Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a single AWS account and wants to implement a multi-account strategy for better isolation. Which AWS service is designed to help centrally manage multiple accounts?

⚠ Common exam trap

Many exam-takers confuse AWS Control Tower (a managed landing zone service) with AWS Organizations (the underlying account management service), but Control Tower relies on Organizations and is not the service designed for direct central management of multiple accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations

AWS Organizations is the native AWS service designed to centrally manage multiple AWS accounts. It allows you to create a hierarchy of accounts with organizational units (OUs), apply service control policies (SCPs) for governance, and consolidate billing. This directly addresses the need for a multi-account strategy with centralized management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS IAM manages identities, roles and policies inside a single account; it cannot create accounts, apply organisational guardrails or consolidate billing across them. It would be correct for fine-grained permission control within one account, but the scenario requires cross-account governance that only AWS Organizations and Control Tower supply.

  • ✓

    AWS Organizations

    Why this is correct

    AWS Organizations provides central governance over multiple accounts through organisational units and service control policies, enabling consolidated billing and policy-based guardrails. It directly satisfies the stem's requirement for centrally managing multiple accounts, whereas IAM and Microsoft Entra ID govern identities within or across separate directories rather than provisioning AWS account structure itself.

  • ✗

    AWS Control Tower

    Why it's wrong here

    AWS Control Tower orchestrates governance across accounts created within an AWS Organizations landing zone, so it presupposes an existing organisation rather than being the service that establishes and centrally manages the multi-account structure itself. It is tempting because it genuinely centralises guardrails, account factory provisioning and compliance drift detection — the right answer when an organisation already exists and needs automated governance at scale.

  • ✗

    AWS Service Catalog

    Why it's wrong here

    AWS Service Catalog governs approved product portfolios and self-service provisioning within accounts; it holds no mechanism for creating accounts, applying baselines or aggregating billing. It would be the right choice when standardising deployable artefacts across teams, not when establishing the multi-account structure itself.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.