Medium1 markMultiple Choice
Domain 1.4: Multi-Account EnvironmentMulti-AccountControl TowerShared Services

AWS SAP-C02 · Question 53 · Domain 1.4: Multi-Account Environment

A company is setting up AWS Control Tower. They want to implement a shared services VPC for centralized Active Directory and security tools. Which TWO steps are required to integrate this with the Control Tower environment? (Select TWO)

Answer options:

A.

Deploy the shared services in the Control Tower management account.

B.

Create a new AWS account using the Control Tower Account Factory for the shared services.

C.

Peer the shared services VPC with the VPCs in other member accounts using Transit Gateway.

D.

Use AWS RAM to share the Active Directory servers directly.

E.

Deploy the shared services in the Log Archive account.

F.

Modify the Control Tower core CloudFormation templates.

How to approach this question

Follow AWS multi-account best practices for shared services.

Full Answer

Create a new AWS account using the Control Tower Account Factory for the shared services., Peer the shared services VPC with the VPCs in other member accounts using Transit Gateway.
Best practices dictate creating a dedicated Shared Services account and using a Transit Gateway to route traffic between the shared services VPC and workload VPCs.

Common mistakes

Putting workloads in the management or log archive accounts.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 3

75 questions · hints · full answers · grading

More questions from this exam