SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has 200 AWS accounts in AWS Organizations. The compliance team needs to prove that all Amazon S3 buckets across every account have server-side encryption enabled and block public access, and they want a single dashboard showing compliance status. Which solution should they implement?
⚠ Common exam trap
The trap here is substituting a data-classification service such as Amazon Macie, or a custom Lambda pipeline, for the configuration compliance capability that AWS Config aggregators provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS Config in each account with an aggregator in the compliance account and deploy managed rules for S3 encryption and public access using AWS CloudFormation StackSets.
AWS Config aggregators consolidate configuration and compliance data from all accounts and Regions into an administrator account, and managed rules can evaluate S3 encryption and public access settings. Using CloudFormation StackSets to deploy the rules ensures uniform coverage across 200 accounts, and the aggregator supplies the single compliance dashboard the team needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable AWS Config in each account with an aggregator in the compliance account and deploy managed rules for S3 encryption and public access using AWS CloudFormation StackSets.
Why this is correct
AWS Config aggregators collect configuration and compliance data from multiple accounts and Regions into one view. Deploying the managed rules with StackSets ensures consistent evaluation across all 200 accounts, giving the compliance team a centralized dashboard that reflects each bucket's encryption and public access state.
- ✗
Use Amazon Macie in the compliance account to inventory all S3 buckets across the organization and report encryption status.
Why it's wrong here
Amazon Macie discovers sensitive data in S3 and can report bucket-level security settings, but it is a data discovery and classification service, not a configuration compliance engine. It does not evaluate custom rules or provide the authoritative compliance dashboard the team requires.
- ✗
Create an AWS Lambda function in each account that calls the S3 API and writes results to a central Amazon DynamoDB table.
Why it's wrong here
A custom Lambda and DynamoDB solution requires deploying and maintaining code in 200 accounts, handling cross-account write permissions, and building the dashboard from scratch. It duplicates functionality that AWS Config aggregators and managed rules already provide, increasing operational burden and risk of drift.
- ✗
Enable AWS Trusted Advisor in the management account and review the S3 bucket permissions checks for all accounts.
Why it's wrong here
Trusted Advisor checks run per account and, for organization-wide views, depend on Business or Enterprise Support and do not provide custom rule evaluation for encryption configuration. It cannot deliver the account-by-account compliance evidence or a consolidated dashboard for 200 accounts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.