Create the AWSControlTowerExecution role in the new account and enroll it with the Service Catalog ProvisionProduct API

Answer Correct answer: C, D — create the AWSControlTowerExecution role in the new account and enroll it via the Service Catalog ProvisionProduct API.

A company recently configured AWS Control Tower in its organization in AWS Organizations. The company enrolled all existing AWS accounts in AWS Control Tower. The company wants to ensure that all new AWS accounts are automatically enrolled in AWS Control Tower. The company has an existing AWS Step Functions workflow that creates new AWS accounts and performs any actions required as part of account creation. The Step Functions workflow is defined in the same AWS account as AWS Control Tower. Which combination of steps should the company add to the Step Functions workflow to meet these requirements? (Choose two.)

  1. Create an Amazon EventBridge event that has an aws.controltower source and a CreateManagedAccount detail-type. Add the details of the new AWS account to the detail field of the event.
  2. Create an Amazon EventBridge event that has an aws.controltower source and a SetupLandingZone detail-type. Add the details of the new AWS account to the detail field of the event.
  3. Create an AWSControlTowerExecution role in the new AWS account. Configure the role to allow the AWS Control Tower administrator account to assume the role. Correct Answer
  4. Call the AWS Service Catalog ProvisionProduct API operation with the details of the new AWS account. Correct Answer
  5. Call the Organizations EnableAWSServiceAccess API operation with the controltower.amazonaws.com service name and the details of the new AWS account.

Community Votes

CD
78%
CE
22%

78% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS Control Tower is built on Service Catalog: enrollment means provisioning the Control Tower landing zone product for the account, which is the ProvisionProduct API call (D). Independently, every managed account needs the AWSControlTowerExecution role so the Control Tower administrator account can assume it and apply governance (C). Option E's Organizations EnableAWSServiceAccess call enables the service integration but does not perform the landing zone enrollment. Options A and B use EventBridge events, but CreateManagedAccount and SetupLandingZone are request-side events describing intent, not a mechanism that enrolls an account that has already been created by the workflow.

Enrolling a newly created account into an existing AWS Control Tower landing zone requires two things in the workflow: the new account must contain an AWSControlTowerExecution role that the Control Tower administrator account can assume, and the account must be enrolled through the Service Catalog by calling the ProvisionProduct API operation against the Control Tower landing zone product. Enabling AWS service access with Organizations is necessary for Control Tower to operate but is not the enrollment step that lands the account in the landing zone.

Calling the Organizations EnableAWSServiceAccess API for controltower.amazonaws.com (E) — this enables AWS service access for the organization, which is a prerequisite for Control Tower to manage accounts, but it is not the action that enrolls an account into the landing zone. Creating EventBridge rules on aws.controltower with CreateManagedAccount or SetupLandingZone detail types (A and B) — these event types describe control-plane activity and cannot retroactively enroll an account; a workflow that creates an account must invoke the Service Catalog enrollment directly. CHRIS12722222 verified against the AWS architecture blog that the enrollment code calls the ProvisionProduct API, which is the decisive evidence for D.

Community Discussion (6 comments)

teo2157 👍 1 Selected: CE
Agrees with CE based on the blog that CHRIS1272222 provided
youonebe 👍 1 Selected: CE
C - AWS Control Tower requires the AWSControlTowerExecution role to be created in each managed account. This role allows AWS Control Tower to manage the account and enforce governance and compliance rules. When a new account is created, AWS Control Tower will need this role to carry out management tasks. E - The EnableAWSServiceAccess API operation is used to enable AWS Control Tower service access in AWS Organizations. This action ensures that AWS Control Tower can operate across the organization and manage new accounts that are created within the organization. By enabling service access for Control Tower, new accounts can be automatically enrolled in the governance and management processes of Control Tower.
CHRIS12722222 👍 3 Selected: CD
Read blog https://aws.amazon.com/blogs/architecture/field-notes-enroll-existing-aws-accounts-into-aws-control-tower/ Download the python code and you will see it calls the ProvisionProduct API in method provision_sc_product
Ky_24 👍 4 Selected: CD
Option Details: 1. C. Create an AWSControlTowerExecution role: • AWS Control Tower requires an AWSControlTowerExecution role in new accounts. • This role allows AWS Control Tower to assume control of the account and apply the necessary guardrails, policies, and configurations. • Without this role, AWS Control Tower cannot manage the account. 2. D. Call the AWS Service Catalog ProvisionProduct API operation: • Account Factory uses AWS Service Catalog to create and enroll new accounts into AWS Control Tower. • The ProvisionProduct API operation allows programmatic provisioning of new accounts through Account Factory, ensuring enrollment into Control Tower governance.
f4b18ba 👍 2
Answer: CD (had a typo)
f4b18ba 👍 3
Answer: CE WSControlTowerExecution Role (Option C): For AWS Control Tower to manage accounts, each account must have the AWSControlTowerExecution role, which allows the AWS Control Tower administrator account to assume the role and apply required policies and controls. Creating this role in the new account enables Control Tower to perform management operations as needed. Service Catalog ProvisionProduct API (Option D): AWS Control Tower uses AWS Service Catalog products to provision and manage accounts. Calling the ProvisionProduct API operation as part of the Step Functions workflow allows the new account to be enrolled in Control Tower by provisioning it through the appropriate Service Catalog product. This step ensures that the new account is enrolled in the AWS Control Tower landing zone.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Control Tower manages member accounts through Service Catalog, so enrolling a new account means calling the Service Catalog ProvisionProduct API to provision the landing zone product for that account (D). For Control Tower to then manage the account, the account must also contain an AWSControlTowerExecution role that the Control Tower administrator account is able to assume, which is created in the new account as part of the workflow (C). Together these two steps perform the enrollment of an account created by an existing account-factory workflow. The AWS architecture blog on enrolling existing accounts into Control Tower confirms that the automation calls the ProvisionProduct API, which is the direct evidence for D.

Why the Other Options Are Wrong

A creates an EventBridge event with an aws.controltower source and a CreateManagedAccount detail type carrying the new account details, and B does the same with a SetupLandingZone detail type. These event types describe Control Tower control-plane activity; creating a rule on them does not cause an already-created account to be enrolled, and emitting such an event with account details does not perform the enrollment either. E calls the Organizations EnableAWSServiceAccess API with controltower.amazonaws.com. Enabling service access is a prerequisite so that Control Tower can operate in the organization, but it is not the step that enrolls an account into the landing zone, which is why youonebe's and teo2157's preference for C and E is incomplete. C and D are the correct combination.

Community Comment Notes

Community voted C,D (78), with C,E a 22 percent minority. CHRIS12722222 provided the decisive evidence by referencing the AWS architecture blog on enrolling existing accounts into Control Tower and noting that the sample code calls the ProvisionProduct API. Ky_24 and youonebe both confirmed that the AWSControlTowerExecution role must exist in each managed account. f4b18ba also arrived at C,D, noting a typo in his earlier answer.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide