SAA-C03 Design Cost-Optimized Architectures Practice Question
Multiple teams share one AWS Organization. Finance wants chargeback by project, alerts before overspend, and monthly views by account without manually opening each account. Which three actions best fit? Select three.
⚠ Common exam trap
Many exam-takers confuse CloudTrail (which records API calls) with AWS Cost Explorer or CUR (which provide actual cost data), leading them to incorrectly select option E for cost estimation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce cost allocation tags on resources and activate them for billing reports.
Option A is correct because enforcing and activating cost allocation tags (e.g., project tags) is the prerequisite for attributing AWS charges to projects in billing data, enabling accurate chargeback. Option B is correct because AWS Budgets supports cost budgets scoped by tag, account, or service, and can trigger SNS alerts and budget actions (such as applying SCPs or stopping instances) before overspend occurs. Option C is correct because Cost Explorer and Cost and Usage Reports (CUR) provide the consolidated, multi-account analysis by account, tag, and service that Finance needs without manually opening each account, especially when integrated with AWS Organizations. Option D is not appropriate because merely isolating teams into separate accounts without tagging does not provide project-level chargeback or the required tag-based views. Option E is incorrect because CloudTrail records API activity for auditing, not resource costs, and cannot estimate spend by resource.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enforce cost allocation tags on resources and activate them for billing reports.
Why this is correct
Enforcing cost allocation tags and activating them for billing reports creates the project dimension Finance needs for chargeback, since AWS only surfaces tag-level costs once tags are activated in Billing. This directly satisfies the stem's requirement to attribute shared-account spend by project rather than by account alone.
- ✓
Use AWS Budgets to create alerts and budget actions for each project.
Why this is correct
AWS Budgets tracks cost or usage against a defined threshold and triggers alerts, satisfying Finance's requirement for pre-overspend notification. Budget actions can then apply controls automatically when thresholds breach. Scoped per project via cost allocation tags, this delivers the project-level alerting the stem demands without manual account-by-account monitoring.
- ✓
Use Cost Explorer or Cost and Usage Reports to analyze spend by account, tag, and service.
Why this is correct
Cost Explorer and Cost and Usage Reports both break spend down by account, tag, and service, satisfying the chargeback-by-project and monthly per-account reporting needs without opening each account. Cost Explorer also supports budget alerts, covering the overspend notification requirement. This directly addresses the Finance team's three stated constraints.
- ✗
Put every team in a separate AWS account and ignore tagging.
Why it's wrong here
Separate accounts give cost isolation but no project-level attribution, and ignoring tagging removes the dimension Finance needs for chargeback. It is tempting because account separation is a genuine AWS best practise for blast-radius and billing boundaries, just not for per-project reporting.
When this WOULD be correct
If the question asked for the best way to ensure security isolation and prevent resource sharing between teams, with cost tracking done via consolidated billing reports per account, then separate accounts without tagging would be correct.
- ✗
Use CloudTrail trails to estimate spend by resource because it records API calls.
Why it's wrong here
CloudTrail records API activity, not resource cost or pricing, so it cannot produce spend figures or budget alerts. It is tempting because CloudTrail logs do identify which principal called which API, which supports forensic auditing rather than financial chargeback.
When this WOULD be correct
If a question asked for a service to track API activity for security auditing or to identify which user created a resource, CloudTrail would be the correct answer. For example: 'Which service records API calls for operational and risk auditing?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Enforce cost allocation tags on resources and activate them for billing reports.Correct answer▾
Why this is correct
Enforcing cost allocation tags and activating them for billing reports creates the project dimension Finance needs for chargeback, since AWS only surfaces tag-level costs once tags are activated in Billing. This directly satisfies the stem's requirement to attribute shared-account spend by project rather than by account alone.
✗Put every team in a separate AWS account and ignore tagging.Wrong answer — click to see why▾
Why this is wrong here
Putting teams in separate accounts without tagging prevents chargeback by project and requires manual account access for monthly views, failing to meet the requirements for cost allocation and automated reporting.
★ When this WOULD be the correct answer
If the question asked for the best way to ensure security isolation and prevent resource sharing between teams, with cost tracking done via consolidated billing reports per account, then separate accounts without tagging would be correct.
Why candidates choose this
Candidates may think separate accounts inherently solve cost tracking, overlooking that chargeback by project still requires tags or other mechanisms to break down costs within an account.
✗Use CloudTrail trails to estimate spend by resource because it records API calls.Wrong answer — click to see why▾
Why this is wrong here
CloudTrail records API calls for auditing, not cost allocation. It does not provide cost or usage data by resource, tag, or project, so it cannot support chargeback, alerts, or monthly views by account.
★ When this WOULD be the correct answer
If a question asked for a service to track API activity for security auditing or to identify which user created a resource, CloudTrail would be the correct answer. For example: 'Which service records API calls for operational and risk auditing?'
Why candidates choose this
Candidates may think CloudTrail can estimate costs because it logs resource creation events, but it lacks pricing data and cannot aggregate spend by tag or account.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.