SAP-C02 · domain
Design Solutions for Organizational Complexity
This domain covers multi-account and multi-VPC architectures on AWS: AWS Organizations, OUs, SCPs, Control Tower, centralized logging, cross-account IAM roles, VPC peering, Transit Gateway, RAM sharing, and hybrid DNS. Questions are scenario-based, asking you to pick configurations that enforce governance, centralize data, and connect networks across accounts correctly.
Focused practice
Practice Design Solutions for Organizational Complexity questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Design Solutions for Organizational Complexity
You must be able to design multi-account governance and cross-account networking: apply SCPs, centralize CloudTrail logs, share resources with RAM, and route traffic via Transit Gateway. The single most important thing is knowing SCPs filter permissions but never grant them.
Designing AWS Organizations OUs, SCPs, and Control Tower guardrails for multi-account governance
Configuring centralized AWS CloudTrail log delivery to a shared S3 bucket across accounts
Building cross-account access with IAM roles, resource policies, and AWS RAM sharing
Connecting VPCs and on-premises networks using Transit Gateway, peering, and Route 53 Resolver
Watch out for
Common Design Solutions for Organizational Complexity exam traps
- ▸Forgetting that SCPs only restrict maximum permissions and never grant access, so IAM policies must still allow the action
- ▸Assuming a VPC internet gateway alone gives internet access without a route table entry to 0.0.0.0/0
- ▸Overlooking that CloudTrail organization trails and S3 bucket policies must permit cross-account log delivery
Question index
All Design Solutions for Organizational Complexity questions (200)
Click any question to see the full explanation, or start a practice session above.
Refer to the exhibit. A company runs the AWS CLI command to list accounts in AWS Organizations. The company wants to remove the account '444444444444' from the organization. What must the company do first before it can remove this account?
Easy2A company wants to centralize management of IAM users and groups across multiple AWS accounts. The solution should allow users to access resources in any account without needing separate credentials. Which AWS service should be used?
Easy3A company has a multi-account AWS environment with a central security account. They want to enable Amazon GuardDuty in all accounts and centrally view findings. The security team has already enabled GuardDuty in the security account and invited all member accounts. However, the security account is not receiving findings from all member accounts. Upon investigation, some member accounts show that GuardDuty is not enabled, and some show that they have not accepted the invitation. The team needs a scalable solution to enable GuardDuty across all accounts and ensure findings are sent to the security account. What should the team do?
Medium4Drag and drop the steps to set up AWS CloudTrail for logging API activity in the correct order.
Medium5A company uses AWS Organizations with a dedicated security account. They want to centralize the management of AWS Config rules and ensure that all accounts are compliant with the same set of rules. Which THREE steps should they take?
Hard6Refer to the exhibit. An SCP is attached to an OU. A developer in an account under this OU tries to launch a t3.large EC2 instance. What will happen?
Hard7A financial services company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that member accounts cannot modify or delete these roles, and that new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?
Medium8A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users are created in member accounts. All access must be through federated roles. Which approach should they use?
Easy9A healthcare company has a multi-account AWS environment with a central audit account. Compliance requires that all access to Amazon S3 buckets containing protected health information be logged and that logs be immutable for seven years. The company wants to centralize log storage and prevent any account, including the management account, from deleting or modifying the logs. Which combination of steps should a solutions architect take?
Hard10A company wants to implement a cost allocation strategy using tags across multiple accounts in AWS Organizations. Which TWO practices should be followed?
Medium11A financial services company has an AWS Organizations structure with production and development OUs. The security team wants to prevent any IAM principal in the development OU from disabling AWS CloudTrail logging, even if an account administrator attempts it. They need a solution that applies automatically to all existing and future accounts in the development OU. What should they do?
Medium12A company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to prevent any member account from disabling AWS CloudTrail or deleting the organization trail. They also want to ensure that only the management account can create new trails. Which solution meets these requirements with the least operational overhead?
Medium13A global company uses AWS Organizations with many OUs and accounts. The finance team needs to track costs by cost center, which is tagged on each resource. However, some resources are not tagged. Which solution will provide the MOST accurate cost allocation?
Hard14A company is designing a multi-account AWS Organizations architecture. Which TWO considerations should be taken into account when designing the organizational structure?
Medium15A company uses AWS Organizations and wants to delegate administration of a specific service to a member account. The service must be able to perform actions across all accounts in the organization. Which steps should the company take?
Hard16A company has a multi-account AWS environment and uses AWS Organizations. The security team wants to automatically remediate non-compliant resources, such as S3 buckets that are publicly accessible. Which design should they implement?
Hard17Refer to the exhibit. An administrator runs this command and sees the output. Which statement about the accounts is correct?
Medium18A company has a centralized networking team that manages a shared VPC with multiple AWS Transit Gateway attachments. Application teams create VPCs in separate AWS accounts and want to connect to the shared VPC. The networking team needs to ensure that only authorized VPCs can connect to the shared VPC. What is the MOST secure and scalable way to manage this?
Medium19A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that when a new member account is added, the required IAM role is automatically created with a trust policy that allows the security account to assume it. The solution must minimize manual steps and work across all current and future accounts. Which approach should be used?
Hard20A healthcare company operates a multi-account AWS environment with a shared services VPC in a central account. Workload accounts need to access a centralized Amazon RDS for MySQL database in the shared services VPC. The security team requires that all database traffic be encrypted in transit and that no workload account can access the database directly from the internet. They also want to minimize administrative overhead. Which solution meets these requirements?
Hard21A company has a multi-account AWS environment. The security team wants to centrally manage VPC flow logs for all accounts. They already have a centralized logging account. What is the MOST scalable solution?
Hard22A company has 200 AWS accounts in AWS Organizations. The compliance team needs to prove that all Amazon S3 buckets across every account have server-side encryption enabled and block public access, and they want a single dashboard showing compliance status. Which solution should they implement?
Medium23A company has a multi-account AWS environment with AWS Organizations. They use AWS IAM Identity Center (successor to AWS Single Sign-On) for workforce access. The security team wants to ensure that all federated users from the corporate identity provider (IdP) are automatically assigned to the appropriate permission sets based on their group membership in the IdP. The company uses SAML 2.0 federation with IAM Identity Center. Which configuration should the solutions architect implement to achieve automatic group-based permission set assignments?
Medium24A company wants to implement AWS Organizations with multiple OUs to isolate development, testing, and production workloads. The company needs to ensure that production workloads are not impacted by changes in other OUs. Which TWO practices should the company follow? (Choose two.)
Medium25A company is using AWS Organizations and wants to centralize the management of Amazon EC2 instance security groups. The security team needs to enforce that certain ports are not open to the internet across all accounts. The company currently uses AWS Firewall Manager. Which approach should the security team use to enforce this policy?
Medium26A company has a multi-account AWS environment with a central shared services account. The company wants to provide a self-service portal for developers to request temporary AWS credentials for specific roles in various accounts. The credentials must be generated without creating IAM users and must be auditable. Which solution meets these requirements?
Medium27A company wants to centralize access control for multiple AWS accounts using AWS Organizations. They need to allow developers in a specific account to launch EC2 instances only in certain regions. What is the most scalable solution?
Medium28A company has an AWS Organizations setup with a management account and several member accounts. The finance team needs to receive a consolidated bill for all accounts and wants to apply volume discounts across the organization. The company also wants to prevent member accounts from leaving the organization without approval. Which action should the company take?
Easy29A company has 200 AWS accounts in AWS Organizations and a shared services VPC in a central networking account. Each workload account needs to reach an on-premises data center over a single AWS Direct Connect connection that terminates in the networking account. The company wants to minimize cost and avoid managing individual VPC peering connections. Which solution should a solutions architect recommend?
Hard30A company uses AWS Organizations with consolidated billing. The finance team wants to track costs by department. Each department has its own AWS account. Which feature should be used to map costs to departments?
Easy31A company has a multi-account AWS environment with a central network account that hosts a shared AWS Transit Gateway. The company wants to implement a hub-and-spoke network topology where all inter-VPC traffic between workload VPCs must be inspected by a central security VPC before reaching its destination. The security VPC contains an AWS Network Firewall. The company needs to ensure that traffic between any two workload VPCs is routed through the security VPC. Which configuration should a solutions architect implement?
Hard32A company uses AWS Organizations and wants to allow a development account to assume a role in the production account for deployment purposes. Which component is necessary for this cross-account access?
Easy33Which TWO AWS services can be used to automate the enforcement of compliance policies across multiple AWS accounts? (Choose TWO.)
Easy34A company has a centralized security account and wants to enable AWS Config in all accounts. They want to centrally manage Config rules and view compliance. What should they do?
Medium35A company wants to centrally manage backups for Amazon EBS volumes across multiple AWS accounts. They need a solution that can automatically back up volumes based on tags, retain backups according to a policy, and send notifications on failures. Which AWS service should they use?
Easy36A global company uses AWS Organizations with hundreds of accounts. The networking team needs to allow VPCs in different accounts to communicate privately using AWS Transit Gateway. The company wants to centralize management while allowing individual account owners to create and attach VPCs. Which solution meets these requirements?
Hard37A company uses AWS Organizations with a management account and 40 member accounts. The security team needs to centrally manage IAM roles that grant cross-account access to a shared services account. They want to deploy the roles to all member accounts and ensure new accounts automatically receive the roles. Which solution meets these requirements with the LEAST operational overhead?
Medium38A multinational company has a multi-account AWS environment with a central network account. They use AWS Transit Gateway to connect all VPCs. The company wants to implement centralized inspection of all traffic between VPCs using a third-party firewall appliance running on EC2 instances in a dedicated inspection VPC. Traffic must be inspected without modifying workload VPC route tables when new VPCs are added. What should the solutions architect recommend?
Hard39A company is migrating to AWS and wants to use AWS CloudFormation to manage infrastructure as code. The DevOps team needs to ensure that stack updates are reviewed and approved before execution. Which feature should they use?
Easy40A company is migrating its on-premises Active Directory to AWS Managed Microsoft AD. The company has multiple VPCs across different accounts that need to authenticate against the same directory. What is the MOST scalable and secure way to provide this access?
Medium41A company is using AWS Organizations with multiple organizational units (OUs). The security team needs to enforce that all newly created S3 buckets in the production OU have versioning enabled and are encrypted with AWS KMS. Which solution meets these requirements with minimal operational overhead?
Easy42A company uses AWS Organizations with 100 accounts. The security team wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. They create an SCP that denies all actions if MFA is not present. However, some users report that they cannot access the console even with MFA. What is the most likely reason?
Hard43A company uses AWS Organizations with a management account and several member accounts. The security team needs to centrally manage IAM users and roles across all accounts. Which AWS service should the company use?
Easy44Drag and drop the steps to restore an Amazon RDS DB instance from a snapshot in the correct order.
Medium45A company is designing a multi-account strategy using AWS Organizations. The security team requires that all API calls to create or modify IAM roles are logged and alerted. Which TWO steps should be taken to meet this requirement?
Medium46A company uses AWS Organizations to manage multiple accounts. The central team wants to deploy a CloudFormation template that creates an S3 bucket with default encryption in every member account. Which THREE steps are required to accomplish this?
