AWS Certified Solutions Architect – Professional (SAP-C02) — Question 324

A company is migrating its infrastructure to the AWS Cloud. The company must comply with a variety of regulatory standards for different projects. The company needs a multi-account environment.

A solutions architect needs to prepare the baseline infrastructure. The solution must provide a consistent baseline of management and security, but it must allow flexibility for different compliance requirements within various AWS accounts. The solution also needs to integrate with the existing on-premises Active Directory Federation Services (AD FS) server.

Which solution meets these requirements with the LEAST amount of operational overhead?

Answer options

Correct answer: B

Explanation

AWS Control Tower is the most efficient service for establishing a secure, multi-account AWS environment because it automates landing zone creation, centralized logging, and guardrails with minimal operational overhead. Integrating AWS IAM Identity Center (formerly AWS Single Sign-On) with the on-premises AD FS server simplifies identity federation across all accounts compared to configuring individual IAM identity providers in each account. Other options require manual configuration of logging, OUs, and compliance rules, which increases administrative overhead.