Build an Account Factory Customization blueprint with the baseline and provision every account from it
A company needs to adopt a multi-account strategy to deploy its applications and the associated CI/CD infrastructure. The company has created an organization in AWS Organizations that has all features enabled. The company has configured AWS Control Tower and has set up a landing zone. The company needs to use AWS Control Tower controls (guardrails) in all AWS accounts in the organization. The company must create the accounts for a multi-environment application and must ensure that all accounts are configured to an initial baseline. Which solution will meet these requirements with the LEAST operational overhead?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Account Factory Customization is the Control Tower feature designed for exactly this: a blueprint whose baseline is applied to every account the account factory provisions, so the configuration and the guardrails arrive together as a single provisioning action (A). Option B provisions accounts and then applies the baseline with StackSets, which is a second, separate mechanism that must be maintained and coordinated with account creation. Options C and D bypass the account factory entirely and provision accounts through Organizations directly, which means Control Tower's baseline and guardrails are not applied automatically at creation.
Every account must receive the Control Tower guardrails and an initial baseline configuration, with the least operational overhead. An Account Factory Customization blueprint packages the baseline configuration so it is part of how accounts are created, and provisioning each environment account and the CI/CD account from that blueprint means the baseline and the guardrails are applied automatically as part of account creation, with no separate deployment step to maintain.
Using the Control Tower account factory and then applying the baseline with CloudFormation StackSets (B) — this works but introduces a second mechanism that must be maintained and kept in step with account creation, which is precisely the operational overhead the AFC blueprint removes. Provisioning accounts with Organizations and applying the baseline with a Lambda in the management account (C) — writing and operating a custom function to configure new accounts adds code and does not integrate with the Control Tower baseline. Provisioning accounts directly with Organizations plus StackSets (D) — the same two-mechanism problem as B, and it also bypasses the account factory that would apply the guardrails.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is that every account in the organization receives the Control Tower guardrails and an initial baseline configuration, and that this happen with the least operational overhead. An Account Factory Customization blueprint is Control Tower's mechanism for baking a baseline configuration into the account creation process itself, so provisioning each dedicated environment account and the CI/CD account from that blueprint applies the baseline and the guardrails as one atomic step with no follow-up deployment to schedule or maintain (A). Because the baseline travels with the blueprint, accounts created later receive the identical configuration automatically, which is what keeps future accounts compliant with the same baseline. A is the correct answer.Why the Other Options Are Wrong
B uses the Control Tower account factory to provision the accounts and then uses CloudFormation StackSets to apply the baseline configuration to the new accounts. This functions but introduces a second, separate mechanism that must be maintained and coordinated with account creation; limelight04 preferred B, but the additional StackSets step is exactly the recurring overhead the AFC blueprint exists to avoid. C provisions the accounts with Organizations and then uses an AWS Lambda function in the management account that assumes the Organizations access role to apply the baseline. This requires developing and operating a custom function and does not integrate with Control Tower's own provisioning flow, so guardrails and baseline are applied by two unrelated mechanisms. D provisions dedicated environment accounts, an audit account, and a CI/CD account with Organizations and applies the baseline with StackSets. This has the same two-mechanism problem as B while additionally bypassing the Control Tower account factory that would apply the guardrails at creation. A is correct.Community Comment Notes
Community voted A unanimously, with only limelight04 dissenting for B. jamesf identified the keywords as AWS Control Tower Account Factory Customization and explained that A meets the requirements with the least operational overhead by leveraging the account factory's blueprint mechanism. trungtd noted that all the options are possible but A is the least operational overhead. KaranNishad and tgv selected A, with KaranNishad naming Account Factory Customization directly.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →