Build an Account Factory Customization blueprint with the baseline and provision every account from it

Answer Correct answer: A — create an Account Factory Customization blueprint with the baseline and provision every account from it.

A company needs to adopt a multi-account strategy to deploy its applications and the associated CI/CD infrastructure. The company has created an organization in AWS Organizations that has all features enabled. The company has configured AWS Control Tower and has set up a landing zone. The company needs to use AWS Control Tower controls (guardrails) in all AWS accounts in the organization. The company must create the accounts for a multi-environment application and must ensure that all accounts are configured to an initial baseline. Which solution will meet these requirements with the LEAST operational overhead?

  1. Create an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the baseline configuration. Use AWS Control Tower Account Factory to provision a dedicated AWS account for each environment and a CI/CD account by using the blueprint. Correct Answer
  2. Use AWS Control Tower Account Factory to provision a dedicated AWS account for each environment and a CI/CD account. Use AWS CloudFormation StackSets to apply the baseline configuration to the new accounts.
  3. Use Organizations to provision a multi-environment AWS account and a CI/CD account. In the Organizations management account, create an AWS Lambda function that assumes the Organizations access role to apply the baseline configuration to the new accounts.
  4. Use Organizations to provision a dedicated AWS account for each environment, an audit account, and a CI/CD account. Use AWS CloudFormation StackSets to apply the baseline configuration to the new accounts.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Account Factory Customization is the Control Tower feature designed for exactly this: a blueprint whose baseline is applied to every account the account factory provisions, so the configuration and the guardrails arrive together as a single provisioning action (A). Option B provisions accounts and then applies the baseline with StackSets, which is a second, separate mechanism that must be maintained and coordinated with account creation. Options C and D bypass the account factory entirely and provision accounts through Organizations directly, which means Control Tower's baseline and guardrails are not applied automatically at creation.

Every account must receive the Control Tower guardrails and an initial baseline configuration, with the least operational overhead. An Account Factory Customization blueprint packages the baseline configuration so it is part of how accounts are created, and provisioning each environment account and the CI/CD account from that blueprint means the baseline and the guardrails are applied automatically as part of account creation, with no separate deployment step to maintain.

Using the Control Tower account factory and then applying the baseline with CloudFormation StackSets (B) — this works but introduces a second mechanism that must be maintained and kept in step with account creation, which is precisely the operational overhead the AFC blueprint removes. Provisioning accounts with Organizations and applying the baseline with a Lambda in the management account (C) — writing and operating a custom function to configure new accounts adds code and does not integrate with the Control Tower baseline. Provisioning accounts directly with Organizations plus StackSets (D) — the same two-mechanism problem as B, and it also bypasses the account factory that would apply the guardrails.

Community Discussion (5 comments)

limelight04 👍 1
Answer is B Use AWS Control Tower Account Factory to provision dedicated AWS accounts for each environment and a CI/CD account. Then, use AWS CloudFormation StackSets to apply the baseline configuration to the new accounts. This approach simplifies account provisioning and ensures consistency across environments while minimizing manual effort.
jamesf 👍 4 Selected: A
keywords: AWS Control Tower Account Factory Customization (AFC) Option A is the best choice as it meets all the requirements with the least operational overhead by leveraging AWS Control Tower’s Account Factory and Customization features. This option provides an automated, compliant, and consistent approach to account provisioning and baseline configuration.
tgv 👍 1
---> A
trungtd 👍 1 Selected: A
All of these options are possible. But A is the LEAST operational overhead
KaranNishad 👍 2 Selected: A
AWS Control Tower Account Factory Customization (AFC)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is that every account in the organization receives the Control Tower guardrails and an initial baseline configuration, and that this happen with the least operational overhead. An Account Factory Customization blueprint is Control Tower's mechanism for baking a baseline configuration into the account creation process itself, so provisioning each dedicated environment account and the CI/CD account from that blueprint applies the baseline and the guardrails as one atomic step with no follow-up deployment to schedule or maintain (A). Because the baseline travels with the blueprint, accounts created later receive the identical configuration automatically, which is what keeps future accounts compliant with the same baseline. A is the correct answer.

Why the Other Options Are Wrong

B uses the Control Tower account factory to provision the accounts and then uses CloudFormation StackSets to apply the baseline configuration to the new accounts. This functions but introduces a second, separate mechanism that must be maintained and coordinated with account creation; limelight04 preferred B, but the additional StackSets step is exactly the recurring overhead the AFC blueprint exists to avoid. C provisions the accounts with Organizations and then uses an AWS Lambda function in the management account that assumes the Organizations access role to apply the baseline. This requires developing and operating a custom function and does not integrate with Control Tower's own provisioning flow, so guardrails and baseline are applied by two unrelated mechanisms. D provisions dedicated environment accounts, an audit account, and a CI/CD account with Organizations and applies the baseline with StackSets. This has the same two-mechanism problem as B while additionally bypassing the Control Tower account factory that would apply the guardrails at creation. A is correct.

Community Comment Notes

Community voted A unanimously, with only limelight04 dissenting for B. jamesf identified the keywords as AWS Control Tower Account Factory Customization and explained that A meets the requirements with the least operational overhead by leveraging the account factory's blueprint mechanism. trungtd noted that all the options are possible but A is the least operational overhead. KaranNishad and tgv selected A, with KaranNishad naming Account Factory Customization directly.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide