SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a large AWS Organizations environment with 200 accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that the roles are deployed to all existing and future accounts, and that any changes to the roles are automatically propagated. Which solution should they use?
⚠ Common exam trap
The trap here is thinking that AWS RAM can share IAM roles, but RAM only supports a specific set of resource types and does not include IAM roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation StackSets with service-managed permissions to deploy the IAM roles to all accounts in the organization, and enable automatic deployment.
CloudFormation StackSets with service-managed permissions is the AWS-native way to deploy IAM roles across an organization. It automatically targets accounts in specified OUs and can be configured to deploy to new accounts as they are added. StackSet updates are rolled out to all stack instances, ensuring consistency. This approach centralizes management and reduces operational overhead compared to manual or scripted methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Write a script using AWS CLI that iterates over all accounts and creates the IAM roles, and schedule it to run periodically to update roles.
Why it's wrong here
A custom script requires managing credentials, handling errors, and scheduling, which adds operational overhead. It also does not automatically cover new accounts unless the script is updated, and it lacks the built-in drift detection and rollback features of CloudFormation StackSets.
- ✗
Use AWS Resource Access Manager (RAM) to share the IAM roles from the central security account to all member accounts.
Why it's wrong here
AWS RAM does not support sharing IAM roles. It is designed for sharing resources like VPC subnets, transit gateways, and Route 53 Resolver rules. IAM roles cannot be shared via RAM; cross-account access is achieved through trust policies and assuming roles.
- ✓
Use AWS CloudFormation StackSets with service-managed permissions to deploy the IAM roles to all accounts in the organization, and enable automatic deployment.
Why this is correct
CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to deploy stacks to all accounts. Enabling automatic deployment ensures that new accounts automatically receive the IAM roles, and updates to the stack are propagated to all accounts, meeting the requirements with minimal effort.
- ✗
Create an IAM role in the management account and use AWS Single Sign-On (SSO) to grant access to the central security account.
Why it's wrong here
AWS SSO (now IAM Identity Center) manages user access to accounts and applications, but it does not deploy IAM roles for cross-account access between accounts. It is used for federated access, not for creating and managing roles in member accounts for service-to-service or cross-account access.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.