AWS Certified Solutions Architect – Professional (SAP-C02) — Question 115

A company wants to migrate to AWS. The company wants to use a multi-account structure with centrally managed access to all accounts and applications. The company also wants to keep the traffic on a private network. Multi-factor authentication (MFA) is required at login, and specific roles are assigned to user groups.

The company must create separate accounts for development. staging, production, and shared network. The production account and the shared network account must have connectivity to all accounts. The development account and the staging account must have access only to each other.

Which combination of steps should a solutions architect take 10 meet these requirements? (Choose three.)

Answer options

Correct answer: A, C, D

Explanation

The correct steps include deploying a landing zone with AWS Control Tower to manage account structure, creating transit gateways for connectivity, and setting up AWS IAM Identity Center for centralized access management with MFA. Options B, E, and F do not adequately address the requirement for a multi-account structure with proper connectivity and centralized access management.