Easy47A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all newly created Amazon S3 buckets are encrypted with AWS KMS keys managed by the security account, and that any attempts to create unencrypted buckets are denied. The company also wants to ensure that existing buckets are remediated. Which two actions should the security team take to meet these requirements? (Choose two.)
Medium48A company has a decentralized IT structure where each business unit manages its own AWS account. The central security team needs visibility into all IAM user activities across accounts. What is the MOST scalable solution to aggregate CloudTrail logs?
Easy49A company has an AWS Organization with multiple accounts. The central IT team wants to deploy a common set of AWS Config rules across all accounts in the production OU. Which approach is the MOST scalable and maintainable?
Easy50A company wants to implement a multi-account strategy using AWS Organizations. The security team requires that all new accounts added to the organization automatically inherit a baseline set of security controls, such as AWS CloudTrail and AWS Config rules. Which approach should the company use?
Medium51A company has a centralized logging account that receives VPC flow logs from all accounts. The logs are stored in an S3 bucket. The security team needs to analyze these logs to detect anomalous traffic patterns. Which solution provides the most cost-effective and scalable analysis?
Medium52A multinational corporation uses AWS Organizations to manage multiple accounts across different geographic regions. The company needs to ensure that all data residing in AWS accounts for a specific country remains within that country's boundaries. Which combination of AWS services and features should the company use to enforce this data residency requirement?
Hard53A company has a centralized network account that hosts a transit gateway with attachments to multiple VPCs in different accounts. The security team needs to ensure that all traffic between VPCs is inspected by a centralized NGFW appliance in the network account. What is the MOST efficient solution?
Medium54A company is designing a multi-account strategy for its development teams. Each team needs to have its own isolated environment with VPCs, subnets, and security groups. The company wants to centralize network administration and ensure that all VPCs use a common set of security rules. Which THREE steps should the company take? (Choose THREE.)
Hard55A company manages multiple AWS accounts using AWS Organizations. The security team needs to enforce that all newly created accounts automatically have a specific set of security controls, including AWS Config rules and an AWS CloudTrail trail. Which solution meets these requirements with the LEAST operational overhead?
Medium56A company manages multiple AWS accounts and wants to centralize billing and cost tracking. They have enabled AWS Organizations and consolidated billing. Which additional step should they take to gain granular visibility into costs per department?
Medium57A healthcare company has 200 AWS accounts in AWS Organizations. The security team wants to prevent any principal in member accounts from disabling AWS CloudTrail or deleting the organization trail, even if they have administrator permissions in their own account. The solution must be centrally managed and apply to all existing and future accounts. Which approach should a solutions architect recommend?
Hard58A multinational corporation is migrating its on-premises Active Directory (AD) to AWS Managed Microsoft AD. The company has a hub-and-spoke VPC topology with a central transit gateway. The AD domain controllers must be deployed in two different AWS Regions for disaster recovery. The corporate security policy requires that all AD traffic between Regions must traverse the transit gateway and be inspected by a third-party firewall appliance deployed in the inspection VPC. Which architecture meets these requirements?
Medium59A company uses AWS Organizations and wants to centrally manage Amazon GuardDuty across all accounts. Which TWO steps are required to enable GuardDuty in all accounts from a single management account?
Medium60A company has a multi-account AWS environment managed with AWS Organizations. The finance team wants to consolidate billing and receive a single bill for all accounts, while still allowing each account to have its own service usage and cost allocation tags. The company also wants to apply volume discounts across accounts. Which AWS Organizations feature should the solutions architect enable?
Easy61A company is managing multiple AWS accounts using AWS Organizations. They want to centralize the management of EC2 instances and enforce tagging standards across all accounts. Which TWO approaches should they use?
Medium62A company has multiple AWS accounts and wants to centrally manage VPC flow logs for all accounts. The flow logs should be sent to a central S3 bucket in the logging account. The solution must be automated for new accounts added to the organization. What should the team do?
Medium63A company is designing a centralized logging solution for multiple AWS accounts. The solution must meet compliance requirements that logs be immutable and stored for 7 years. Which THREE services should be combined to achieve this?
Medium64A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to prevent member accounts from disabling AWS CloudTrail or modifying its configuration. They also want to ensure that all CloudTrail logs are stored in a central S3 bucket in the management account. Which combination of actions should be taken?
Easy65Which TWO actions should a company take to implement a least-privilege access model across multiple AWS accounts? (Choose TWO.)
Medium66A company has a single AWS account and wants to implement a multi-account strategy using AWS Organizations. They need to centrally manage billing and apply policies to restrict which AWS services can be used in each account. The company also wants to ensure that new accounts automatically inherit these restrictions. Which step should they take first to set up AWS Organizations with these capabilities?
Easy67A company has a multi-account AWS environment with a central security account. The security team needs to audit all API activity across all accounts and retain the logs for 7 years in a tamper-evident manner. They also need to ensure that no account administrator can disable or modify the logging configuration. Which solution meets these requirements?
Hard68A company is using AWS Organizations with a set of member accounts that need to access a shared Amazon S3 bucket in the master account. The bucket policy allows access only from the member accounts' root user. However, developers in member accounts are unable to access the bucket even when they assume an IAM role. What is the most likely cause?
Hard69A multinational company is adopting AWS Organizations to manage multiple accounts across business units. The security team requires that specific IAM roles be automatically deployed to all existing and future member accounts. Which solution should the company use?
Medium70Match each AWS service to its primary use case.
Medium71A company is deploying a multi-account AWS environment using AWS Organizations. The security team requires that all Amazon S3 buckets in member accounts are encrypted with AWS KMS customer managed keys, and that the keys are created and managed centrally in a security account. Which solution should a solutions architect recommend?
Medium72A company has multiple AWS accounts managed via AWS Organizations. The security team requires that all S3 buckets across all accounts must block public access. How can this be enforced centrally with minimal operational overhead?
Medium73A multinational company is implementing a multi-account strategy using AWS Organizations. The security team needs to ensure that all newly created accounts automatically have a specific baseline CloudTrail trail and a set of AWS Config rules applied. The company also wants to enforce that no account can disable these controls. Which solution should be used?
Hard74A company has a multi-account AWS environment and wants to centralize the management of IAM roles. The security team needs to ensure that all IAM roles across all accounts trust the same identity provider (IdP) for federated access. The company uses AWS IAM Identity Center (successor to AWS SSO) for user management. Which solution should be implemented?
Medium75A large enterprise is migrating to AWS and wants to implement a multi-account strategy with centralized network connectivity. The company has multiple VPCs in various accounts that need to communicate with each other and with on-premises resources. The solution must be scalable and minimize operational overhead. Which design should be used?
Hard76A company is migrating a legacy monolithic application to a microservices architecture on AWS. The application has strict latency requirements and must be deployed across multiple Availability Zones. Which design strategy BEST meets these requirements while minimizing operational overhead?
Hard77A company wants to centralize AWS CloudTrail logs from all accounts in AWS Organizations into a single S3 bucket. Which configuration is required?
Easy78A company uses a single AWS account for development and production workloads. To improve security and cost allocation, the company decides to separate environments into multiple accounts. What is the PRIMARY benefit of using multiple accounts?
Easy79A company wants to centrally manage IAM users across multiple AWS accounts using AWS IAM Identity Center (successor to AWS Single Sign-On). Which of the following are true? (Choose TWO.)
Easy80Match each AWS migration service to its function.
Medium81A company uses AWS Organizations and wants to centrally manage AWS Config rules across all member accounts. They have enabled AWS Config in the management account and used AWS Config aggregator to view compliance status across accounts. However, they want to enforce a specific Config rule in all accounts automatically. Which solution should they use?
Medium82Refer to the exhibit. A company has created a CloudTrail trail named 'my-trail' in the management account of AWS Organizations. The trail is configured to deliver logs to a central S3 bucket. The security team wants to capture all management events from all accounts in the organization. Based on the exhibit, what is the most likely issue?
Medium83A company has a large AWS Organizations environment with 200 accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that the roles are deployed to all existing and future accounts, and that any changes to the roles are automatically propagated. Which solution should they use?
Hard84A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a member account. Which step is required?
Easy85A company uses AWS Organizations and wants to establish a central logging solution. They need to collect CloudTrail logs from all accounts and store them in a central S3 bucket in the management account. Which TWO steps are required to achieve this?
Medium86A company has a central IT team that manages AWS Organizations. The development team needs to create and manage their own AWS accounts for new projects. What is the BEST way to automate account creation while maintaining governance?
Medium87A company uses AWS Organizations and has a requirement that all Amazon S3 buckets must have versioning enabled. The company wants to automatically enable versioning on any bucket that is created without it. Which solution should be implemented?
Easy88A company is using AWS Organizations with multiple accounts. The central IT team wants to enforce that all EC2 instances are launched with specific tags (e.g., CostCenter and Environment). The solution should prevent any untagged instances from being created. Which approach should be taken?
Medium89A healthcare company operates a multi-account AWS environment with AWS Organizations. A central Security account runs Amazon GuardDuty and AWS Security Hub, and all member accounts are delegated administrators for those services. The company now wants to centrally manage Amazon Inspector findings across all accounts and ensure that new accounts are automatically covered. Which solution meets these requirements with the LEAST operational effort?
Hard90A company is implementing a multi-account strategy using AWS Organizations. They want to centralize CloudTrail logs from all accounts into a single S3 bucket in the management account. Which TWO steps are required to achieve this? (Choose two.)
Medium91A company is using AWS Organizations to manage multiple accounts. The security team requires that all newly created member accounts automatically have an AWS Config rule enabled that checks whether S3 buckets have default encryption enabled. Which solution should be used?
Medium92A company has a multi-account AWS environment with a central shared services VPC and multiple workload VPCs connected via AWS Transit Gateway. The security team wants to inspect all traffic between workload VPCs using a centralized firewall appliance in the shared services VPC. They need to ensure that traffic is inspected without modifying the workload VPC route tables. What should they do?
Hard93A company uses AWS Organizations and wants to allow certain accounts to use AWS Service Catalog for self-service provisioning. The IT team needs to control which products are available. Where should the product portfolio be shared?
Medium94A company has a multi-account AWS environment with a central network account and multiple workload accounts. They want to use AWS Transit Gateway to connect VPCs across accounts. The network team has created a Transit Gateway in the network account and shared it using AWS Resource Access Manager (RAM) with the workload accounts. The workload accounts have created VPC attachments to the Transit Gateway. However, traffic is not flowing between the VPCs. The route tables in the workload VPCs have routes pointing to the Transit Gateway. What is the most likely cause?
Hard95A company is expanding its AWS Organizations environment to include several new business units. The security team must ensure that all new accounts automatically have a baseline security configuration, including a VPC with specific flow logs enabled, an AWS Config recorder, and a set of IAM roles for cross-account access. They want to minimize manual effort and ensure consistency. Which two solutions should they use to achieve these goals? (Choose two.)
Hard96A company wants to centralize management of AWS resources across multiple accounts using AWS Control Tower. What is a prerequisite for setting up Control Tower?
Easy97A company uses AWS Organizations with a single OU for all accounts. The security team wants to prevent any account from leaving the organization without approval. What should they do?
Easy98A global company uses a multi-account AWS Organizations structure with hundreds of accounts. The network team wants to centrally manage VPC flow logs for all accounts and send them to a centralized S3 bucket in the security account. Which solution is MOST scalable and operationally efficient?
Hard99A company is implementing a hybrid network architecture with multiple VPCs in different AWS accounts. They need to ensure private connectivity between the VPCs and their on-premises data center. Which TWO services should they use together to meet this requirement?
Medium100A company has a VPC with a CIDR block of 10.0.0.0/16. They need to connect this VPC to an on-premises network that uses the CIDR block 10.0.0.0/8. The company wants to use AWS Site-to-Site VPN for the connection. They must avoid IP address conflicts. What is the MOST appropriate solution?
Hard101A financial services company uses AWS Organizations with all features enabled. A security account runs AWS CloudFormation StackSets with service-managed permissions to deploy guardrail resources into every account. Compliance requires that no member account administrator can disable AWS CloudTrail or delete the organization trail, even in accounts where they hold full administrative rights, and that new accounts automatically receive the guardrail. Which combination should the solutions architect recommend?
Hard102A startup has 25 AWS accounts in a single organization. A new compliance officer wants a single, read-only view of all resources and their configuration across every account, and wants to be alerted when an S3 bucket becomes publicly accessible. The team has no existing aggregation tooling. Which approach requires the least operational effort?
Easy103A company has multiple AWS accounts and wants to use AWS CloudFormation StackSets to deploy a common set of resources across all accounts. The StackSet should be managed from the management account. What permissions are required?
Medium104A company uses AWS Config to evaluate resource compliance across multiple accounts. The security team wants to automatically remediate non-compliant resources using AWS Systems Manager Automation documents. Which solution is MOST scalable and secure?
Hard105A company has a centralized logging solution using Amazon S3 and AWS CloudTrail. They want to ensure that logs are immutable and cannot be deleted or modified by any user, including the root user. Which S3 feature should be enabled?
Easy106A company is designing a multi-account strategy for its development, testing, and production environments. The security team requires that all accounts share a centralized logging solution. Which approach meets this requirement with the LEAST administrative overhead?
Easy107A company is implementing a multi-account strategy using AWS Organizations. They need to centralize logging of all API calls across accounts. Which solution meets this requirement with the least operational overhead?
Medium108A company uses AWS Organizations with multiple accounts. The central IT team wants to restrict the use of specific EC2 instance types across all accounts to control costs. Which approach should the team use?
Easy109A financial services company uses AWS Organizations with 300 member accounts. The security team wants to ensure that all AWS API activity in every account is logged to a central Amazon S3 bucket owned by the management account. The logs must be immutable for 7 years and protected from deletion by any member account administrator. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?
Hard110A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a specific member account. What must be done?
Medium111A company wants to allow developers to assume a role in a production account from their development account using AWS IAM. What is needed for this cross-account access?
Easy112A company is using AWS Organizations with consolidated billing. The company has a production account and a development account. The security team needs to ensure that developers cannot create IAM users in the development account. Which option is the MOST effective?
Medium113A financial services company has an AWS Organizations structure with a management account, a dedicated network account, and 40 workload accounts. Each workload account has its own VPC, and all VPCs must be able to reach a shared services VPC in the network account. The security team requires that all inter-VPC traffic be inspected by a central firewall appliance before reaching the shared services. Which solution meets these requirements with the LEAST operational overhead?
Medium114A company has a multi-account AWS environment with a centralized security account. The security team needs to have read-only access to all Amazon S3 buckets across all accounts for auditing purposes. Which solution is the MOST secure and scalable?
Medium115Which TWO actions improve the security of an S3 bucket that stores sensitive data?
Medium116A company uses AWS Organizations with multiple accounts. The finance team needs to track costs by department, where each department uses resources across several accounts. What is the BEST way to allocate costs accurately?
Medium117A company uses AWS Organizations and wants to centrally manage backups of EC2 instances across multiple accounts. Which service should they use?
Easy118A company uses AWS Control Tower to manage a multi-account environment. The security team needs to ensure that all accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket. What is the BEST way to achieve this?
Easy119A company is using AWS Organizations with hundreds of accounts. The central IT team needs to deploy a common set of AWS resources (e.g., VPCs, subnets, security groups) to all accounts in a specific organizational unit (OU). The solution must be automated and ensure that new accounts added to the OU automatically receive the resources. Which three steps should the team take? (Choose three.)
Hard120A company has a production AWS account and a development AWS account. The development team needs to assume an IAM role in the production account to deploy resources. What is the correct way to set up this cross-account access?
Easy121A company has 30 AWS accounts in AWS Organizations. The finance team wants to receive a single consolidated bill for all accounts and apply volume discounts across the organization. Which action should a solutions architect take?
Easy122A company has a complex AWS environment with multiple accounts and VPCs. The company wants to ensure that all outbound traffic from VPCs goes through a centralized inspection VPC for security monitoring. The company uses AWS Transit Gateway. Which solution should be implemented?
Hard123A company has a production AWS account and a development AWS account under AWS Organizations. The development team wants to deploy a CloudFormation stack that creates an S3 bucket with a bucket policy that grants access to the production account's IAM roles. The development account has an SCP that denies all s3:PutBucketPolicy actions. The development team has full administrator access in their account. When they try to create the stack, it fails. What is the most likely reason and how should they proceed?
Medium124A healthcare company has a multi-account AWS environment with a central audit account. The security team needs to ensure that all API activity across all accounts is logged and that logs are stored immutably for 7 years. They also need to be able to search logs across all accounts quickly. Which solution meets these requirements with the LEAST operational overhead?
Medium125A company has a multi-account AWS environment and wants to implement a secure, scalable cross-account network architecture using AWS Transit Gateway. Which TWO steps should be taken?
