SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is designing a multi-account strategy for its AWS environment. Which TWO considerations are important when using AWS Organizations?
⚠ Common exam trap
Test-takers frequently assume SCPs apply to all accounts including the management account, but AWS explicitly excludes the management account from SCP effects to prevent accidental lockout of administrative access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail can be enabled for all accounts from the management account using an organization trail.
Option B is correct because AWS Organizations lets the management account create an organization trail in AWS CloudTrail that automatically applies to all member accounts, providing centralized logging of API activity across the organization. Option D is correct because consolidated billing aggregates usage from all member accounts into a single bill paid by the management account, and this combined usage can qualify for volume pricing discounts on services like S3 and data transfer. Option A is incorrect because SCPs do not apply to the management account; they only affect member accounts (and the management account is exempt to prevent lockout). Option C is incorrect because AWS Organizations uses consolidated billing, so member accounts do not each need their own payment method—the management account pays the single bill. Option E is incorrect because AWS Config supports organization-wide rules and conformance packs deployed from the management account across member accounts via AWS Organizations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service control policies (SCPs) apply to all accounts in the organization, including the management account.
Why it's wrong here
SCPs do not apply to the management account; they affect only member accounts, so the stated scope is wrong. It is tempting because SCPs are attached at the organization root or OU and inherit downwards, which is exactly how you would restrict member accounts while leaving the management account unrestricted.
- ✓
AWS CloudTrail can be enabled for all accounts from the management account using an organization trail.
Why this is correct
An organisation trail created in the management account automatically applies to every member account, including accounts added later, and delivers events to a central bucket. This satisfies the multi-account consideration that activity logging be consistent and centrally governed rather than configured per account.
- ✗
Each account in an organization must have its own payment method.
Why it's wrong here
AWS Organizations consolidates billing so all member accounts draw on the management account's single payment method; separate payment methods are unnecessary. It is tempting because standalone AWS accounts each require their own payment instrument, which is the situation before those accounts are invited into an organization.
- ✓
Consolidated billing allows you to combine usage and receive volume discounts.
Why this is correct
Consolidated billing aggregates usage across all member accounts into a single payer, so consumption combines before tiered pricing thresholds are applied. This satisfies the multi-account consideration that volume discounts and reserved instance sharing are realised across the whole organisation rather than per isolated account.
- ✗
AWS Config rules cannot be applied across accounts via AWS Organizations.
Why it's wrong here
AWS Config supports an aggregator that collects configuration and compliance data across every account in an organization, so cross-account evaluation is achievable. The option is tempting because Config rules are created per account and per Region, which matters only when no aggregator or delegated administrator is configured.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.