses AWS Control Tower. They need to customize the account vending process to automatically deploy a specific third-party security agent on all EC2 instances created in new accounts. What is the BEST approach?
Answer options:
Manually log into each new account and install the agent.
Use Control Tower Account Factory Customization (AFC) or lifecycle events to trigger an AWS Step Functions workflow that deploys the agent via Systems Manager.
Modify the default Control Tower CloudFormation templates.
Use an SCP to enforce the installation of the agent.
75 questions · hints · full answers · grading