A. Create a landing zone in the security OU of the large company’s AWS Control Tower landing zone. Provide the account’s email address, the account owners first and last name, and the name of the landing zone created in the security OU to complete the AWS Control Tower Account Factory enrollment request.
B. Create and apply SCPs in the destination OU to restrict the types of resources that can be created in the small company’s account. Assess the impact of the applied SCPs on the small company’s account. Delete existing SCPs in the small company’s account.
C. Create an AWS Config conformance pack that contains the policies that are currently applied to the large company’s account. Use AWS Config to assess the impact that enrollment in AWS Control Tower will have on the small company’s account. Delete the configuration recorder and delivery channels from the AWS Config settings of the small company’s account.
D. Enroll the OU of the small company’s account in the large company’s AWS Control Tower environment. Specify the destination OU in the large company’s AWS Control Tower landing zone as the receiving OU in the request.
E. Create an AWSControlTowerExecution role in the small company’s account. Provide the account’s email address, the account owner’s first and last name, and the destination OU to complete the AWS Control Tower Account Factory enrollment request.

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.