SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is designing a multi-account AWS Organizations architecture. Which TWO considerations should be taken into account when designing the organizational structure?
⚠ Common exam trap
Candidates often confuse SCPs with IAM policies, thinking SCPs can only be applied to the root account, when in fact they can be attached to any OU or account within the organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail can be configured to log management events across all accounts from the management account.
Option C is correct because AWS CloudTrail supports organization trails: when created in the management account (or a delegated administrator) with the organization setting enabled, it automatically logs management events for all member accounts and delivers them to a central S3 bucket. Option D is correct because service control policies (SCPs) are a core AWS Organizations feature that let you centrally set permission guardrails (allow lists or deny lists) that apply to all IAM principals in the accounts attached to the OU or root, restricting what member accounts can do. Option A is wrong because accounts can be moved between OUs at any time (though each account can belong to only one OU at a time). Option B is wrong because OUs are meant to group multiple accounts with similar policy needs, and isolation is achieved through separate accounts and SCPs, not by limiting an OU to a single account. Option E is wrong because SCPs can be attached to the organization root, OUs, and individual member accounts — not only to root accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accounts cannot be moved between OUs once created.
Why it's wrong here
Accounts can be moved between OUs.
- ✗
Each organizational unit (OU) should contain only one account for security isolation.
Why it's wrong here
OUs can contain multiple accounts; isolation is achieved via SCPs.
- ✓
AWS CloudTrail can be configured to log management events across all accounts from the management account.
Why this is correct
CloudTrail organisation trails let the management account aggregate management events from every member account into one destination bucket, satisfying the centralised auditing constraint of a multi-account structure. This removes per-account trail configuration and preserves a single immutable log archive, which is essential when accounts are created and removed dynamically.
- ✓
Service control policies (SCPs) can be used to centrally restrict permissions across accounts.
Why this is correct
SCPs attach to organizational units or accounts and define the maximum available permissions, so a single policy edit centrally caps what any principal in member accounts can do. This directly satisfies the multi-account governance constraint, restricting permissions across accounts without per-account IAM rework.
- ✗
SCPs can only be applied to root accounts, not OUs.
Why it's wrong here
SCPs can be applied to OUs and individual accounts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.