Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account for incident response. They need to ensure that the roles can be assumed only by specific IAM principals in the security account and that the permissions are consistent across all member accounts. Which approach meets these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is assuming that SCPs can restrict which principals can assume an IAM role, when they actually only limit permissions for principals within the account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CloudFormation StackSets to deploy a standardized IAM role in each member account with a trust policy that allows assumption by the security account's incident response role, and manage updates centrally.

CloudFormation StackSets provide a centralized, scalable way to deploy and update IAM roles across multiple accounts with consistent trust policies. This ensures only the specified security account principal can assume the roles, and updates are managed from a single place, minimizing operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS IAM Identity Center (successor to AWS Single Sign-On) to create a permission set that grants access to the security account, and assign it to all member accounts.

    Why it's wrong here

    IAM Identity Center permission sets grant access to users to AWS accounts, but they do not create cross-account IAM roles that can be assumed by a specific principal in the security account for incident response. The requirement is for a role in member accounts that the security account can assume, which is not directly addressed by permission sets.

  • ✓

    Use AWS CloudFormation StackSets to deploy a standardized IAM role in each member account with a trust policy that allows assumption by the security account's incident response role, and manage updates centrally.

    Why this is correct

    CloudFormation StackSets allow you to deploy and update IAM roles across all member accounts from a central location. The trust policy can specify the exact security account principal, ensuring only that principal can assume the role. This provides consistency and minimal operational overhead because updates are applied automatically to all accounts.

  • ✗

    Implement a custom AWS Lambda function that uses the AWS SDK to create the IAM role in each member account upon a scheduled trigger.

    Why it's wrong here

    A custom Lambda solution requires development, deployment, and maintenance of code, increasing operational overhead. It may not handle error cases or updates as reliably as StackSets. While it could work, it is not the least operational overhead solution compared to a managed service like CloudFormation StackSets.

  • ✗

    Create an IAM role in each member account manually and use AWS Organizations SCPs to enforce that only the security account can assume it.

    Why it's wrong here

    SCPs do not control which principals can assume a role; they only define the maximum permissions for principals in the account. Manual creation in each account is error-prone and does not scale. This approach does not ensure consistency and requires significant operational effort to maintain across many accounts.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.