ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 208 - SAP-C02 discussion

Report
Export

A company has a few AWS accounts for development and wants to move its production application to AWS. The company needs to enforce Amazon Elastic Block Store (Amazon EBS) encryption at rest current production accounts and future production accounts only. The company needs a solution that includes built-in blueprints and guardrails.

Which combination of steps will meet these requirements? (Choose three.)

A.
Use AWS CloudFormation StackSets to deploy AWS Config rules on production accounts.
Answers
A.
Use AWS CloudFormation StackSets to deploy AWS Config rules on production accounts.
B.
Create a new AWS Control Tower landing zone in an existing developer account. Create OUs for accounts. Add production and development accounts to production and development OUs, respectively.
Answers
B.
Create a new AWS Control Tower landing zone in an existing developer account. Create OUs for accounts. Add production and development accounts to production and development OUs, respectively.
C.
Create a new AWS Control Tower landing zone in the company's management account. Add production and development accounts to production and development OUs. respectively.
Answers
C.
Create a new AWS Control Tower landing zone in the company's management account. Add production and development accounts to production and development OUs. respectively.
D.
Invite existing accounts to join the organization in AWS Organizations. Create SCPs to ensure compliance.
Answers
D.
Invite existing accounts to join the organization in AWS Organizations. Create SCPs to ensure compliance.
E.
Create a guardrail from the management account to detect EBS encryption.
Answers
E.
Create a guardrail from the management account to detect EBS encryption.
F.
Create a guardrail for the production OU to detect EBS encryption.
Answers
F.
Create a guardrail for the production OU to detect EBS encryption.
Suggested answer: C, D, F

Explanation:

https://docs.aws.amazon.com/controltower/latest/userguide/controls.html https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#ebs-enable-encryption AWS is now transitioning the previous term 'guardrail' new term 'control'.

asked 16/09/2024
Robert Endicott
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first