AWS Certified SAP on AWS – Specialty (PAS-C01) — Question 40

A company is starting a new project to implement an SAP landscape with multiple accounts that belong to multiple teams in the us-east-2 Region. These teams include procurement, finance, sales, and human resources. An SAP solutions architect has started designing this new landscape and the AWS account structures.
The company wants to use automation as much as possible. The company also wants to secure the environment, implement federated access to accounts, centralize logging, and establish cross-account security audits. In addition, the company’s management team needs to receive a top-level summary of policies that are applied to the AWS accounts.
What should the SAP solutions architect do to meet these requirements?

Answer options

Correct answer: D

Explanation

The correct answer is D because AWS Control Tower is specifically designed to manage multi-account AWS environments, allowing for the application of Service Control Policies (SCPs) and providing a centralized dashboard for policy oversight. Options A, B, and C do not provide the same level of integration for managing multiple accounts and centralizing governance, making them less suitable for the company's requirements.