Share CloudFormation StackSets from an admin account and use SCPs to block non-compliant provisioning

Implement a secure and consistent deployment strategy for cloud resources. Develop a strategy to centrally deploy and manage AWS accounts.
Answer Correct answer: A, D — share CloudFormation StackSets from an admin account to the app account and use SCPs to block non-compliant provisioning.

A company that uses AWS Organizations is migrating workloads to AWS. The company's application team determines that the workloads will use Amazon EC2 instances, Amazon S3 buckets, Amazon DynamoDB tables, and Application Load Balancers. For each resource type, the company mandates that deployments must comply with the following requirements: • All EC2 instances must be launched from approved AWS accounts. • All DynamoDB tables must be provisioned with a standardized naming convention. • All infrastructure that is provisioned in any accounts in the organization must be deployed by AWS CloudFormation templates. Which combination of steps should the application team take to meet these requirements? (Choose two.)

  1. Create CloudFormation templates in an administrator AWS account. Share the stack sets with an application AWS account. Restrict the template to be used specifically by the application AWS account. Correct Answer
  2. Create CloudFormation templates in an application AWS account. Share the output with an administrator AWS account ta review compliant resources. Restrict output to only the administrator AWS account.
  3. Use permissions boundaries to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met.
  4. Use SCPs to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met. Correct Answer
  5. Activate AWS Config managed rules for each service in the application AWS account.

Community Votes

AD
50%
DE
50%

50% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

StackSets (A) centrally deploy approved, versioned templates to the app account, satisfying the 'all infra via CloudFormation from approved accounts' mandate proactively. SCPs (D) act as preventive guardrails that block resources not meeting conditions (e.g., wrong account or missing naming). Config managed rules (E) only detect after the fact, so they do not enforce the 'must comply' mandate on their own. A+D is the preventive, proactive pairing.

Three deployment mandates: EC2 only from approved accounts, DynamoDB with standardized naming, and all infrastructure via CloudFormation. Use AWS CloudFormation StackSets created in an administrator account and shared/restricted to the application account (enforces 'deployed by CloudFormation from an approved account'), and apply SCPs that deny provisioning of specific resources unless compliance conditions (e.g., approved account, naming) are met—preventing non-compliant resources org-wide.

Relying on AWS Config managed rules alone (E)—they are detective, not preventive, so non-compliant resources can still be created before a finding fires. Building templates in the app account and sharing output back to admin (B) inverts the approved-account control. Permissions boundaries (C) limit a principal but do not enforce organization-wide provisioning rules like SCPs.

Community Discussion (3 comments)

AWSLoverLoverLoverLoverLover 👍 1 Selected: DE
The correct answers are: D. Use SCPs to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met. E. Activate AWS Config managed rules for each service in the application AWS account. D. Use SCPs (Service Control Policies) to enforce compliance on resource provisioning. Why the other options are incorrect: A. Create CloudFormation templates in an administrator AWS account and share them. ❌ While CloudFormation helps with standardization, it does not enforce compliance. A user could still create resources manually without CloudFormation.
IPLogic 👍 1 Selected: AD
To meet the company’s compliance requirements for deploying workloads, the application team should take the following steps: A. Create CloudFormation templates in an administrator AWS account. Share the stack sets with an application AWS account. Restrict the template to be used specifically by the application AWS account. This ensures that all infrastructure is deployed using approved CloudFormation templates, maintaining consistency and compliance across the organization. D. Use SCPs to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met.
mikelord 👍 1
Agree, AD seems to be right answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CloudFormation StackSets (A) let an administrator account define compliant templates and deploy them to the application account, restricting use to that account—this enforces 'infrastructure deployed by CloudFormation from approved accounts.' SCPs (D) provide preventive guardrails that deny provisioning of specific resources unless the internal compliance conditions (approved account, naming convention) are satisfied. Together they proactively enforce all three mandates.

Why the Other Options Are Wrong

E (AWS Config managed rules) detects non-compliance but does not prevent it, so it cannot satisfy a 'deployments must comply' requirement alone. B creates templates in the app account, weakening the approved-account control. C (permissions boundaries) constrain a principal's max permissions but are not the organization-wide preventive mechanism SCPs are. A and D are the correct combination (note: community was split A+D vs D+E; A+D is the proactive enforcement pair).

Community Comment Notes

Community was split 50/50 between A,D and D,E. The stronger interpretation favors A,D: StackSets centrally deploy compliant CloudFormation from an approved admin account, and SCPs prevent non-compliant provisioning. D,E substitutes detective Config for the proactive StackSets deployment control.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide