Ends in
00
days
00
hrs
00
mins
00
secs
SHOP NOW

🚀 30% OFF All Solutions Architect Reviewers

Find answers, ask questions, and connect with our
community around the world.

Home Forums AWS AWS Certified Advanced Networking – Specialty Review Mode Bonus Set 3 – AWS Certified Advanced Networking Question: #24

  • Review Mode Bonus Set 3 – AWS Certified Advanced Networking Question: #24

  • thewebguru

    Member
    March 5, 2026 at 11:12 pm

    Hello,

    I would like to report a possible issue in:

    Quiz: Review Mode Bonus Set 3 – AWS Certified Advanced Networking
    Question: #24

    In the explanation, the option “Establish an AWSControlTowerBlueprintAccess role in the central network services account…” is listed as one of the correct answers. However, this seems inconsistent with how AWS Control Tower operates.

    From the AWS documentation, the standard roles used by Control Tower include roles such as AWSControlTowerExecution, AWSControlTowerAdmin, and AWSControlTowerStackSetRole. I could not find any official reference to a role named AWSControlTowerBlueprintAccess. Additionally, creating an IAM role by itself would not automate VPC provisioning or Transit Gateway attachments across accounts, which appears to be the core requirement of the question.

    For this reason, it seems more consistent that the automation-related options (such as Account Factory Customization (AFC) and Service Catalog with CloudFormation) would address the requirement of minimizing operational effort across accounts.

    Could you please confirm whether the answer explanation might need clarification or correction?

    Thank you for your time and for maintaining these practice exams.Hello,

    I would like to report a possible issue in:

    Quiz: Review Mode Bonus Set 3 – AWS Certified Advanced Networking
    Question: #24

    In the explanation, the option “Establish an AWSControlTowerBlueprintAccess role in the central network services account…” is listed as one of the correct answers. However, this seems inconsistent with how AWS Control Tower operates.

    From the AWS documentation, the standard roles used by Control Tower include roles such as AWSControlTowerExecution, AWSControlTowerAdmin, and AWSControlTowerStackSetRole. I could not find any official reference to a role named AWSControlTowerBlueprintAccess. Additionally, creating an IAM role by itself would not automate VPC provisioning or Transit Gateway attachments across accounts, which appears to be the core requirement of the question.

    For this reason, it seems more consistent that the automation-related options (such as Account Factory Customization (AFC) and Service Catalog with CloudFormation) would address the requirement of minimizing operational effort across accounts.

    Could you please confirm whether the answer explanation might need clarification or correction?

    Thank you for your time and for maintaining these practice exams.

  • Nikee-TutorialsDojo

    Administrator
    March 9, 2026 at 2:32 pm

    Hello thewebguru,

    Thank you for taking the time to report this and for pointing out the inconsistency so clearly.

    After reviewing the current AWS documentation, the role name AWSControlTowerBlueprintAccess does exist in AWS Control Tower. It is used in the Account Factory Customization (AFC) workflow so that AWS Control Tower can access and share the AWS Service Catalog blueprint product during account provisioning. That said, the concern remains valid: the role itself does not provision VPCs or create Transit Gateway attachments. Its purpose is to support the blueprint-based customization workflow, not to perform the network automation on its own.

    Because of that, the explanation can be improved for clarity. The automation aspect of the solution is primarily addressed by Account Factory Customization (AFC) together with an AWS Service Catalog product backed by CloudFormation. Those are the components that enable consistent VPC deployment across new and existing accounts with lower operational effort. The AWSControlTowerBlueprintAccess role is a supporting prerequisite for AFC, rather than the direct mechanism that creates the networking resources.

    We will review the wording of the explanation for this item and update it accordingly.

    Thanks again for helping us improve the quality and accuracy of the practice exams. Feedback like this is greatly appreciated.

    Best regards,
    Nikee @ Tutorials Dojo

Viewing 1 - 2 of 2 replies

Log in to reply.

Original Post
0 of 0 posts June 2018
Now
Skip to content