exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 893 discussion

A company wants to isolate its workloads by creating an AWS account for each workload. The company needs a solution that centrally manages networking components for the workloads. The solution also must create accounts with automatic security controls (guardrails).

Which solution will meet these requirements with the LEAST operational overhead?

  • A. Use AWS Control Tower to deploy accounts. Create a networking account that has a VPC with private subnets and public subnets. Use AWS Resource Access Manager (AWS RAM) to share the subnets with the workload accounts.
  • B. Use AWS Organizations to deploy accounts. Create a networking account that has a VPC with private subnets and public subnets. Use AWS Resource Access Manager (AWS RAM) to share the subnets with the workload accounts.
  • C. Use AWS Control Tower to deploy accounts. Deploy a VPC in each workload account. Configure each VPC to route through an inspection VPC by using a transit gateway attachment.
  • D. Use AWS Organizations to deploy accounts. Deploy a VPC in each workload account. Configure each VPC to route through an inspection VPC by using a transit gateway attachment.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bujuman
Highly Voted 8 months, 2 weeks ago
Selected Answer: A
Statement: - The solution also must create accounts with automatic security controls (guardrails). https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html AWS Control Tower provides a pre-packaged set of guardrails (policies) and blueprints (best-practice configurations) to ensure that the environment complies with security and compliance standards. It’s designed to simplify the process of creating and managing a multi-account AWS environment while maintaining security and compliance.
upvoted 9 times
...
sandordini
Highly Voted 9 months, 1 week ago
Selected Answer: B
It's a hard one. I'd go for B Several accounts in an org, with central mgmt > AWS Organization Sharing resources among accounts > AWS RAM AWS Organizations and RAM typically work well together... Happy to be challenged, of course.
upvoted 6 times
sandordini
9 months, 1 week ago
Although automatic security control could be a hint for AWS Control Tower (set up and operate your multi-account AWS environment with prescriptive controls)
upvoted 1 times
...
...
FlyingHawk
Most Recent 1 week, 5 days ago
Selected Answer: A
AWS Control Tower automates the setup of accounts and guardrails, reducing the need for manual configuration. Centralizing networking in a single account and sharing resources via AWS RAM minimizes the operational effort required to manage networking across multiple accounts.
upvoted 1 times
...
LeonSauveterre
1 month ago
Selected Answer: A
A - It works but on first sight I eliminated this option because if you have a large number of workloads, the manual work would be too much. However, other options have bigger issues so this one is pretty great actually. B - AWS Organizations alone does not provide the automatic guardrails, so it requires manual implementation of security controls and policies. C - Also a valid choice, especially if more isolation and advanced traffic inspection are needed, but it introduces more complexity than option A and might require more operational oversight, which would not be ideal for "least operational overhead." D - Like B.
upvoted 1 times
...
mk168898
3 months, 2 weeks ago
guard rails => AWS control tower
upvoted 2 times
...
XXXXXlNN
3 months, 4 weeks ago
A Guardrails >> AWS Control Tower
upvoted 3 times
...
dhewa
5 months, 2 weeks ago
Selected Answer: A
AWS Control Tower provides built-in guardrails and automates the creation of accounts with security controls.
upvoted 2 times
...
muhammadahmer36
6 months, 3 weeks ago
Selected Answer: A
A. Use AWS Control Tower to deploy accounts. Create a networking account that has a VPC with private subnets and public subnets. Use AWS Resource Access Manager (AWS RAM) to share the subnets with the workload accounts.
upvoted 2 times
...
emakid
7 months, 1 week ago
Selected Answer: A
It leverages AWS Control Tower for automated account deployment and management, along with AWS RAM for centralized networking management, thus minimizing operational overhead while meeting the company's requirements for workload isolation and automatic security controls.
upvoted 3 times
...
stalk98
8 months, 2 weeks ago
Selected Answer: A
answer is A
upvoted 2 times
...
Tomrr
8 months, 2 weeks ago
Selected Answer: A
Anser is A, Control Tower has guardrails AWS Audit Manager provides an AWS Control Tower Guardrails framework to assist you with your audit preparation.
upvoted 2 times
...
Scheldon
8 months, 2 weeks ago
Selected Answer: A
Taking into consideration that AWS Control Tower is Orchestrator for AWS Organization which applies guardrails, I think A is a good choose. https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html
upvoted 3 times
...
1223d0e
9 months, 1 week ago
Please explain why the answer is option A
upvoted 1 times
jackey_feng
8 months, 4 weeks ago
I prefer B which is free. A may cause fee for sevice used while I am not sure about it.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago