AWS Certified Solutions Architect – Associate (SAA-C03) — Question 554

A company's solutions architect is designing an AWS multi-account solution that uses AWS Organizations. The solutions architect has organized the company's accounts into organizational units (OUs).

The solutions architect needs a solution that will identify any changes to the OU hierarchy. The solution also needs to notify the company's operations team of any changes.

Which solution will meet these requirements with the LEAST operational overhead?

Answer options

Correct answer: A

Explanation

AWS Control Tower natively manages OUs and accounts, providing built-in drift detection capabilities that automatically identify when OU structures or landing zones deviate from their intended configuration. This built-in feature generates drift notifications with minimal configuration, ensuring the lowest operational overhead. Other methods involving AWS Config, AWS CloudTrail, or CloudFormation drift detection require significant manual setup and custom integration to achieve the same alerting functionality.