Share CloudFormation StackSets from an admin account and use SCPs to block non-compliant provisioning
A company that uses AWS Organizations is migrating workloads to AWS. The company's application team determines that the workloads will use Amazon EC2 instances, Amazon S3 buckets, Amazon DynamoDB tables, and Application Load Balancers. For each resource type, the company mandates that deployments must comply with the following requirements: • All EC2 instances must be launched from approved AWS accounts. • All DynamoDB tables must be provisioned with a standardized naming convention. • All infrastructure that is provisioned in any accounts in the organization must be deployed by AWS CloudFormation templates. Which combination of steps should the application team take to meet these requirements? (Choose two.)
Community Votes
50% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
StackSets (A) centrally deploy approved, versioned templates to the app account, satisfying the 'all infra via CloudFormation from approved accounts' mandate proactively. SCPs (D) act as preventive guardrails that block resources not meeting conditions (e.g., wrong account or missing naming). Config managed rules (E) only detect after the fact, so they do not enforce the 'must comply' mandate on their own. A+D is the preventive, proactive pairing.
Three deployment mandates: EC2 only from approved accounts, DynamoDB with standardized naming, and all infrastructure via CloudFormation. Use AWS CloudFormation StackSets created in an administrator account and shared/restricted to the application account (enforces 'deployed by CloudFormation from an approved account'), and apply SCPs that deny provisioning of specific resources unless compliance conditions (e.g., approved account, naming) are met—preventing non-compliant resources org-wide.
Relying on AWS Config managed rules alone (E)—they are detective, not preventive, so non-compliant resources can still be created before a finding fires. Building templates in the app account and sharing output back to admin (B) inverts the approved-account control. Permissions boundaries (C) limit a principal but do not enforce organization-wide provisioning rules like SCPs.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.