Q: 12
A company is using AWS Organizations with nested OUs to manage AWS accounts. The company has
a custom compliance monitoring service for the accounts. The monitoring service runs as an AWS
Lambda function and is invoked by Amazon EventBridge Scheduler.
The company needs to deploy the monitoring service in all existing and future accounts in the
organization. The company must avoid using the organization's management account when the
management account is not required.
Which solution will meet these requirements?
Options
Discussion
Probably B since it avoids using the management account and handles auto deployment to all current and future accounts. A is too manual, C/D don't guarantee org-wide auto rollout. Pretty sure this is what AWS recommends.
C/D? I'm honestly a bit confused here since both mention Systems Manager, but B seems like the better fit because it talks about delegated admin and targets org root with auto deployment. I think B meets the auto-deploy requirement, but would love a sanity check from someone who's done this.
Be respectful. No spam.