Domain 1 · Organizational complexity
26% of the exam. Networks, security controls, resilience, accounts and cost visibility at company scale.
This domain assumes a company is already large: dozens of accounts, a data center that isn't going away, several teams, and auditors. The question is almost never "can this be done?". It's "what still works when there are 50 of them?"
| Task | What it's really asking | Pages |
|---|---|---|
| 1.1 Network connectivity | How to connect VPCs, data centers and Regions without a routing mess | Connecting VPCs, Hybrid connectivity, Hybrid DNS, VPC endpoints |
| 1.2 Security controls | Cross-account access, federation, encryption, central auditing | Cross-account access, Federation, Encryption, Central security logging |
| 1.3 Reliability and resilience | Which DR pattern meets a given RTO and RPO | Disaster recovery |
| 1.4 Multi-account environment | Organizations, Control Tower, SCPs, sharing resources | Multi-account governance, Central security logging |
| 1.5 Cost visibility | Tagging, purchasing options, rightsizing tools | Cost visibility, Pricing models |
Most of this domain's scenarios take place in a layout like this one. Networking lives in a hub account and is shared out. Security tooling lives in accounts that workload teams can't change. Workloads get their own accounts.