Basic Information
| Field | Value |
|---|---|
| English | AWS Control Tower |
| Full name | AWS Control Tower |
| Chinese | 多账户 Landing Zone 与治理 |
| Japanese | AWS Control Tower(マルチアカウント環境の構築・統制) |
| Exam frequency | ⭐⭐⭐⭐ |
| Often confused with | AWS Organizations / AWS Config |
One-line summary
Build and continuously govern a standardized multi-account AWS environment using best practices.
Core capabilities and use cases
- A landing zone provides a preconfigured multi-account foundation.
- Account Factory creates and configures new accounts from standardized templates.
- Preventive, detective, and proactive controls help enforce governance requirements.
- The dashboard centralizes account, OU, and control status.
- It uses Organizations and integrates with IAM Identity Center, Config, CloudTrail, and Service Catalog.
Exam focus and common pitfalls
- Choose Control Tower for a standardized landing zone, automatic account enrollment, or governance controls.
- Preventive controls often use SCPs; detective controls often use Config.
- Control Tower does not replace Organizations or workload-level architecture and security design.
Key takeaway
Organizations is the foundation; Control Tower builds and continuously governs the standardized environment.