Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has 200 AWS accounts in AWS Organizations. The compliance team needs to prove that all Amazon S3 buckets across every account have server-side encryption enabled and block public access, and they want a single dashboard showing compliance status. Which solution should they implement?

⚠ Common exam trap

The trap here is substituting a data-classification service such as Amazon Macie, or a custom Lambda pipeline, for the configuration compliance capability that AWS Config aggregators provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS Config in each account with an aggregator in the compliance account and deploy managed rules for S3 encryption and public access using AWS CloudFormation StackSets.

AWS Config aggregators consolidate configuration and compliance data from all accounts and Regions into an administrator account, and managed rules can evaluate S3 encryption and public access settings. Using CloudFormation StackSets to deploy the rules ensures uniform coverage across 200 accounts, and the aggregator supplies the single compliance dashboard the team needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable AWS Config in each account with an aggregator in the compliance account and deploy managed rules for S3 encryption and public access using AWS CloudFormation StackSets.

    Why this is correct

    AWS Config aggregators collect configuration and compliance data from multiple accounts and Regions into one view. Deploying the managed rules with StackSets ensures consistent evaluation across all 200 accounts, giving the compliance team a centralized dashboard that reflects each bucket's encryption and public access state.

  • ✗

    Use Amazon Macie in the compliance account to inventory all S3 buckets across the organization and report encryption status.

    Why it's wrong here

    Amazon Macie discovers sensitive data in S3 and can report bucket-level security settings, but it is a data discovery and classification service, not a configuration compliance engine. It does not evaluate custom rules or provide the authoritative compliance dashboard the team requires.

  • ✗

    Create an AWS Lambda function in each account that calls the S3 API and writes results to a central Amazon DynamoDB table.

    Why it's wrong here

    A custom Lambda and DynamoDB solution requires deploying and maintaining code in 200 accounts, handling cross-account write permissions, and building the dashboard from scratch. It duplicates functionality that AWS Config aggregators and managed rules already provide, increasing operational burden and risk of drift.

  • ✗

    Enable AWS Trusted Advisor in the management account and review the S3 bucket permissions checks for all accounts.

    Why it's wrong here

    Trusted Advisor checks run per account and, for organization-wide views, depend on Business or Enterprise Support and do not provide custom rule evaluation for encryption configuration. It cannot deliver the account-by-account compliance evidence or a consolidated dashboard for 200 accounts.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.