Medium126A company has a multi-account AWS environment using AWS Organizations with 50 accounts. The accounts are organized into OUs based on environment: Production, Staging, and Development. The central IT team uses AWS CloudFormation StackSets to deploy a baseline network configuration (VPC, subnets, security groups) to all accounts. Recently, the network team updated the stack set to add a new subnet to the VPC. After the update, they noticed that the stack set operation failed for 10 accounts. The error message indicates that the stack set cannot update because a resource already exists. What is the MOST LIKELY cause of this failure?
Medium127A media company uses AWS Organizations with a central shared services account that hosts a Transit Gateway. Workload accounts in two OUs must be able to route traffic through the Transit Gateway to on-premises networks via AWS Site-to-Site VPN, but must not be able to route traffic to each other. A solutions architect needs to enforce this segmentation centrally. What should the architect do?
Medium128A company has a single AWS account with multiple VPCs. They want to connect all VPCs to a central VPC for shared services, such as Active Directory and DNS, without using a complex mesh of VPC peering connections. They also want to minimize costs. Which solution should they use?
Easy129A multinational enterprise uses AWS Organizations with 300 accounts. The network team wants to centrally manage VPC IP address allocation and share subnets across multiple accounts to simplify connectivity. They also need to ensure that when a new account is created, it automatically receives a VPC with a predefined CIDR that does not overlap with existing VPCs. Which combination of AWS services should they use?
Hard130A company has 200 AWS accounts in AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security tooling account. The roles must be created consistently in every account, and any change to the role trust policy must propagate automatically. Which approach requires the LEAST ongoing effort?
Medium131A company is designing a multi-account strategy for development, testing, and production environments. They want to ensure that developers can deploy resources in development and testing accounts but not in production. Which TWO methods should the company use to achieve this? (Choose TWO.)
Easy132A company is using AWS Organizations to manage 50 accounts. They want to centralize billing and also allow a central team to manage IAM roles across all accounts. The central team needs to be able to assume a role in any member account to perform administrative tasks. They have already enabled all features in Organizations. Which two steps are required to allow the central team to assume roles in member accounts? (Choose two.)
Medium133A financial services company has an AWS Organizations structure with a management account, a dedicated Network account, and 40 workload accounts. The Network team wants to share a single AWS Transit Gateway with all workload accounts so that each account can attach its own VPCs. Workload accounts must not be able to modify the Transit Gateway route tables owned by the Network account. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?
Medium134A company has a management account in AWS Organizations and wants to share a central Amazon VPC subnet with multiple member accounts for a shared services VPC. Which AWS service should be used to share the subnet?
Medium135A company has multiple VPCs across different AWS accounts and wants to establish private connectivity between them. They also need to centrally manage network traffic for security inspection. Which architecture should they use?
Hard136A company has multiple AWS accounts and wants to share a centrally managed Amazon VPC subnet for workloads that require low latency. The VPC is in the networking account. Which solution meets these requirements with the LEAST operational overhead?
Medium137A company is designing a network architecture for a multi-account AWS environment. They need to establish a central inspection VPC through which all traffic between VPCs in different accounts must pass. Which AWS service should be used to route traffic between VPCs through the inspection VPC?
Easy138A company is designing a multi-account strategy using AWS Organizations. They want to enforce that no one can disable AWS CloudTrail in any account. Which TWO methods can achieve this?
Medium139A company is using AWS Organizations with a centralized networking account that hosts a transit gateway. The company wants to ensure that all traffic between VPCs in different accounts flows through the transit gateway. Which THREE steps are required to implement this architecture?
Hard140A company has a management account in AWS Organizations. It wants to delegate administration of AWS IAM Identity Center to a member account for user management. What is the correct way to achieve this?
Easy141A company has an AWS Organizations environment with a management account, a central log archive account, and many workload accounts. The security team must prevent workload accounts from disabling AWS CloudTrail, deleting the central log bucket, or leaving the organization, while still allowing account administrators to manage their own resources. (Choose two.)
Hard142A company has a multi-account AWS environment with over 500 accounts. The security team uses AWS Config to evaluate resource compliance across all accounts. They have set up an AWS Config aggregator in the security account to collect configuration snapshots from all member accounts. Recently, the team noticed that some member accounts are not showing up in the aggregator. The accounts are active and have AWS Config enabled. What should the security team do to troubleshoot this issue?
Medium143A company has multiple AWS accounts and wants to centralize CloudTrail logs from all accounts into a single S3 bucket in the audit account. Which configuration is required?
Medium144A solutions architect needs to design a network architecture for a multi-account AWS environment using AWS Transit Gateway. The company requires that all traffic between VPCs be inspected by a central security appliance. What is the MOST efficient way to achieve this?
Easy145A company has a multi-account strategy with a dedicated audit account. The audit account needs to have read-only access to all resources in all other accounts. The security team wants to use IAM roles. What is the MOST scalable way to set up this cross-account access?
Hard146Refer to the exhibit. A solutions architect is troubleshooting why EC2 instances launched in subnet-11111111 cannot access the internet. The subnet is in a VPC with an internet gateway attached. The route table for the subnet has a default route (0.0.0.0/0) pointing to the internet gateway. What is the MOST likely cause?
Hard147A company is adopting AWS Organizations and wants a baseline set of IAM roles, a standard VPC, and a security agent deployed automatically into every new account the moment it is created. The operations team does not want to run scripts manually after each account creation. Which AWS service should they use to meet this requirement?
Easy148A company wants to implement a data lake on AWS with data from multiple sources. They need to store data in its raw format and allow multiple teams to query it using different tools. Which service should be used as the central storage layer?
Easy149A financial services company uses AWS Organizations with a central networking account. Workload accounts need to reach an on-premises data center over AWS Site-to-Site VPN, and the network team wants to enforce that all inter-VPC traffic flows through a central inspection VPC. Which combination of components should the network team deploy to route traffic through the inspection VPC while keeping the architecture scalable?
Hard150A company uses AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a member account. Which step is required to set this up?
Medium151A company has an AWS Organizations structure with a management account and 40 member accounts grouped into four OUs. The security team wants a single AWS account to receive all Amazon GuardDuty findings from every account and to view them in one place. They also need new accounts created under any OU to be automatically enrolled. Which solution meets these requirements with the LEAST operational overhead?
Medium152A multinational corporation is deploying a multi-account AWS environment using AWS Organizations. The security team requires that all S3 buckets across all accounts be encrypted with a specific AWS KMS key managed by the security account. Which solution should the company implement to enforce this policy across the organization?
Medium153A company has multiple AWS accounts and wants to centrally manage CloudWatch dashboards. Which solution should they use?
Easy154A company is using AWS Organizations with a hierarchical OU structure. The security team wants to enforce that any new account created in the organization automatically inherits a baseline set of AWS Config rules and a VPC with a default CIDR block. What is the MOST efficient way to achieve this?
Medium155A financial services company uses AWS Organizations with 60 accounts. The security team has enabled AWS CloudTrail organization trails in the management account and wants to prevent any member account administrator from disabling CloudTrail logging in their own account. Which solution will meet this requirement with the LEAST operational overhead?
Medium156A media company has 200 AWS accounts in AWS Organizations. The networking team wants to provide each account with a shared VPC subnet from a central networking account. The central networking account owns the VPC and subnets. Workload accounts must be able to launch resources into the shared subnets, but they must not be able to modify the subnet configuration or delete the shared subnets. Which solution meets these requirements?
Medium157A company needs to share a central Amazon S3 bucket containing common data files with multiple accounts in AWS Organizations. Which approach is most secure and scalable?
Easy158A company uses AWS Organizations with 50 accounts. The network team wants to centrally manage VPC flow logs for all accounts, storing them in a central S3 bucket in the security account. The flow logs must be encrypted with a KMS key managed by the security account. What is the MOST efficient way to configure this?
Hard159A company has a central IT team that manages multiple AWS accounts. The team wants to allow developers to create resources in their own accounts but wants to restrict the use of certain expensive services like Amazon Redshift. The developers should not be able to launch Redshift clusters in any account. What is the MOST efficient way to achieve this?
Easy160A global e-commerce company is migrating its on-premises application to AWS. The application uses Active Directory for authentication and requires integration with AWS Managed Microsoft AD. The company has a multi-account strategy using AWS Organizations. Which TWO steps should the solutions architect take to ensure seamless authentication across the organization?
Easy161A company is designing a multi-account strategy for its AWS environment. Which TWO considerations are important when using AWS Organizations?
Medium162A large financial services company uses AWS Organizations with over 200 accounts. The security team has implemented a Service Control Policy (SCP) that denies access to all services except a whitelist that includes Amazon S3, Amazon DynamoDB, AWS Lambda, and Amazon CloudWatch. Recently, the DevOps team reported that they cannot create new EC2 instances in their development account, even though the administrator explicitly attached an IAM policy allowing ec2:RunInstances. The SCP does not explicitly deny EC2. What is the most likely cause of this issue?
Hard163A company uses AWS Organizations with multiple OUs. The DevOps team needs to allow developers to launch EC2 instances only of type t3.micro in the dev OU. Which action should the team take?
Easy164A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account for incident response. They need to ensure that the roles can be assumed only by specific IAM principals in the security account and that the permissions are consistent across all member accounts. Which approach meets these requirements with the LEAST operational overhead?
Medium165A company uses AWS Organizations and wants to delegate administrative tasks for specific AWS services to a member account. Which AWS feature should be used?
Easy166A company uses AWS Organizations and has deployed a multi-account strategy. The security team wants to enforce that all S3 buckets have versioning enabled. They create an SCP that denies the PutBucketVersioning action if versioning is not enabled. However, they find that the SCP is not preventing users in member accounts from disabling versioning on existing buckets. What is the most likely reason?
Hard167A company is designing a multi-account strategy using AWS Organizations. Which TWO benefits does this approach provide? (Choose TWO.)
Medium168A company has a multi-account environment with AWS Organizations. The security team wants to enforce that all EC2 instances launched in any account must have a specific tag key 'CostCenter'. Which approach should be used?
Hard169Drag and drop the steps to set up a Direct Connect private virtual interface in the correct order.
Medium170A company has a multi-account AWS environment with hundreds of accounts. The security team needs to centrally manage IAM roles for cross-account access. They want to ensure that when a role is created in a member account, it automatically adheres to the principle of least privilege and is auditable. What solution should they implement?
Hard171A company has a multi-account AWS environment with a central shared services VPC in a networking account. They want to allow resources in workload accounts to access a shared Amazon RDS database in the shared services VPC. The RDS database is in a private subnet. The company uses AWS Transit Gateway to connect all VPCs. They have set up a route in the workload VPC route table pointing to the Transit Gateway for the shared services VPC CIDR. However, resources in the workload accounts cannot connect to the RDS database. What is the most likely cause?
Hard172A company has a production AWS account that is part of an AWS Organization. The account has a VPC with a NAT gateway for internet access. The security team wants to ensure that all outbound traffic to the internet flows through a centralized inspection VPC in the security account for traffic inspection. Which architecture should be used?
Hard173A company is centralizing its logging across multiple AWS accounts using a central logging account. Each application account delivers its CloudTrail logs and VPC Flow Logs to an S3 bucket in the logging account. The security team needs to query these logs using Amazon Athena. The logs are currently in separate S3 prefixes per account. The team wants to create a single Athena table that can query logs from all accounts without having to modify the table definition every time a new account is added. The logs are in CSV format for VPC Flow Logs and JSON format for CloudTrail. What is the MOST efficient solution?
Medium174A company wants to automate the creation of new AWS accounts and apply baseline security configurations. Which combination of services should be used to achieve this?
Easy175A company with multiple AWS accounts wants to centralize CloudTrail logging. They create a CloudTrail trail in the management account that logs all events across all accounts and regions. However, the security team notices that some management events from member accounts are not being logged. What is the most likely cause?
Hard176A startup is using a single AWS account for development, testing, and production. They want to isolate environments and improve security. What is the most aligned AWS best practice?
Easy177Which THREE design patterns are recommended for decoupling components in a microservices architecture on AWS?
Hard178A company has a multi-account AWS environment managed by AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. The roles must be automatically created in all existing and future accounts, and any changes to the roles must be applied consistently. Which solution meets these requirements with the LEAST administrative effort?
Medium179A large enterprise is consolidating 300 AWS accounts under AWS Organizations. The security team needs a way to centrally define and deploy IAM roles that grant break-glass access, must ensure the roles can be assumed only by members of a specific federated group, and must be able to update the roles across all accounts without logging into each account. (Choose two.)
Medium180A company uses AWS Organizations and wants to ensure that all member accounts have AWS CloudTrail enabled and logs are delivered to a central S3 bucket in the management account. Which approach is MOST efficient?
Easy181A global company is using a multi-account AWS Organizations setup with a centralized logging account. They want to aggregate CloudTrail logs from all accounts into a single S3 bucket in the logging account. Which combination of steps will meet this requirement?
Medium182A company has a multi-account environment with a central security account. They want to use AWS Security Hub to aggregate findings from all accounts. What is the correct setup?
Medium183A company uses AWS Organizations with hundreds of accounts. The security team needs to ensure that no IAM user in any account can create a new IAM user or access key. What is the most scalable way to enforce this?
Hard184A company is migrating to a multi-account AWS environment. They want to centralize DNS management using Amazon Route 53 private hosted zones. The private zones must be accessible from all VPCs in the organization. Which THREE steps are required to achieve this?
Hard185A multinational corporation uses AWS Organizations with hundreds of accounts. The security team requires that all Amazon S3 buckets across the organization be encrypted with a specific AWS KMS key from the security account. Which combination of controls should be implemented to enforce this requirement?
Hard186A company has multiple AWS accounts managed using AWS Organizations. The security team wants to enforce that all new accounts automatically have a specific AWS Config rule enabled to prohibit public S3 bucket access. Which solution requires the least operational overhead?
Medium187A company needs to share a VPC subnet with multiple accounts in the same AWS Organization. What is the MOST secure way to achieve this?
Easy188A company has a decentralized IT structure where each business unit manages its own AWS accounts. The central IT team wants to enforce security policies across all accounts but allow business units to retain administrative control. Which solution should the central IT team implement?
Easy189A company has a multi-account AWS environment with AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that only the audit account can assume these roles and that the roles are automatically created in all existing and future accounts. What should they do?
Medium190A company is using AWS Organizations with all features enabled. They want to apply a service control policy (SCP) that denies the ability to delete AWS KMS keys across all member accounts, but they need to allow a specific break-glass role in the management account to delete keys in case of emergency. Which statement is true regarding SCP enforcement in this scenario?
Easy191A company wants to ensure that no IAM user in any account can create access keys. The company uses AWS Organizations. Which approach should be used?
Easy192A company has a single AWS account and wants to implement a multi-account strategy for better isolation. Which AWS service is designed to help centrally manage multiple accounts?
Easy193A company uses AWS Organizations with several OUs for different environments (dev, test, prod). They want to restrict the use of specific EC2 instance types in the prod OU only. Which approach should they use?
Easy194A company uses AWS Organizations and has a requirement that all root user activities in member accounts must be immediately reported to the security team. Which combination of actions should be taken to meet this requirement? (Choose the best answer.)
Easy195A company is migrating to AWS and plans to use a multi-account strategy. The management account will be used solely for administrative purposes. Which best practice should be followed when setting up AWS Organizations?
Easy196A company has a multi-account AWS environment with a centralized network account that hosts a transit gateway. The company wants to share the transit gateway with multiple member accounts. Which AWS service should be used to share the transit gateway?
Easy197A company wants to provide its developers with access to a shared development environment in AWS. The developers are in different AWS accounts, and they need to assume an IAM role in the development account. What is the secure way to allow cross-account access?
Easy198A company uses AWS Organizations with consolidated billing. The finance team needs to track costs by department, which are tagged with 'department' tags. However, some resources are not tagged. The team wants to ensure that all new resources are tagged, and existing untagged resources are identified. What should they do?
Medium199A company is using AWS Organizations and wants to allow certain member accounts to create VPCs with specific CIDR ranges. Which mechanism should be used to enforce this restriction?
Easy200A company wants to implement a least-privilege security model across multiple AWS accounts. Which TWO services can help enforce this?
MediumOther domains
All SAP-C02 exam domains
Frequently asked questions
- What does the Design Solutions for Organizational Complexity domain cover on the SAP-C02 exam?
- You must be able to design multi-account governance and cross-account networking: apply SCPs, centralize CloudTrail logs, share resources with RAM, and route traffic via Transit Gateway. The single most important thing is knowing SCPs filter permissions but never grant them.
- How many questions are in this domain?
- This page lists all 200 Design Solutions for Organizational Complexity questions in the SAP-C02 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Design Solutions for Organizational Complexity questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.