SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has an AWS Organizations structure with a management account and 40 member accounts grouped into four OUs. The security team wants a single AWS account to receive all Amazon GuardDuty findings from every account and to view them in one place. They also need new accounts created under any OU to be automatically enrolled. Which solution meets these requirements with the LEAST operational overhead?
⚠ Common exam trap
The trap here is assuming GuardDuty detectors can be shared across accounts with AWS Resource Access Manager instead of using the built-in Organizations delegated administrator and auto-enable features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Designate a delegated administrator for GuardDuty in AWS Organizations and enable GuardDuty with auto-enable for all existing and new member accounts.
GuardDuty's native AWS Organizations integration is the intended mechanism for multi-account security monitoring. A delegated administrator account manages the service centrally, and auto-enable covers both existing accounts and accounts created later under any OU. This avoids building and maintaining per-account EventBridge and SNS forwarding pipelines while still delivering a consolidated findings view.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Designate a delegated administrator for GuardDuty in AWS Organizations and enable GuardDuty with auto-enable for all existing and new member accounts.
Why this is correct
GuardDuty integrates natively with AWS Organizations. Designating a delegated administrator lets that account manage GuardDuty across the organization, and auto-enable ensures every current and future member account is protected and its findings are aggregated in the delegated administrator account with no per-account scripting.
- ✗
Create an organization trail in AWS CloudTrail and use CloudTrail Lake to query GuardDuty findings across all accounts.
Why it's wrong here
CloudTrail records API activity, not GuardDuty threat findings, so a CloudTrail organization trail cannot aggregate GuardDuty detections. CloudTrail Lake queries event data stores built from CloudTrail events, so it would return API call history rather than the GuardDuty findings the security team needs in a single view.
- ✗
Enable GuardDuty in each member account and create an Amazon EventBridge rule in each account that forwards findings to a central Amazon SNS topic.
Why it's wrong here
This approach requires configuring EventBridge rules and cross-account SNS permissions in every existing account and in each new account, which is exactly the manual overhead the team wants to avoid. It also does not provide a native aggregated findings view, and new accounts would not be enrolled automatically without additional automation such as StackSets.
- ✗
Enable GuardDuty only in the management account and use AWS Resource Access Manager to share the detector with all member accounts.
Why it's wrong here
AWS Resource Access Manager does not share GuardDuty detectors; GuardDuty is not a shareable resource type. Enabling it solely in the management account also gives no visibility into member account activity, and the management account cannot act as a delegated administrator for GuardDuty while also being the organization's management account.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.