Create a Control Tower landing zone with per-team OUs, enroll existing accounts, and provision new accounts through it
A company has started using AWS across several teams. Each team has multiple accounts and unique security profiles. The company manages the accounts in an organization in AWS Organizations. Each account has its own configuration and security controls. The company's DevOps team wants to use preventive and detective controls to govern all accounts. The DevOps team needs to ensure the security of accounts now and in the future as the company creates new accounts in the organization. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Control Tower is the only option that natively implements preventive, detective, and proactive controls and applies them to accounts created later without any extra automation (B). Option A relies only on SCPs attached to OUs, which covers preventive guardrails but not detective controls, and it requires the team to remember to place each new account correctly. Option C's StackSets must be manually updated whenever accounts are added, and StackSets do not deploy to the management account at all, as documented. Option D proposes AWS Config managing Config rules across accounts with conformance packs, but that is detective-only and does not provide preventive controls.
The requirement is preventive and detective governance across all current accounts plus automatic coverage of accounts created in the future, with a different security profile per team. An AWS Control Tower landing zone expresses those profiles directly: OUs are configured with the appropriate controls, existing accounts are enrolled into the OU matching their team's policy, and trusted access is enabled so Control Tower can manage them. Because Control Tower provisions new accounts through the account factory, future accounts land inside those OUs with the controls already applied.
Creating OUs with SCPs attached for each team (A) — SCPs deliver preventive guardrails but nothing detective, so a purely SCP-based design cannot satisfy the requirement for both preventive and detective controls, and new accounts depend on manual placement. Using StackSets updated as accounts are created (C) — the engineering effort of updating StackSets for every new account adds recurring overhead, and StackSets cannot deploy stack instances to the management account, which is a documented limitation. Configuring AWS Config with conformance packs across the organization (D) — conformance packs provide detective rules and remediation, but no preventive guardrails, so the preventive half of the requirement is unmet.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement has two halves that must hold now and in the future: preventive and detective controls governing every account today, and automatic coverage for accounts created later. AWS Control Tower implements preventive, detective, and proactive controls as first-class concepts, so configuring OUs with the appropriate controls for the existing teams, enabling trusted access for Control Tower, and enrolling each existing account into the OU whose policy matches its team satisfies the governance requirement in a single place (B). For future accounts, Control Tower's account factory is the provisioning path, so any account created through it is placed into the governed OUs with the controls already applied, which is what makes the future coverage automatic rather than a manual step. B is the correct answer.Why the Other Options Are Wrong
A uses Organizations to create OUs with appropriate SCPs attached and to place team accounts in them. Service control policies provide preventive guardrails, but SCPs alone deliver no detective controls, so this design cannot satisfy a requirement that explicitly asks for both preventive and detective governance. It also leaves the placement of each new account as a manual responsibility. C creates CloudFormation stack sets in the management account that deploy AWS Config rules and remediation actions, and states they will be updated as accounts are created. This covers detective controls but not preventive ones, requires an update for every new account which is recurring operational work, and there is a documented limitation that StackSets does not deploy stack instances to the organization's management account. D configures AWS Config to manage rules across all accounts and deploys conformance packs. Conformance packs are a detective mechanism delivering rules and remediation actions, so the preventive half of the requirement is not met. B is correct.Community Comment Notes
Community voted B unanimously. c3518fc explained that a control is a high-level rule providing ongoing governance and that Control Tower implements preventive, detective, and proactive controls, which is exactly the terminology in the requirement. Seoyong and WhyIronMan both linked the AWS Control Tower controls documentation. dkp and Ola2234 confirmed B, with Ola2234 noting that guardrails provided as part of Control Tower are what the question's preventive and detective wording points to. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →