20+ practice questions focused on Design Solutions for Organizational Complexity — one of the most tested topics on the AWS Certified Solutions Architect Professional SAP-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Design Solutions for Organizational Complexity PracticeA multinational company is implementing AWS Organizations to manage multiple accounts across business units. The security team requires that all IAM users in member accounts must use a specific password policy and must have MFA enabled. Which combination of actions should the company take to enforce these requirements?
Explanation: SCPs can deny changes to the password policy and deny deactivation of MFA devices, preventing users from weakening security controls. AWS Config rules then detect non-compliant users (e.g., those without MFA or with a non-compliant password policy), allowing the security team to trigger remediation or alerts. SCPs alone cannot enforce a specific password policy or enable MFA; they only block actions, so Config rules are needed for detection and enforcement.
A company has a centralized logging account that receives VPC Flow Logs from all accounts in the organization. The logs are stored in an S3 bucket. A security analyst needs to query the logs to identify traffic to a specific IP address. The analyst has been granted read-only access to the S3 bucket. However, the analyst cannot access the logs. What is the MOST likely cause?
Explanation: The S3 bucket policy likely includes a condition that restricts access to only AWS service principals (e.g., the logging account's own services) rather than individual IAM users or roles from other accounts. Even with read-only access granted to the analyst's IAM user or role, the bucket policy's explicit deny for non-service principals overrides any allow, preventing the analyst from accessing the logs. This is a common cross-account access issue where bucket policies must explicitly allow principals from other accounts.
A company uses AWS Organizations with multiple OUs. The finance team needs to have read-only access to billing data across all accounts. The security team wants to ensure that no IAM user can modify billing preferences. Which policy should be attached to the root OU to achieve this?
Explanation: A Service Control Policy (SCP) attached to the root OU can deny the effect of actions that modify billing preferences across all accounts in the organization. SCPs are the only mechanism that can restrict permissions for all principals (including the root user) in member accounts, and by using a Deny effect on specific billing modification actions, the security team ensures no IAM user or role can alter billing settings. This approach does not require enumerating every allowed read-only action, which avoids the risk of missing future read-only actions.
A company has multiple AWS accounts managed via AWS Organizations. The security team wants to restrict the use of specific instance types across all accounts. Which TWO methods can be used to enforce this restriction?
Explanation: Option A is correct because an AWS Organizations Service Control Policy (SCP) can be attached at the OU or account level and include a Deny statement on ec2:RunInstances with a condition such as ec2:InstanceType (StringEquals or StringNotEquals) to block prohibited instance types across all accounts in scope. Option B is correct because AWS Config rules can evaluate launched instances against desired instance types and, via remediation, invoke AWS Systems Manager Automation to terminate non-compliant instances, providing detective and corrective enforcement across accounts. Option C is not correct because CloudTrail is only an auditing/logging service; it records API activity but does not natively enforce or automatically terminate resources. Option D is not correct because Service Quotas limits counts or capacity, not the specific instance type families/sizes used. Option E is not correct because IAM policies in each account are not centrally enforced across an AWS Organization and can be bypassed or inconsistently applied compared with SCPs.
A company is migrating to a multi-account AWS environment using AWS Control Tower. The security team must ensure that all accounts have AWS Config enabled and that logs are delivered to a central S3 bucket. Which THREE steps should the security team take?
Explanation: Option B is correct because an AWS Organizations service control policy (SCP) applied at the OU or root level can explicitly deny the config:StopConfigurationRecorder and config:DeleteConfigurationRecorder actions, ensuring no member account can disable AWS Config. Option C is correct because AWS Config in each account delivers snapshots and history files to the central S3 bucket, so the bucket policy must grant s3:PutObject (and related permissions) to the Config service principals or the accounts' delivery roles across the organization to permit cross-account delivery. Option D is correct because AWS Control Tower's account factory uses an Account Factory Customization (AFC) or a Config recorder/conformance pack baseline so that enabling AWS Config in the management account and propagating it through account factory provisions the recorder and delivery channel in every new and existing account. Option A is not correct because creating a separate S3 bucket per account defeats the requirement for a single central bucket and is unnecessary manual work. Option E is not correct because AWS Config log delivery to S3 is performed by the Config service using a delivery channel and bucket policy, not by an IAM role in each account granting the management account access to logs.
+15 more Design Solutions for Organizational Complexity questions available
Practice all Design Solutions for Organizational Complexity questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Design Solutions for Organizational Complexity. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Design Solutions for Organizational Complexity questions on the SAP-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Design Solutions for Organizational Complexity is tested as part of the AWS Certified Solutions Architect Professional SAP-C02 blueprint. Practicing with targeted Design Solutions for Organizational Complexity questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SAP-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Design Solutions for Organizational Complexity is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Design Solutions for Organizational Complexity practice session with instant scoring and detailed explanations.
Start Design Solutions for Organizational Complexity Practice →