Create a Control Tower landing zone with per-team OUs, enroll existing accounts, and provision new accounts through it

Answer Correct answer: B — create a Control Tower landing zone with per-team OUs, enroll existing accounts, and provision new accounts through it.

A company has started using AWS across several teams. Each team has multiple accounts and unique security profiles. The company manages the accounts in an organization in AWS Organizations. Each account has its own configuration and security controls. The company's DevOps team wants to use preventive and detective controls to govern all accounts. The DevOps team needs to ensure the security of accounts now and in the future as the company creates new accounts in the organization. Which solution will meet these requirements?

  1. Use Organizations to create OUs that have appropriate SCPs attached for each team. Place team accounts in the appropriate OUs to apply security controls. Create any new team accounts in the appropriate OUs.
  2. Create an AWS Control Tower landing zone. Configure OUs and appropriate controls in AWS Control Tower for the existing teams. Configure trusted access for AWS Control Tower. Enroll the existing accounts in the appropriate OUs that match the appropriate security policies for each team. Use AWS Control Tower to provision any new accounts. Correct Answer
  3. Create AWS CloudFormation stack sets in the organization's management account. Configure a stack set that deploys AWS Config with configuration rules and remediation actions for all controls to each account in the organization. Update the stack sets to deploy to new accounts as the accounts are created.
  4. Configure AWS Config to manage the AWS Config rules across all AWS accounts in the organization. Deploy conformance packs that provide AWS Config rules and remediation actions across the organization.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Control Tower is the only option that natively implements preventive, detective, and proactive controls and applies them to accounts created later without any extra automation (B). Option A relies only on SCPs attached to OUs, which covers preventive guardrails but not detective controls, and it requires the team to remember to place each new account correctly. Option C's StackSets must be manually updated whenever accounts are added, and StackSets do not deploy to the management account at all, as documented. Option D proposes AWS Config managing Config rules across accounts with conformance packs, but that is detective-only and does not provide preventive controls.

The requirement is preventive and detective governance across all current accounts plus automatic coverage of accounts created in the future, with a different security profile per team. An AWS Control Tower landing zone expresses those profiles directly: OUs are configured with the appropriate controls, existing accounts are enrolled into the OU matching their team's policy, and trusted access is enabled so Control Tower can manage them. Because Control Tower provisions new accounts through the account factory, future accounts land inside those OUs with the controls already applied.

Creating OUs with SCPs attached for each team (A) — SCPs deliver preventive guardrails but nothing detective, so a purely SCP-based design cannot satisfy the requirement for both preventive and detective controls, and new accounts depend on manual placement. Using StackSets updated as accounts are created (C) — the engineering effort of updating StackSets for every new account adds recurring overhead, and StackSets cannot deploy stack instances to the management account, which is a documented limitation. Configuring AWS Config with conformance packs across the organization (D) — conformance packs provide detective rules and remediation, but no preventive guardrails, so the preventive half of the requirement is unmet.

Community Discussion (6 comments)

c3518fc 👍 6 Selected: B
A control is a high-level rule that provides ongoing governance for your overall AWS environment. It's expressed in plain language. AWS Control Tower implements preventive, detective, and proactive controls that help you govern your resources and monitor compliance across groups of AWS accounts. https://docs.aws.amazon.com/controltower/latest/controlreference/controls.html
Seoyong 👍 5 Selected: B
About controls in AWS Control Tower: https://docs.aws.amazon.com/controltower/latest/userguide/controls.html
dkp 👍 3 Selected: B
answer B
Ola2234 👍 2
Option B. Keyword: Preventive and detective controls to govern all accounts. This service is provided by guardrails as part of AWS Control Tower.
WhyIronMan 👍 3 Selected: B
https://docs.aws.amazon.com/controltower/latest/userguide/controls.html
ogerber 👍 2 Selected: B
its B for me

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement has two halves that must hold now and in the future: preventive and detective controls governing every account today, and automatic coverage for accounts created later. AWS Control Tower implements preventive, detective, and proactive controls as first-class concepts, so configuring OUs with the appropriate controls for the existing teams, enabling trusted access for Control Tower, and enrolling each existing account into the OU whose policy matches its team satisfies the governance requirement in a single place (B). For future accounts, Control Tower's account factory is the provisioning path, so any account created through it is placed into the governed OUs with the controls already applied, which is what makes the future coverage automatic rather than a manual step. B is the correct answer.

Why the Other Options Are Wrong

A uses Organizations to create OUs with appropriate SCPs attached and to place team accounts in them. Service control policies provide preventive guardrails, but SCPs alone deliver no detective controls, so this design cannot satisfy a requirement that explicitly asks for both preventive and detective governance. It also leaves the placement of each new account as a manual responsibility. C creates CloudFormation stack sets in the management account that deploy AWS Config rules and remediation actions, and states they will be updated as accounts are created. This covers detective controls but not preventive ones, requires an update for every new account which is recurring operational work, and there is a documented limitation that StackSets does not deploy stack instances to the organization's management account. D configures AWS Config to manage rules across all accounts and deploys conformance packs. Conformance packs are a detective mechanism delivering rules and remediation actions, so the preventive half of the requirement is not met. B is correct.

Community Comment Notes

Community voted B unanimously. c3518fc explained that a control is a high-level rule providing ongoing governance and that Control Tower implements preventive, detective, and proactive controls, which is exactly the terminology in the requirement. Seoyong and WhyIronMan both linked the AWS Control Tower controls documentation. dkp and Ola2234 confirmed B, with Ola2234 noting that guardrails provided as part of Control Tower are what the question's preventive and detective wording points to. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide