AWS Certified DevOps Engineer – Professional (DOP-C02) — Question 208

A company has started using AWS across several teams. Each team has multiple accounts and unique security profiles. The company manages the accounts in an organization in AWS Organizations. Each account has its own configuration and security controls.

The company's DevOps team wants to use preventive and detective controls to govern all accounts. The DevOps team needs to ensure the security of accounts now and in the future as the company creates new accounts in the organization.

Which solution will meet these requirements?

Answer options

Correct answer: B

Explanation

The correct answer is B because AWS Control Tower provides a comprehensive governance solution that includes OUs and controls tailored to security policies, which is essential for managing multiple accounts effectively. Option A lacks the structured management provided by AWS Control Tower, while C and D do not offer the built-in governance and account provisioning features that AWS Control Tower provides, making them less suitable for the company's future needs.