Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a multi-account AWS environment managed by AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. The roles must be automatically created in all existing and future accounts, and any changes to the roles must be applied consistently. Which solution meets these requirements with the LEAST administrative effort?

⚠ Common exam trap

The trap here is thinking that SCPs can create resources, but they only define permissions boundaries and cannot provision IAM roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack that creates the IAM roles to all accounts in the organization.

AWS CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to automatically deploy stacks to all accounts, including new ones. This enables centralized creation and updates of IAM roles across the organization without manual intervention. It provides consistency and reduces administrative effort, making it the ideal solution for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Organizations service control policies (SCPs) to enforce the creation of IAM roles with specific permissions in all accounts.

    Why it's wrong here

    SCPs are used to set permission guardrails, not to create IAM roles. They can restrict what actions are allowed but cannot provision resources. SCPs alone cannot automatically create roles in all accounts, so this does not meet the requirement for centralized role creation and management.

  • ✗

    Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share the role with all member accounts.

    Why it's wrong here

    AWS RAM is used to share resources like subnets, transit gateways, and Route 53 resolver rules, not IAM roles. IAM roles cannot be shared via RAM. Cross-account access is typically granted by creating roles in each account and allowing principals from other accounts to assume them, which requires per-account setup.

  • ✗

    Develop a script using the AWS CLI that iterates over all accounts and creates the IAM roles, and schedule it to run regularly to catch new accounts.

    Why it's wrong here

    A custom script requires ongoing maintenance, credentials management, and does not automatically handle new accounts unless scheduled and updated. It introduces operational overhead and potential for drift. This is not the least-effort solution compared to a managed service like StackSets.

  • ✓

    Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack that creates the IAM roles to all accounts in the organization.

    Why this is correct

    AWS CloudFormation StackSets with service-managed permissions can deploy stacks to all accounts in an organization, including automatically to new accounts as they are added. This allows centralized management of IAM roles, and any updates to the stack set are rolled out to all accounts, ensuring consistency with minimal effort.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.