SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a decentralized IT structure where each business unit manages its own AWS accounts. The central IT team wants to enforce security policies across all accounts but allow business units to retain administrative control. Which solution should the central IT team implement?
⚠ Common exam trap
Test-takers frequently confuse SCPs with IAM policies, thinking SCPs remove all administrative control, when in fact SCPs only set upper permission boundaries and allow business units to retain full administrative autonomy within those limits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Organizations with service control policies (SCPs) to enforce baseline permissions, and delegate administration to organizational units (OUs) for each business unit.
AWS Organizations with SCPs allows the central IT team to enforce baseline security policies across all accounts without removing administrative control from business units. By delegating administration to OUs for each business unit, the central team sets guardrails while business units retain full IAM management within their accounts, satisfying the decentralized structure requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy AWS CloudFormation StackSets to each account with security templates.
Why it's wrong here
CloudFormation StackSets deploy templates but do not provide ongoing preventive policy enforcement across accounts. They are tempting for standardised provisioning, yet they would be correct for rolling out baseline resources, not for continuously enforcing security policies while business units retain administrative control.
- ✗
Create a shared services account and use IAM cross-account roles for each business unit.
Why it's wrong here
Cross-account IAM roles grant access between accounts but do not enforce central security policies across all of them. They are tempting for centralised access management, yet they would be correct only when the requirement is shared resource access, not policy enforcement with retained business-unit control.
- ✓
Use AWS Organizations with service control policies (SCPs) to enforce baseline permissions, and delegate administration to organizational units (OUs) for each business unit.
Why this is correct
AWS Organizations SCPs set permission guardrails at the organisation root or OU level, capping the maximum permissions available to every principal in member accounts. Delegating each business unit to its own OU preserves their administrative autonomy within those guardrails, satisfying central enforcement without removing local control.
- ✗
Migrate all workloads to a single AWS account and use IAM roles for each business unit.
Why it's wrong here
Consolidating into one account removes the business units' administrative control and contradicts the decentralised structure. It is tempting as a way to centralise governance, but it would be correct only if the company wanted to abandon account separation entirely, not enforce policies across existing accounts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.