SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a central IT team that manages multiple AWS accounts. The team wants to allow developers to create resources in their own accounts but wants to restrict the use of certain expensive services like Amazon Redshift. The developers should not be able to launch Redshift clusters in any account. What is the MOST efficient way to achieve this?
⚠ Common exam trap
SAP-C02 often tests the difference between preventive controls (SCPs) and detective controls (CloudTrail, Config)—candidates pick monitoring or remediation options because they sound operationally safe, but the question asks for the most efficient way to prevent the action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an SCP that denies redshift:CreateCluster to the organizational unit containing the developer accounts.
Service Control Policies (SCPs) in AWS Organizations are the most efficient way to enforce guardrails across multiple accounts. Applying an SCP that denies redshift:CreateCluster to the organizational unit containing developer accounts prevents any principal in those accounts from launching Redshift clusters, regardless of their IAM permissions. This is a centralized, preventive control that scales across all accounts in the OU.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply an SCP that denies redshift:CreateCluster to the organizational unit containing the developer accounts.
Why this is correct
An SCP denying redshift:CreateCluster at the OU level applies to every principal in every member account, so developers cannot launch clusters regardless of their IAM permissions, meeting the organisation-wide restriction with one policy rather than per-account edits.
- ✗
Use AWS CloudTrail to monitor cluster creation and alert the security team.
Why it's wrong here
CloudTrail records API activity after the fact; it cannot block Redshift cluster creation, so developers could still launch clusters before any alert fires. CloudTrail suits auditing, compliance and forensic investigation. Preventing the action requires an SCP in AWS Organizations denying redshift:CreateCluster across accounts.
- ✗
Create an IAM policy that denies redshift:CreateCluster and attach it to the developers' IAM groups in each account.
Why it's wrong here
An IAM deny policy attached per account enforces the restriction, but must be replicated and maintained in every account, so new accounts can be missed. A service control policy in AWS Organizations denies redshift:CreateCluster centrally across all accounts, which is the efficient mechanism this option lacks.
- ✗
Use AWS Config rules to detect Redshift cluster creation and automatically delete them.
Why it's wrong here
AWS Config rules are detective, not preventive: they react after a Redshift cluster already exists, so developers can still launch one and incur cost before remediation runs. Config conformance packs suit auditing and compliance reporting across accounts, not blocking service usage at the API call.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.