Automating Network VPC Deployment in AWS Control Tower

A network engineer is working on a large migration effort from an on-premises data center to an AWS Control Tower based multi-account environment. The environment has a transit gateway that is deployed to a central network services account. The central network services account has been shared with an organization in AWS Organizations through AWS Resource Access Manager (AWS RAM). A shared services account also exists in the environment. The shared services account hosts workloads that need to be shared with the entire organization. The network engineer needs to create a solution to automate the deployment of common network components across the environment. The solution must provision a VPC for application workloads to each new and existing member account. The VPCs must be connected to the transit gateway in the central network services account. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose three.)

  1. Deploy an AWS Lambda function to the shared services account. Program the Lambda function to assume a role in the new and existing member accounts to provision the necessary network infrastructure.
  2. Update the existing accounts with an Account Factory Customization (AFC). Select the same AFC when provisioning new accounts. Source Reference Answer
  3. Create an AWS CloudFormation template that describes the infrastructure that needs to be created in each account. Upload the template as an AWS Service Catalog product to the shared services account. Source Reference Answer
  4. Deploy an Amazon EventBridge rule on a default event bus in the shared services account. Configure the EventBridge rule to react to AWS Control Tower CreateManagedAccount lifecycle events and to invoke the AWS Lambda function.
  5. Create an AWSControlTowerBiueprintAccess role in the shared services account. Source Reference Answer

Community Votes

BCE
80%
ACD
20%

80% of anonymous learners picked answer BCE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of native AWS Control Tower automation features; the trap is choosing manual Lambda scripting instead of declarative infrastructure-as-code tools like Service Catalog integrated with AFC.

This question tests the integration of AWS Control Tower, Service Catalog, and EventBridge for automated resource provisioning. The community consensus identifies using Account Factory Customizations (AFC) combined with Service Catalog as the lowest overhead solution.

Candidates often select ACD (Lambda/EventBridge/Role), assuming custom code is required. However, this introduces significant operational overhead compared to managed services like Service Catalog and AFC.

Community Discussion (4 comments)

Rollizo 👍 1 Selected: ACD
For me you have to use Cloudformation, later event Bridge and Lambda Function
AzureDP900 👍 1 Selected: BCE
BCE (Create an AWS CloudFormation template, Deploy an Amazon EventBridge rule, and Update the existing accounts with an Account Factory Customization) is actually a more efficient and streamlined approach.
cas_tori 👍 1 Selected: BCE
this is BCE
aragon_saa 👍 2 Selected: BCE
Answer is BCE

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

BCE represents the most streamlined approach by leveraging AWS Control Tower's native capabilities. Option B uses Account Factory Customization (AFC) to pre-define network configurations (VPCs, TGW attachments) that are automatically applied when new accounts are created or existing ones are customized. Option C utilizes AWS Service Catalog, which allows the administrator to manage the CloudFormation template centrally in the shared services account, ensuring standardized deployment across member accounts.

Why the Other Options Are Wrong

Option A suggests using a Lambda function to assume roles and provision resources manually. While functional, this requires extensive custom coding, error handling, and maintenance, violating the 'least operational overhead' requirement. Option D is incorrect because while EventBridge can trigger actions, it is not needed if AFC handles the provisioning natively during account creation. Option E is insufficient on its own as it only creates a role without defining the actual infrastructure deployment mechanism.

Community Comment Notes

Several commenters initially favored ACD, believing custom automation was necessary. However, experienced users clarified that BCE leverages built-in Control Tower features, reducing the need for custom scripts. One comment explicitly stated, "this is BCE," highlighting the efficiency of using native tools over custom Lambda solutions.

Official Reference

Exam Strategy

Prioritize native AWS managed services (like Service Catalog and Control Tower features) over custom Lambda implementations when the requirement specifies 'least operational overhead.' Look for combinations that use declarative templates (CloudFormation) paired with automation triggers (EventBridge/AFC).

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide