You must be able to design multi-account governance and cross-account networking: apply SCPs, centralize CloudTrail logs, share resources with RAM, and route traffic via Transit Gateway. The single most important thing is knowing SCPs filter permissions but never grant them.
Start practicing
Design Solutions for Organizational Complexity — choose a session length
Free · No account required
Domain overview
This domain covers multi-account and multi-VPC architectures on AWS: AWS Organizations, OUs, SCPs, Control Tower, centralized logging, cross-account IAM roles, VPC peering, Transit Gateway, RAM sharing, and hybrid DNS. Questions are scenario-based, asking you to pick configurations that enforce governance, centralize data, and connect networks across accounts correctly.
Exam objectives
Designing AWS Organizations OUs, SCPs, and Control Tower guardrails for multi-account governance
Configuring centralized AWS CloudTrail log delivery to a shared S3 bucket across accounts
Building cross-account access with IAM roles, resource policies, and AWS RAM sharing
Connecting VPCs and on-premises networks using Transit Gateway, peering, and Route 53 Resolver
Forgetting that SCPs only restrict maximum permissions and never grant access, so IAM policies must still allow the action
Assuming a VPC internet gateway alone gives internet access without a route table entry to 0.0.0.0/0
Overlooking that CloudTrail organization trails and S3 bucket policies must permit cross-account log delivery
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company has a centralized networking team that manages a shared VPC with multiple AWS Transit Gateway attachments. Application teams create VPCs in separate AWS accounts and want to connect to the shared VPC. The networking team needs to ensure that only authorized VPCs can connect to the shared VPC. What is the MOST secure and scalable way to manage this?
2A company uses AWS Control Tower to manage a multi-account environment. The security team needs to ensure that all accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket. What is the BEST way to achieve this?
3Refer to the exhibit. A company runs the AWS CLI command to list accounts in AWS Organizations. The company wants to remove the account '444444444444' from the organization. What must the company do first before it can remove this account?
4A multinational corporation is migrating its on-premises Active Directory (AD) to AWS Managed Microsoft AD. The company has a hub-and-spoke VPC topology with a central transit gateway. The AD domain controllers must be deployed in two different AWS Regions for disaster recovery. The corporate security policy requires that all AD traffic between Regions must traverse the transit gateway and be inspected by a third-party firewall appliance deployed in the inspection VPC. Which architecture meets these requirements?
5A company is using AWS Organizations with multiple organizational units (OUs). The security team needs to enforce that all newly created S3 buckets in the production OU have versioning enabled and are encrypted with AWS KMS. Which solution meets these requirements with minimal operational overhead?
6A company uses AWS Organizations and has a requirement that all root user activities in member accounts must be immediately reported to the security team. Which combination of actions should be taken to meet this requirement? (Choose the best answer.)
7A global e-commerce company is migrating its on-premises application to AWS. The application uses Active Directory for authentication and requires integration with AWS Managed Microsoft AD. The company has a multi-account strategy using AWS Organizations. Which TWO steps should the solutions architect take to ensure seamless authentication across the organization?
8Drag and drop the steps to set up a Direct Connect private virtual interface in the correct order.
9Drag and drop the steps to restore an Amazon RDS DB instance from a snapshot in the correct order.
10Drag and drop the steps to set up AWS CloudTrail for logging API activity in the correct order.
11Match each AWS service to its primary use case.
12Match each AWS migration service to its function.
13A company wants to implement a multi-account strategy using AWS Organizations. The security team requires that all new accounts added to the organization automatically inherit a baseline set of security controls, such as AWS CloudTrail and AWS Config rules. Which approach should the company use?
14A company uses AWS Organizations and wants to delegate administration of a specific service to a member account. The service must be able to perform actions across all accounts in the organization. Which steps should the company take?
15A company has a multi-account environment with AWS Organizations. The security team wants to enforce that all EC2 instances launched in any account must have a specific tag key 'CostCenter'. Which approach should be used?
16A company is implementing a multi-account strategy using AWS Organizations. They want to centralize CloudTrail logs from all accounts into a single S3 bucket in the management account. Which TWO steps are required to achieve this? (Choose two.)
17A company wants to implement AWS Organizations with multiple OUs to isolate development, testing, and production workloads. The company needs to ensure that production workloads are not impacted by changes in other OUs. Which TWO practices should the company follow? (Choose two.)
18A company is designing a multi-account strategy for its development, testing, and production environments. The security team requires that all accounts share a centralized logging solution. Which approach meets this requirement with the LEAST administrative overhead?
19A global company uses AWS Organizations with hundreds of accounts. The networking team needs to allow VPCs in different accounts to communicate privately using AWS Transit Gateway. The company wants to centralize management while allowing individual account owners to create and attach VPCs. Which solution meets these requirements?
20A company has a management account in AWS Organizations. It wants to delegate administration of AWS IAM Identity Center to a member account for user management. What is the correct way to achieve this?
21A company is migrating its on-premises Active Directory to AWS Managed Microsoft AD. The company has multiple VPCs across different accounts that need to authenticate against the same directory. What is the MOST scalable and secure way to provide this access?
22A company uses AWS Organizations with consolidated billing. The finance team wants to track costs by department. Each department has its own AWS account. Which feature should be used to map costs to departments?
23A company is implementing a multi-account strategy using AWS Organizations. They need to centralize logging of all API calls across accounts. Which solution meets this requirement with the least operational overhead?
24A company has multiple AWS accounts and wants to use AWS CloudFormation StackSets to deploy a common set of resources across all accounts. The StackSet should be managed from the management account. What permissions are required?
25A company wants to centralize management of AWS resources across multiple accounts using AWS Control Tower. What is a prerequisite for setting up Control Tower?
26A company wants to centrally manage IAM users across multiple AWS accounts using AWS IAM Identity Center (successor to AWS Single Sign-On). Which of the following are true? (Choose TWO.)
27A company is using AWS Organizations to manage multiple accounts. The security team requires that all newly created member accounts automatically have an AWS Config rule enabled that checks whether S3 buckets have default encryption enabled. Which solution should be used?
28A company is using AWS Organizations and wants to allow certain member accounts to create VPCs with specific CIDR ranges. Which mechanism should be used to enforce this restriction?
29A company is designing a multi-account strategy using AWS Organizations. The security team requires that all API calls to create or modify IAM roles are logged and alerted. Which TWO steps should be taken to meet this requirement?
30A company has a production AWS account that is part of an AWS Organization. The account has a VPC with a NAT gateway for internet access. The security team wants to ensure that all outbound traffic to the internet flows through a centralized inspection VPC in the security account for traffic inspection. Which architecture should be used?
31A company is migrating to AWS and plans to use a multi-account strategy. The management account will be used solely for administrative purposes. Which best practice should be followed when setting up AWS Organizations?
32A company has multiple AWS accounts and wants to share a centrally managed Amazon VPC subnet for workloads that require low latency. The VPC is in the networking account. Which solution meets these requirements with the LEAST operational overhead?
33A company uses AWS Organizations with 100 accounts. The security team wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. They create an SCP that denies all actions if MFA is not present. However, some users report that they cannot access the console even with MFA. What is the most likely reason?
34A company has an AWS Organization with multiple accounts. The central IT team wants to deploy a common set of AWS Config rules across all accounts in the production OU. Which approach is the MOST scalable and maintainable?
35A company uses AWS Organizations to manage multiple accounts. The central team wants to deploy a CloudFormation template that creates an S3 bucket with default encryption in every member account. Which THREE steps are required to accomplish this?
36A multinational corporation is deploying a multi-account AWS environment using AWS Organizations. The security team requires that all S3 buckets across all accounts be encrypted with a specific AWS KMS key managed by the security account. Which solution should the company implement to enforce this policy across the organization?
37A company uses AWS Organizations with 50 accounts. The network team wants to centrally manage VPC flow logs for all accounts, storing them in a central S3 bucket in the security account. The flow logs must be encrypted with a KMS key managed by the security account. What is the MOST efficient way to configure this?
38A company wants to provide its developers with access to a shared development environment in AWS. The developers are in different AWS accounts, and they need to assume an IAM role in the development account. What is the secure way to allow cross-account access?
39Refer to the exhibit. A company has created a CloudTrail trail named 'my-trail' in the management account of AWS Organizations. The trail is configured to deliver logs to a central S3 bucket. The security team wants to capture all management events from all accounts in the organization. Based on the exhibit, what is the most likely issue?
40A company wants to centralize access control for multiple AWS accounts using AWS Organizations. They need to allow developers in a specific account to launch EC2 instances only in certain regions. What is the most scalable solution?
41A multinational corporation uses AWS Organizations with hundreds of accounts. The security team requires that all Amazon S3 buckets across the organization be encrypted with a specific AWS KMS key from the security account. Which combination of controls should be implemented to enforce this requirement?
42A company is migrating to AWS and wants to use AWS CloudFormation to manage infrastructure as code. The DevOps team needs to ensure that stack updates are reviewed and approved before execution. Which feature should they use?
43A company is migrating a legacy monolithic application to a microservices architecture on AWS. The application has strict latency requirements and must be deployed across multiple Availability Zones. Which design strategy BEST meets these requirements while minimizing operational overhead?
44A solutions architect needs to design a network architecture for a multi-account AWS environment using AWS Transit Gateway. The company requires that all traffic between VPCs be inspected by a central security appliance. What is the MOST efficient way to achieve this?
45A company has a centralized logging solution using Amazon S3 and AWS CloudTrail. They want to ensure that logs are immutable and cannot be deleted or modified by any user, including the root user. Which S3 feature should be enabled?
46A company uses AWS Organizations with multiple accounts. The finance team needs to track costs by department, where each department uses resources across several accounts. What is the BEST way to allocate costs accurately?
47A company wants to allow developers to assume a role in a production account from their development account using AWS IAM. What is needed for this cross-account access?
48Which TWO actions improve the security of an S3 bucket that stores sensitive data?
49Which THREE design patterns are recommended for decoupling components in a microservices architecture on AWS?
50A company uses AWS Organizations with a single OU for all accounts. The security team wants to prevent any account from leaving the organization without approval. What should they do?
51A company has a multi-account AWS environment. The security team wants to centrally manage VPC flow logs for all accounts. They already have a centralized logging account. What is the MOST scalable solution?
52A company has a centralized security account and wants to enable AWS Config in all accounts. They want to centrally manage Config rules and view compliance. What should they do?
53A company needs to share a VPC subnet with multiple accounts in the same AWS Organization. What is the MOST secure way to achieve this?
54Which TWO actions should a company take to implement a least-privilege access model across multiple AWS accounts? (Choose TWO.)
55Which TWO AWS services can be used to automate the enforcement of compliance policies across multiple AWS accounts? (Choose TWO.)
56A company uses AWS Organizations with multiple accounts. The central IT team wants to restrict the use of specific EC2 instance types across all accounts to control costs. Which approach should the team use?
57A company uses AWS Organizations with consolidated billing. The finance team needs to track costs by department, which are tagged with 'department' tags. However, some resources are not tagged. The team wants to ensure that all new resources are tagged, and existing untagged resources are identified. What should they do?
58A company has a central IT team that manages multiple AWS accounts. The team wants to allow developers to create resources in their own accounts but wants to restrict the use of certain expensive services like Amazon Redshift. The developers should not be able to launch Redshift clusters in any account. What is the MOST efficient way to achieve this?
59A company has multiple AWS accounts and wants to centrally manage VPC flow logs for all accounts. The flow logs should be sent to a central S3 bucket in the logging account. The solution must be automated for new accounts added to the organization. What should the team do?
60A company with multiple AWS accounts wants to centralize CloudTrail logging. They create a CloudTrail trail in the management account that logs all events across all accounts and regions. However, the security team notices that some management events from member accounts are not being logged. What is the most likely cause?
61A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users are created in member accounts. All access must be through federated roles. Which approach should they use?
62A company is using AWS Organizations with hundreds of accounts. The central IT team needs to deploy a common set of AWS resources (e.g., VPCs, subnets, security groups) to all accounts in a specific organizational unit (OU). The solution must be automated and ensure that new accounts added to the OU automatically receive the resources. Which three steps should the team take? (Choose three.)
63A company manages multiple AWS accounts using AWS Organizations. The security team needs to enforce that all newly created accounts automatically have a specific set of security controls, including AWS Config rules and an AWS CloudTrail trail. Which solution meets these requirements with the LEAST operational overhead?
64A multinational corporation uses AWS Organizations to manage multiple accounts across different geographic regions. The company needs to ensure that all data residing in AWS accounts for a specific country remains within that country's boundaries. Which combination of AWS services and features should the company use to enforce this data residency requirement?
65A company uses AWS Organizations with a management account and several member accounts. The security team needs to centrally manage IAM users and roles across all accounts. Which AWS service should the company use?
66A company has a multi-account AWS environment using AWS Organizations with 50 accounts. The accounts are organized into OUs based on environment: Production, Staging, and Development. The central IT team uses AWS CloudFormation StackSets to deploy a baseline network configuration (VPC, subnets, security groups) to all accounts. Recently, the network team updated the stack set to add a new subnet to the VPC. After the update, they noticed that the stack set operation failed for 10 accounts. The error message indicates that the stack set cannot update because a resource already exists. What is the MOST LIKELY cause of this failure?
67A company is using AWS Organizations with a hierarchical OU structure. The security team wants to enforce that any new account created in the organization automatically inherits a baseline set of AWS Config rules and a VPC with a default CIDR block. What is the MOST efficient way to achieve this?
68A company is designing a multi-account strategy for development, testing, and production environments. They want to ensure that developers can deploy resources in development and testing accounts but not in production. Which TWO methods should the company use to achieve this? (Choose TWO.)
69A company is centralizing its logging across multiple AWS accounts using a central logging account. Each application account delivers its CloudTrail logs and VPC Flow Logs to an S3 bucket in the logging account. The security team needs to query these logs using Amazon Athena. The logs are currently in separate S3 prefixes per account. The team wants to create a single Athena table that can query logs from all accounts without having to modify the table definition every time a new account is added. The logs are in CSV format for VPC Flow Logs and JSON format for CloudTrail. What is the MOST efficient solution?
70A startup is using a single AWS account for development, testing, and production. They want to isolate environments and improve security. What is the most aligned AWS best practice?
71A company needs to share a central Amazon S3 bucket containing common data files with multiple accounts in AWS Organizations. Which approach is most secure and scalable?
72A company is designing a multi-account strategy using AWS Organizations. They want to enforce that no one can disable AWS CloudTrail in any account. Which TWO methods can achieve this?
73A company has a production AWS account and a development AWS account under AWS Organizations. The development team wants to deploy a CloudFormation stack that creates an S3 bucket with a bucket policy that grants access to the production account's IAM roles. The development account has an SCP that denies all s3:PutBucketPolicy actions. The development team has full administrator access in their account. When they try to create the stack, it fails. What is the most likely reason and how should they proceed?
74A company uses AWS Organizations and has deployed a multi-account strategy. The security team wants to enforce that all S3 buckets have versioning enabled. They create an SCP that denies the PutBucketVersioning action if versioning is not enabled. However, they find that the SCP is not preventing users in member accounts from disabling versioning on existing buckets. What is the most likely reason?
75A company has a multi-account AWS environment with a central network account and multiple workload accounts. They want to use AWS Transit Gateway to connect VPCs across accounts. The network team has created a Transit Gateway in the network account and shared it using AWS Resource Access Manager (RAM) with the workload accounts. The workload accounts have created VPC attachments to the Transit Gateway. However, traffic is not flowing between the VPCs. The route tables in the workload VPCs have routes pointing to the Transit Gateway. What is the most likely cause?
76A company uses AWS Organizations and wants to centrally manage AWS Config rules across all member accounts. They have enabled AWS Config in the management account and used AWS Config aggregator to view compliance status across accounts. However, they want to enforce a specific Config rule in all accounts automatically. Which solution should they use?
77A company has multiple AWS accounts managed via AWS Organizations. The security team requires that all S3 buckets across all accounts must block public access. How can this be enforced centrally with minimal operational overhead?
78A global company uses a multi-account AWS Organizations structure with hundreds of accounts. The network team wants to centrally manage VPC flow logs for all accounts and send them to a centralized S3 bucket in the security account. Which solution is MOST scalable and operationally efficient?
79A company has a centralized logging account that receives VPC flow logs from all accounts. The logs are stored in an S3 bucket. The security team needs to analyze these logs to detect anomalous traffic patterns. Which solution provides the most cost-effective and scalable analysis?
80A company wants to implement a data lake on AWS with data from multiple sources. They need to store data in its raw format and allow multiple teams to query it using different tools. Which service should be used as the central storage layer?
81A company is designing a multi-account AWS Organizations architecture. Which TWO considerations should be taken into account when designing the organizational structure?
82A company wants to implement a cost allocation strategy using tags across multiple accounts in AWS Organizations. Which TWO practices should be followed?
83A company uses AWS Organizations and wants to allow a development account to assume a role in the production account for deployment purposes. Which component is necessary for this cross-account access?
84A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a specific member account. What must be done?
85A company wants to ensure that no IAM user in any account can create access keys. The company uses AWS Organizations. Which approach should be used?
86A company uses AWS Organizations and wants to allow certain accounts to use AWS Service Catalog for self-service provisioning. The IT team needs to control which products are available. Where should the product portfolio be shared?
87A company has a centralized network account that hosts a transit gateway with attachments to multiple VPCs in different accounts. The security team needs to ensure that all traffic between VPCs is inspected by a centralized NGFW appliance in the network account. What is the MOST efficient solution?
88A company uses AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a member account. Which step is required to set this up?
89A company has a single AWS account and wants to implement a multi-account strategy for better isolation. Which AWS service is designed to help centrally manage multiple accounts?
90A company is designing a centralized logging solution for multiple AWS accounts. The solution must meet compliance requirements that logs be immutable and stored for 7 years. Which THREE services should be combined to achieve this?
91A global company is using a multi-account AWS Organizations setup with a centralized logging account. They want to aggregate CloudTrail logs from all accounts into a single S3 bucket in the logging account. Which combination of steps will meet this requirement?
92A company uses AWS Organizations with hundreds of accounts. The security team needs to ensure that no IAM user in any account can create a new IAM user or access key. What is the most scalable way to enforce this?
93A company is managing multiple AWS accounts using AWS Organizations. They want to centralize the management of EC2 instances and enforce tagging standards across all accounts. Which TWO approaches should they use?
94A company uses AWS Organizations with a dedicated security account. They want to centralize the management of AWS Config rules and ensure that all accounts are compliant with the same set of rules. Which THREE steps should they take?
95A company has a production AWS account and a development AWS account. The development team needs to assume an IAM role in the production account to deploy resources. What is the correct way to set up this cross-account access?
96A company uses AWS Config to evaluate resource compliance across multiple accounts. The security team wants to automatically remediate non-compliant resources using AWS Systems Manager Automation documents. Which solution is MOST scalable and secure?
97A company manages multiple AWS accounts and wants to centralize billing and cost tracking. They have enabled AWS Organizations and consolidated billing. Which additional step should they take to gain granular visibility into costs per department?
98A company uses AWS Organizations and wants to delegate administrative tasks for specific AWS services to a member account. Which AWS feature should be used?
99A company has multiple VPCs across different AWS accounts and wants to establish private connectivity between them. They also need to centrally manage network traffic for security inspection. Which architecture should they use?
100A company wants to centralize AWS CloudTrail logs from all accounts in AWS Organizations into a single S3 bucket. Which configuration is required?
101A company has a multi-account AWS environment and wants to implement a secure, scalable cross-account network architecture using AWS Transit Gateway. Which TWO steps should be taken?
102A company uses AWS Organizations and wants to centrally manage Amazon GuardDuty across all accounts. Which TWO steps are required to enable GuardDuty in all accounts from a single management account?
103Refer to the exhibit. A solutions architect is troubleshooting why EC2 instances launched in subnet-11111111 cannot access the internet. The subnet is in a VPC with an internet gateway attached. The route table for the subnet has a default route (0.0.0.0/0) pointing to the internet gateway. What is the MOST likely cause?
104A multinational company is adopting AWS Organizations to manage multiple accounts across business units. The security team requires that specific IAM roles be automatically deployed to all existing and future member accounts. Which solution should the company use?
105A company is designing a network architecture for a multi-account AWS environment. They need to establish a central inspection VPC through which all traffic between VPCs in different accounts must pass. Which AWS service should be used to route traffic between VPCs through the inspection VPC?
106A company has a management account in AWS Organizations and wants to share a central Amazon VPC subnet with multiple member accounts for a shared services VPC. Which AWS service should be used to share the subnet?
107A company wants to centrally manage backups for Amazon EBS volumes across multiple AWS accounts. They need a solution that can automatically back up volumes based on tags, retain backups according to a policy, and send notifications on failures. Which AWS service should they use?
108A company is implementing a hybrid network architecture with multiple VPCs in different AWS accounts. They need to ensure private connectivity between the VPCs and their on-premises data center. Which TWO services should they use together to meet this requirement?
109A company uses AWS Organizations and wants to establish a central logging solution. They need to collect CloudTrail logs from all accounts and store them in a central S3 bucket in the management account. Which TWO steps are required to achieve this?
110Refer to the exhibit. An administrator runs this command and sees the output. Which statement about the accounts is correct?
111A company has multiple AWS accounts managed using AWS Organizations. The security team wants to enforce that all new accounts automatically have a specific AWS Config rule enabled to prohibit public S3 bucket access. Which solution requires the least operational overhead?
112A company is migrating to a multi-account AWS environment. They want to centralize DNS management using Amazon Route 53 private hosted zones. The private zones must be accessible from all VPCs in the organization. Which THREE steps are required to achieve this?
113A company uses a single AWS account for development and production workloads. To improve security and cost allocation, the company decides to separate environments into multiple accounts. What is the PRIMARY benefit of using multiple accounts?
114A company is designing a multi-account strategy using AWS Organizations. Which TWO benefits does this approach provide? (Choose TWO.)
115A company has a multi-account AWS environment with a centralized security account. The security team needs to have read-only access to all Amazon S3 buckets across all accounts for auditing purposes. Which solution is the MOST secure and scalable?
116A company has a multi-account AWS environment with a centralized network account that hosts a transit gateway. The company wants to share the transit gateway with multiple member accounts. Which AWS service should be used to share the transit gateway?
117A company is using AWS Organizations with consolidated billing. The company has a production account and a development account. The security team needs to ensure that developers cannot create IAM users in the development account. Which option is the MOST effective?
118A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a member account. Which step is required?
119A company uses AWS Organizations and wants to ensure that all member accounts have AWS CloudTrail enabled and logs are delivered to a central S3 bucket in the management account. Which approach is MOST efficient?
120A company is designing a multi-account strategy for its development teams. Each team needs to have its own isolated environment with VPCs, subnets, and security groups. The company wants to centralize network administration and ensure that all VPCs use a common set of security rules. Which THREE steps should the company take? (Choose THREE.)
121A global company uses AWS Organizations with many OUs and accounts. The finance team needs to track costs by cost center, which is tagged on each resource. However, some resources are not tagged. Which solution will provide the MOST accurate cost allocation?
122A company has a decentralized IT structure where each business unit manages its own AWS account. The central security team needs visibility into all IAM user activities across accounts. What is the MOST scalable solution to aggregate CloudTrail logs?
123A company has a multi-account strategy with a dedicated audit account. The audit account needs to have read-only access to all resources in all other accounts. The security team wants to use IAM roles. What is the MOST scalable way to set up this cross-account access?
124Refer to the exhibit. An SCP is attached to an OU. A developer in an account under this OU tries to launch a t3.large EC2 instance. What will happen?
125A company has a multi-account environment with a central security account. They want to use AWS Security Hub to aggregate findings from all accounts. What is the correct setup?
126A company is using AWS Organizations with a set of member accounts that need to access a shared Amazon S3 bucket in the master account. The bucket policy allows access only from the member accounts' root user. However, developers in member accounts are unable to access the bucket even when they assume an IAM role. What is the most likely cause?
127A company wants to automate the creation of new AWS accounts and apply baseline security configurations. Which combination of services should be used to achieve this?
128A company is using AWS Organizations with a centralized networking account that hosts a transit gateway. The company wants to ensure that all traffic between VPCs in different accounts flows through the transit gateway. Which THREE steps are required to implement this architecture?
129A company has a multi-account AWS environment with hundreds of accounts. The security team needs to centrally manage IAM roles for cross-account access. They want to ensure that when a role is created in a member account, it automatically adheres to the principle of least privilege and is auditable. What solution should they implement?
130A company has multiple AWS accounts and wants to centralize CloudTrail logs from all accounts into a single S3 bucket in the audit account. Which configuration is required?
131A company uses AWS Organizations with several OUs for different environments (dev, test, prod). They want to restrict the use of specific EC2 instance types in the prod OU only. Which approach should they use?
132A company has a central IT team that manages AWS Organizations. The development team needs to create and manage their own AWS accounts for new projects. What is the BEST way to automate account creation while maintaining governance?
133A company is designing a multi-account strategy for its AWS environment. Which TWO considerations are important when using AWS Organizations?
134A company wants to implement a least-privilege security model across multiple AWS accounts. Which TWO services can help enforce this?
135A company has a multi-account AWS environment with over 500 accounts. The security team uses AWS Config to evaluate resource compliance across all accounts. They have set up an AWS Config aggregator in the security account to collect configuration snapshots from all member accounts. Recently, the team noticed that some member accounts are not showing up in the aggregator. The accounts are active and have AWS Config enabled. What should the security team do to troubleshoot this issue?
136A multinational company is implementing a multi-account strategy using AWS Organizations. The security team needs to ensure that all newly created accounts automatically have a specific baseline CloudTrail trail and a set of AWS Config rules applied. The company also wants to enforce that no account can disable these controls. Which solution should be used?
137A large enterprise is migrating to AWS and wants to implement a multi-account strategy with centralized network connectivity. The company has multiple VPCs in various accounts that need to communicate with each other and with on-premises resources. The solution must be scalable and minimize operational overhead. Which design should be used?
138A company is using AWS Organizations with multiple accounts. The central IT team wants to enforce that all EC2 instances are launched with specific tags (e.g., CostCenter and Environment). The solution should prevent any untagged instances from being created. Which approach should be taken?
139A company wants to centralize management of IAM users and groups across multiple AWS accounts. The solution should allow users to access resources in any account without needing separate credentials. Which AWS service should be used?
140A company uses AWS Organizations with multiple OUs. The DevOps team needs to allow developers to launch EC2 instances only of type t3.micro in the dev OU. Which action should the team take?
141A company uses AWS Organizations and wants to centrally manage backups of EC2 instances across multiple accounts. Which service should they use?
142A company has a multi-account AWS environment and uses AWS Organizations. The security team wants to automatically remediate non-compliant resources, such as S3 buckets that are publicly accessible. Which design should they implement?
143A company has multiple AWS accounts and wants to centrally manage CloudWatch dashboards. Which solution should they use?
144A company has a multi-account AWS environment with a central security account. They want to enable Amazon GuardDuty in all accounts and centrally view findings. The security team has already enabled GuardDuty in the security account and invited all member accounts. However, the security account is not receiving findings from all member accounts. Upon investigation, some member accounts show that GuardDuty is not enabled, and some show that they have not accepted the invitation. The team needs a scalable solution to enable GuardDuty across all accounts and ensure findings are sent to the security account. What should the team do?
145A company has a decentralized IT structure where each business unit manages its own AWS accounts. The central IT team wants to enforce security policies across all accounts but allow business units to retain administrative control. Which solution should the central IT team implement?
146A company is using AWS Organizations and wants to centralize the management of Amazon EC2 instance security groups. The security team needs to enforce that certain ports are not open to the internet across all accounts. The company currently uses AWS Firewall Manager. Which approach should the security team use to enforce this policy?
147A company uses AWS Organizations and has a requirement that all Amazon S3 buckets must have versioning enabled. The company wants to automatically enable versioning on any bucket that is created without it. Which solution should be implemented?
148A company has a multi-account AWS environment and wants to centralize the management of IAM roles. The security team needs to ensure that all IAM roles across all accounts trust the same identity provider (IdP) for federated access. The company uses AWS IAM Identity Center (successor to AWS SSO) for user management. Which solution should be implemented?
149A company has a complex AWS environment with multiple accounts and VPCs. The company wants to ensure that all outbound traffic from VPCs goes through a centralized inspection VPC for security monitoring. The company uses AWS Transit Gateway. Which solution should be implemented?
150A large financial services company uses AWS Organizations with over 200 accounts. The security team has implemented a Service Control Policy (SCP) that denies access to all services except a whitelist that includes Amazon S3, Amazon DynamoDB, AWS Lambda, and Amazon CloudWatch. Recently, the DevOps team reported that they cannot create new EC2 instances in their development account, even though the administrator explicitly attached an IAM policy allowing ec2:RunInstances. The SCP does not explicitly deny EC2. What is the most likely cause of this issue?
151A company uses AWS Organizations with a management account and 40 member accounts. The security team needs to centrally manage IAM roles that grant cross-account access to a shared services account. They want to deploy the roles to all member accounts and ensure new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?
152A financial services company has an AWS Organizations structure with a management account, a dedicated Network account, and 40 workload accounts. The Network team wants to share a single AWS Transit Gateway with all workload accounts so that each account can attach its own VPCs. Workload accounts must not be able to modify the Transit Gateway route tables owned by the Network account. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?
153A multinational enterprise uses AWS Organizations with 300 accounts. The network team wants to centrally manage VPC IP address allocation and share subnets across multiple accounts to simplify connectivity. They also need to ensure that when a new account is created, it automatically receives a VPC with a predefined CIDR that does not overlap with existing VPCs. Which combination of AWS services should they use?
154A company has a multi-account AWS environment with a central shared services account. The company wants to provide a self-service portal for developers to request temporary AWS credentials for specific roles in various accounts. The credentials must be generated without creating IAM users and must be auditable. Which solution meets these requirements?
155A media company has 200 AWS accounts in AWS Organizations. The networking team wants to provide each account with a shared VPC subnet from a central networking account. The central networking account owns the VPC and subnets. Workload accounts must be able to launch resources into the shared subnets, but they must not be able to modify the subnet configuration or delete the shared subnets. Which solution meets these requirements?
156A healthcare company has a multi-account AWS environment with a central audit account. The security team needs to ensure that all API activity across all accounts is logged and that logs are stored immutably for 7 years. They also need to be able to search logs across all accounts quickly. Which solution meets these requirements with the LEAST operational overhead?
157A healthcare company operates a multi-account AWS environment with AWS Organizations. A central Security account runs Amazon GuardDuty and AWS Security Hub, and all member accounts are delegated administrators for those services. The company now wants to centrally manage Amazon Inspector findings across all accounts and ensure that new accounts are automatically covered. Which solution meets these requirements with the LEAST operational effort?
158A company has a multi-account AWS environment with a central shared services VPC in a networking account. They want to allow resources in workload accounts to access a shared Amazon RDS database in the shared services VPC. The RDS database is in a private subnet. The company uses AWS Transit Gateway to connect all VPCs. They have set up a route in the workload VPC route table pointing to the Transit Gateway for the shared services VPC CIDR. However, resources in the workload accounts cannot connect to the RDS database. What is the most likely cause?
159A company is expanding its AWS Organizations environment to include several new business units. The security team must ensure that all new accounts automatically have a baseline security configuration, including a VPC with specific flow logs enabled, an AWS Config recorder, and a set of IAM roles for cross-account access. They want to minimize manual effort and ensure consistency. Which two solutions should they use to achieve these goals? (Choose two.)
160A company has a large AWS Organizations environment with 200 accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that the roles are deployed to all existing and future accounts, and that any changes to the roles are automatically propagated. Which solution should they use?
161A company is using AWS Organizations to manage 50 accounts. They want to centralize billing and also allow a central team to manage IAM roles across all accounts. The central team needs to be able to assume a role in any member account to perform administrative tasks. They have already enabled all features in Organizations. Which two steps are required to allow the central team to assume roles in member accounts? (Choose two.)
162A healthcare company has 200 AWS accounts in AWS Organizations. The security team wants to prevent any principal in member accounts from disabling AWS CloudTrail or deleting the organization trail, even if they have administrator permissions in their own account. The solution must be centrally managed and apply to all existing and future accounts. Which approach should a solutions architect recommend?
163A company has an AWS Organizations setup with a management account and several member accounts. The finance team needs to receive a consolidated bill for all accounts and wants to apply volume discounts across the organization. The company also wants to prevent member accounts from leaving the organization without approval. Which action should the company take?
164A media company uses AWS Organizations with a central shared services account that hosts a Transit Gateway. Workload accounts in two OUs must be able to route traffic through the Transit Gateway to on-premises networks via AWS Site-to-Site VPN, but must not be able to route traffic to each other. A solutions architect needs to enforce this segmentation centrally. What should the architect do?
165A financial services company has an AWS Organizations structure with production and development OUs. The security team wants to prevent any IAM principal in the development OU from disabling AWS CloudTrail logging, even if an account administrator attempts it. They need a solution that applies automatically to all existing and future accounts in the development OU. What should they do?
166A healthcare company operates a multi-account AWS environment with a shared services VPC in a central account. Workload accounts need to access a centralized Amazon RDS for MySQL database in the shared services VPC. The security team requires that all database traffic be encrypted in transit and that no workload account can access the database directly from the internet. They also want to minimize administrative overhead. Which solution meets these requirements?
167A company has 200 AWS accounts in AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security tooling account. The roles must be created consistently in every account, and any change to the role trust policy must propagate automatically. Which approach requires the LEAST ongoing effort?
168A company has an AWS Organizations structure with a management account and 40 member accounts grouped into four OUs. The security team wants a single AWS account to receive all Amazon GuardDuty findings from every account and to view them in one place. They also need new accounts created under any OU to be automatically enrolled. Which solution meets these requirements with the LEAST operational overhead?
169A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all newly created Amazon S3 buckets are encrypted with AWS KMS keys managed by the security account, and that any attempts to create unencrypted buckets are denied. The company also wants to ensure that existing buckets are remediated. Which two actions should the security team take to meet these requirements? (Choose two.)
170A financial services company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that member accounts cannot modify or delete these roles, and that new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?
171A financial services company uses AWS Organizations with 300 member accounts. The security team wants to ensure that all AWS API activity in every account is logged to a central Amazon S3 bucket owned by the management account. The logs must be immutable for 7 years and protected from deletion by any member account administrator. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?
172A company has a multi-account AWS environment with a central shared services VPC and multiple workload VPCs connected via AWS Transit Gateway. The security team wants to inspect all traffic between workload VPCs using a centralized firewall appliance in the shared services VPC. They need to ensure that traffic is inspected without modifying the workload VPC route tables. What should they do?
173A financial services company uses AWS Organizations with 60 accounts. The security team has enabled AWS CloudTrail organization trails in the management account and wants to prevent any member account administrator from disabling CloudTrail logging in their own account. Which solution will meet this requirement with the LEAST operational overhead?
174A financial services company uses AWS Organizations with a central networking account. Workload accounts need to reach an on-premises data center over AWS Site-to-Site VPN, and the network team wants to enforce that all inter-VPC traffic flows through a central inspection VPC. Which combination of components should the network team deploy to route traffic through the inspection VPC while keeping the architecture scalable?
175A company has a multi-account AWS environment managed by AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. The roles must be automatically created in all existing and future accounts, and any changes to the roles must be applied consistently. Which solution meets these requirements with the LEAST administrative effort?
176A company has a multi-account AWS environment with a central network account that hosts a shared AWS Transit Gateway. The company wants to implement a hub-and-spoke network topology where all inter-VPC traffic between workload VPCs must be inspected by a central security VPC before reaching its destination. The security VPC contains an AWS Network Firewall. The company needs to ensure that traffic between any two workload VPCs is routed through the security VPC. Which configuration should a solutions architect implement?
177A company has 200 AWS accounts in AWS Organizations and a shared services VPC in a central networking account. Each workload account needs to reach an on-premises data center over a single AWS Direct Connect connection that terminates in the networking account. The company wants to minimize cost and avoid managing individual VPC peering connections. Which solution should a solutions architect recommend?
178A company is adopting AWS Organizations and wants a baseline set of IAM roles, a standard VPC, and a security agent deployed automatically into every new account the moment it is created. The operations team does not want to run scripts manually after each account creation. Which AWS service should they use to meet this requirement?
179A company has a multi-account AWS environment managed with AWS Organizations. The finance team wants to consolidate billing and receive a single bill for all accounts, while still allowing each account to have its own service usage and cost allocation tags. The company also wants to apply volume discounts across accounts. Which AWS Organizations feature should the solutions architect enable?
180A company has an AWS Organizations environment with a management account, a central log archive account, and many workload accounts. The security team must prevent workload accounts from disabling AWS CloudTrail, deleting the central log bucket, or leaving the organization, while still allowing account administrators to manage their own resources. (Choose two.)
181A company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to prevent any member account from disabling AWS CloudTrail or deleting the organization trail. They also want to ensure that only the management account can create new trails. Which solution meets these requirements with the least operational overhead?
182A financial services company has an AWS Organizations structure with a management account, a dedicated network account, and 40 workload accounts. Each workload account has its own VPC, and all VPCs must be able to reach a shared services VPC in the network account. The security team requires that all inter-VPC traffic be inspected by a central firewall appliance before reaching the shared services. Which solution meets these requirements with the LEAST operational overhead?
183A company has 200 AWS accounts in AWS Organizations. The compliance team needs to prove that all Amazon S3 buckets across every account have server-side encryption enabled and block public access, and they want a single dashboard showing compliance status. Which solution should they implement?
184A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to prevent member accounts from disabling AWS CloudTrail or modifying its configuration. They also want to ensure that all CloudTrail logs are stored in a central S3 bucket in the management account. Which combination of actions should be taken?
185A company has a single AWS account with multiple VPCs. They want to connect all VPCs to a central VPC for shared services, such as Active Directory and DNS, without using a complex mesh of VPC peering connections. They also want to minimize costs. Which solution should they use?
186A company is deploying a multi-account AWS environment using AWS Organizations. The security team requires that all Amazon S3 buckets in member accounts are encrypted with AWS KMS customer managed keys, and that the keys are created and managed centrally in a security account. Which solution should a solutions architect recommend?
187A healthcare company has a multi-account AWS environment with a central audit account. Compliance requires that all access to Amazon S3 buckets containing protected health information be logged and that logs be immutable for seven years. The company wants to centralize log storage and prevent any account, including the management account, from deleting or modifying the logs. Which combination of steps should a solutions architect take?
188A company has a VPC with a CIDR block of 10.0.0.0/16. They need to connect this VPC to an on-premises network that uses the CIDR block 10.0.0.0/8. The company wants to use AWS Site-to-Site VPN for the connection. They must avoid IP address conflicts. What is the MOST appropriate solution?
189A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that when a new member account is added, the required IAM role is automatically created with a trust policy that allows the security account to assume it. The solution must minimize manual steps and work across all current and future accounts. Which approach should be used?
190A company has 30 AWS accounts in AWS Organizations. The finance team wants to receive a single consolidated bill for all accounts and apply volume discounts across the organization. Which action should a solutions architect take?
191A company is using AWS Organizations with all features enabled. They want to apply a service control policy (SCP) that denies the ability to delete AWS KMS keys across all member accounts, but they need to allow a specific break-glass role in the management account to delete keys in case of emergency. Which statement is true regarding SCP enforcement in this scenario?
192A financial services company uses AWS Organizations with all features enabled. A security account runs AWS CloudFormation StackSets with service-managed permissions to deploy guardrail resources into every account. Compliance requires that no member account administrator can disable AWS CloudTrail or delete the organization trail, even in accounts where they hold full administrative rights, and that new accounts automatically receive the guardrail. Which combination should the solutions architect recommend?
193A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account for incident response. They need to ensure that the roles can be assumed only by specific IAM principals in the security account and that the permissions are consistent across all member accounts. Which approach meets these requirements with the LEAST operational overhead?
194A multinational company has a multi-account AWS environment with a central network account. They use AWS Transit Gateway to connect all VPCs. The company wants to implement centralized inspection of all traffic between VPCs using a third-party firewall appliance running on EC2 instances in a dedicated inspection VPC. Traffic must be inspected without modifying workload VPC route tables when new VPCs are added. What should the solutions architect recommend?
195A company has a multi-account AWS environment with a central security account. The security team needs to audit all API activity across all accounts and retain the logs for 7 years in a tamper-evident manner. They also need to ensure that no account administrator can disable or modify the logging configuration. Which solution meets these requirements?
196A company has a multi-account AWS environment with AWS Organizations. They use AWS IAM Identity Center (successor to AWS Single Sign-On) for workforce access. The security team wants to ensure that all federated users from the corporate identity provider (IdP) are automatically assigned to the appropriate permission sets based on their group membership in the IdP. The company uses SAML 2.0 federation with IAM Identity Center. Which configuration should the solutions architect implement to achieve automatic group-based permission set assignments?
197A large enterprise is consolidating 300 AWS accounts under AWS Organizations. The security team needs a way to centrally define and deploy IAM roles that grant break-glass access, must ensure the roles can be assumed only by members of a specific federated group, and must be able to update the roles across all accounts without logging into each account. (Choose two.)
198A company has a single AWS account and wants to implement a multi-account strategy using AWS Organizations. They need to centrally manage billing and apply policies to restrict which AWS services can be used in each account. The company also wants to ensure that new accounts automatically inherit these restrictions. Which step should they take first to set up AWS Organizations with these capabilities?
199A startup has 25 AWS accounts in a single organization. A new compliance officer wants a single, read-only view of all resources and their configuration across every account, and wants to be alerted when an S3 bucket becomes publicly accessible. The team has no existing aggregation tooling. Which approach requires the least operational effort?
200A company has a multi-account AWS environment with AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that only the audit account can assume these roles and that the roles are automatically created in all existing and future accounts. What should they do?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
You must be able to design multi-account governance and cross-account networking: apply SCPs, centralize CloudTrail logs, share resources with RAM, and route traffic via Transit Gateway. The single most important thing is knowing SCPs filter permissions but never grant them.
The Courseiva SAP-C02 question bank contains 200 questions in the Design Solutions for Organizational Complexity domain, covering the 26% of the exam attributed to this domain in the official Amazon Web Services blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Design Solutions for Organizational Complexity domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included