Courseiva
Design Solutions for Organizational ComplexityhardMultiple SelectObjective-mapped

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a multi-account AWS environment with a central security account. The security team wants to implement a solution that allows them to centrally manage and audit IAM permissions across all accounts. Which THREE services should be combined to achieve this?

⚠ Common exam trap

Candidates often confuse AWS Config's compliance evaluation with IAM permission management, but Config does not enforce or audit IAM permissions across accounts—it only checks resource configurations against rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Organizations

AWS Organizations is correct because it provides a centralized governance framework for managing multiple AWS accounts, enabling the security team to apply service control policies (SCPs) that centrally restrict IAM permissions across all member accounts. This allows the security account to enforce permission boundaries and audit IAM actions at the organizational level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Organizations

    Why this is correct

    Organizations provides a central view and management of all accounts.

  • AWS Config

    Why it's wrong here

    Config tracks resource configuration but does not audit IAM permissions.

  • AWS IAM Access Analyzer

    Why this is correct

    Access Analyzer helps identify resources shared with external entities.

  • AWS CloudTrail

    Why this is correct

    CloudTrail logs all IAM-related API calls for audit.

  • Amazon GuardDuty

    Why it's wrong here

    GuardDuty detects threats, not IAM permission audit.

About these practice questions

This SAP-C02 question is part of Courseiva's 1,660-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.