Question 132
An enterprise company is building an infrastructure services platform for its users. The company has the following requirements: • Provide least privilege access to users when launching AWS infrastructure so users cannot provision unapproved services. • Use a central account to manage the creation of infrastructure services. • Provide the ability to distribute infrastructure services to multiple accounts in AWS Organizations. • Provide the ability to enforce tags on any infrastructure that is started by users. Which combination of actions using AWS services will meet these requirements? (Choose three.)
Show Answer
AWS Service Catalog is designed for centrally managed, approved infrastructure with least privilege. Option B uses CloudFormation templates as Service Catalog products shared across AWS Organizations, satisfying central management and multi-account distribution. Option D restricts users to ServiceCatalogEndUserAccess and uses launch constraints and automation, enforcing least privilege and controlled provisioning. Option E uses Service Catalog TagOption Library to enforce mandatory tags on all provisioned infrastructure. Other options lack proper enforcement or bypass Service Catalog controls.