Home › Forums › AWS › AWS Certified Advanced Networking – Specialty › Review Mode Bonus Set 3 – AWS Certified Advanced Networking Question: #24
-
Review Mode Bonus Set 3 – AWS Certified Advanced Networking Question: #24
Nikee-TutorialsDojo updated 6 months ago
2 Members
·
2
Posts
-
Hello,
I would like to report a possible issue in:
Quiz: Review Mode Bonus Set 3 – AWS Certified Advanced Networking
Question: #24In the explanation, the option “Establish an AWSControlTowerBlueprintAccess role in the central network services account…” is listed as one of the correct answers. However, this seems inconsistent with how AWS Control Tower operates.
From the AWS documentation, the standard roles used by Control Tower include roles such as AWSControlTowerExecution, AWSControlTowerAdmin, and AWSControlTowerStackSetRole. I could not find any official reference to a role named AWSControlTowerBlueprintAccess. Additionally, creating an IAM role by itself would not automate VPC provisioning or Transit Gateway attachments across accounts, which appears to be the core requirement of the question.
For this reason, it seems more consistent that the automation-related options (such as Account Factory Customization (AFC) and Service Catalog with CloudFormation) would address the requirement of minimizing operational effort across accounts.
Could you please confirm whether the answer explanation might need clarification or correction?
Thank you for your time and for maintaining these practice exams.Hello,
I would like to report a possible issue in:
Quiz: Review Mode Bonus Set 3 – AWS Certified Advanced Networking
Question: #24In the explanation, the option “Establish an AWSControlTowerBlueprintAccess role in the central network services account…” is listed as one of the correct answers. However, this seems inconsistent with how AWS Control Tower operates.
From the AWS documentation, the standard roles used by Control Tower include roles such as AWSControlTowerExecution, AWSControlTowerAdmin, and AWSControlTowerStackSetRole. I could not find any official reference to a role named AWSControlTowerBlueprintAccess. Additionally, creating an IAM role by itself would not automate VPC provisioning or Transit Gateway attachments across accounts, which appears to be the core requirement of the question.
For this reason, it seems more consistent that the automation-related options (such as Account Factory Customization (AFC) and Service Catalog with CloudFormation) would address the requirement of minimizing operational effort across accounts.
Could you please confirm whether the answer explanation might need clarification or correction?
Thank you for your time and for maintaining these practice exams.
-
Hello thewebguru,
Thank you for taking the time to report this and for pointing out the inconsistency so clearly.
After reviewing the current AWS documentation, the role name AWSControlTowerBlueprintAccess does exist in AWS Control Tower. It is used in the Account Factory Customization (AFC) workflow so that AWS Control Tower can access and share the AWS Service Catalog blueprint product during account provisioning. That said, the concern remains valid: the role itself does not provision VPCs or create Transit Gateway attachments. Its purpose is to support the blueprint-based customization workflow, not to perform the network automation on its own.
Because of that, the explanation can be improved for clarity. The automation aspect of the solution is primarily addressed by Account Factory Customization (AFC) together with an AWS Service Catalog product backed by CloudFormation. Those are the components that enable consistent VPC deployment across new and existing accounts with lower operational effort. The AWSControlTowerBlueprintAccess role is a supporting prerequisite for AFC, rather than the direct mechanism that creates the networking resources.
We will review the wording of the explanation for this item and update it accordingly.
Thanks again for helping us improve the quality and accuracy of the practice exams. Feedback like this is greatly appreciated.
Best regards,
Nikee @ Tutorials Dojo
Log in to reply.