Create the AWSControlTowerExecution role in the new account and enroll it with the Service Catalog ProvisionProduct API
A company recently configured AWS Control Tower in its organization in AWS Organizations. The company enrolled all existing AWS accounts in AWS Control Tower. The company wants to ensure that all new AWS accounts are automatically enrolled in AWS Control Tower. The company has an existing AWS Step Functions workflow that creates new AWS accounts and performs any actions required as part of account creation. The Step Functions workflow is defined in the same AWS account as AWS Control Tower. Which combination of steps should the company add to the Step Functions workflow to meet these requirements? (Choose two.)
Community Votes
78% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
AWS Control Tower is built on Service Catalog: enrollment means provisioning the Control Tower landing zone product for the account, which is the ProvisionProduct API call (D). Independently, every managed account needs the AWSControlTowerExecution role so the Control Tower administrator account can assume it and apply governance (C). Option E's Organizations EnableAWSServiceAccess call enables the service integration but does not perform the landing zone enrollment. Options A and B use EventBridge events, but CreateManagedAccount and SetupLandingZone are request-side events describing intent, not a mechanism that enrolls an account that has already been created by the workflow.
Enrolling a newly created account into an existing AWS Control Tower landing zone requires two things in the workflow: the new account must contain an AWSControlTowerExecution role that the Control Tower administrator account can assume, and the account must be enrolled through the Service Catalog by calling the ProvisionProduct API operation against the Control Tower landing zone product. Enabling AWS service access with Organizations is necessary for Control Tower to operate but is not the enrollment step that lands the account in the landing zone.
Calling the Organizations EnableAWSServiceAccess API for controltower.amazonaws.com (E) — this enables AWS service access for the organization, which is a prerequisite for Control Tower to manage accounts, but it is not the action that enrolls an account into the landing zone. Creating EventBridge rules on aws.controltower with CreateManagedAccount or SetupLandingZone detail types (A and B) — these event types describe control-plane activity and cannot retroactively enroll an account; a workflow that creates an account must invoke the Service Catalog enrollment directly. CHRIS12722222 verified against the AWS architecture blog that the enrollment code calls the ProvisionProduct API, which is the decisive evidence for D.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS Control Tower manages member accounts through Service Catalog, so enrolling a new account means calling the Service Catalog ProvisionProduct API to provision the landing zone product for that account (D). For Control Tower to then manage the account, the account must also contain an AWSControlTowerExecution role that the Control Tower administrator account is able to assume, which is created in the new account as part of the workflow (C). Together these two steps perform the enrollment of an account created by an existing account-factory workflow. The AWS architecture blog on enrolling existing accounts into Control Tower confirms that the automation calls the ProvisionProduct API, which is the direct evidence for D.Why the Other Options Are Wrong
A creates an EventBridge event with an aws.controltower source and a CreateManagedAccount detail type carrying the new account details, and B does the same with a SetupLandingZone detail type. These event types describe Control Tower control-plane activity; creating a rule on them does not cause an already-created account to be enrolled, and emitting such an event with account details does not perform the enrollment either. E calls the Organizations EnableAWSServiceAccess API with controltower.amazonaws.com. Enabling service access is a prerequisite so that Control Tower can operate in the organization, but it is not the step that enrolls an account into the landing zone, which is why youonebe's and teo2157's preference for C and E is incomplete. C and D are the correct combination.Community Comment Notes
Community voted C,D (78), with C,E a 22 percent minority. CHRIS12722222 provided the decisive evidence by referencing the AWS architecture blog on enrolling existing accounts into Control Tower and noting that the sample code calls the ProvisionProduct API. Ky_24 and youonebe both confirmed that the AWSControlTowerExecution role must exist in each managed account. f4b18ba also arrived at C,D, noting a typo in his earlier answer.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →