SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a multi-account AWS environment with AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that only the audit account can assume these roles and that the roles are automatically created in all existing and future accounts. What should they do?
⚠ Common exam trap
The trap here is assuming that AWS Resource Access Manager can share IAM roles, but RAM does not support IAM roles as shareable resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack set that creates the IAM roles in all accounts in the organization.
CloudFormation StackSets with service-managed permissions is designed to deploy resources across all accounts in an AWS Organization, including automatically to new accounts when auto-deployment is enabled. By defining a stack set that creates IAM roles with trust policies restricted to the audit account, the security team can centrally manage and automatically provision these roles. This is the most efficient and native solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Organizations to create a service control policy (SCP) that allows sts:AssumeRole only from the audit account, and manually create the roles in each account.
Why it's wrong here
SCPs can restrict sts:AssumeRole, but they cannot create IAM roles. Manually creating roles in each account does not scale and does not automatically cover future accounts. This approach requires ongoing manual effort and does not meet the requirement for automatic provisioning. SCPs are for permissions boundaries, not resource creation.
- ✗
Use AWS Identity and Access Management (IAM) to create a role in each account with a trust policy that allows the audit account, and use AWS Lambda to create the roles in new accounts as they are added.
Why it's wrong here
This approach requires custom Lambda automation to detect new accounts and create roles, which adds operational overhead and potential for failure. While it can work, it is not the most efficient or native solution. CloudFormation StackSets with service-managed permissions is the AWS-recommended way to deploy resources across an organization automatically.
- ✓
Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack set that creates the IAM roles in all accounts in the organization.
Why this is correct
CloudFormation StackSets with service-managed permissions can automatically deploy stack instances to all accounts in an organization, including future accounts when auto-deployment is enabled. The stack set can create IAM roles with trust policies that allow only the audit account to assume them. This meets the requirements for central management and automatic provisioning.
- ✗
Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share it with all member accounts.
Why it's wrong here
AWS RAM does not support sharing IAM roles. IAM roles are not shareable resources via RAM. Cross-account access to IAM roles is achieved through trust policies and sts:AssumeRole, not RAM. This solution is technically invalid and does not meet the requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.