Examtopics

AWS Certified DevOps Engineer - Professional
  • Topic 1 Question 336

    A company uses an organization in AWS Organizations to manage 10 AWS accounts. All features are enabled, and trusted access for AWS CloudFormation is enabled.

    A DevOps engineer needs to use CloudFormation to deploy an IAM role to the Organizations management account and all member accounts in the organization.

    Which solution will meet these requirements with the LEAST operational overhead?

    • Create a CloudFormation StackSet that has service-managed permissions. Set the root OU as a deployment target.

    • Create a CloudFormation StackSet that has service-managed permissions. Set the root OU as a deployment target. Deploy a separate CloudFormation stack in the Organizations management account.

    • Create a CloudFormation StackSet that has self-managed permissions. Set the root OU as a deployment target.

    • Create a CloudFormation StackSet that has self-managed permissions. Set the root OU as a deployment target. Deploy a separate CloudFormation stack in the Organizations management account.


    シャッフルモード