SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is designing a multi-account strategy using AWS Organizations. The security team requires that all API calls to create or modify IAM roles are logged and alerted. Which TWO steps should be taken to meet this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Config (which records configuration changes) with CloudTrail (which records API calls), leading them to select Option A instead of the correct combination of CloudTrail and CloudWatch Logs metric filters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch Logs metric filter and alarm to detect IAM role creation/modification events.
Option D is correct because CloudTrail management events capture IAM API calls such as CreateRole, UpdateRole, and PutRolePolicy, and integrating CloudTrail with CloudWatch Logs in every account (or via an organization trail) delivers those events to a central place for monitoring. Option B is correct because a CloudWatch Logs metric filter matches patterns for IAM role creation/modification events in the delivered CloudTrail logs, and an associated CloudWatch alarm triggers the required alerting. Together, D provides the logging pipeline and B provides detection and alerting. Option A is not appropriate because AWS Config records resource configuration changes and compliance, not the API call events needed for real-time alerting on IAM role creation/modification. Option C is wrong because an SCP that denies IAM role creation/modification would block the activity rather than log and alert on it. Option E is wrong because IAM Access Analyzer identifies resource access and permissions issues, not API call logging or alerting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config to record IAM role changes and stream to CloudWatch Logs.
Why it's wrong here
AWS Config records resource configuration changes, including IAM roles, and can stream them to CloudWatch Logs, but the requirement is logging and alerting on API calls, which CloudTrail captures. Config is tempting because it tracks IAM role state over time, the right choice for compliance auditing of configuration drift.
- ✓
Create a CloudWatch Logs metric filter and alarm to detect IAM role creation/modification events.
Why this is correct
CloudTrail delivers IAM role creation and modification events to CloudWatch Logs, where a metric filter matches the specific API calls (CreateRole, UpdateAssumeRolePolicy, AttachRolePolicy). The alarm then alerts the security team, satisfying the requirement to both log and alert on these events across the organisation's accounts.
- ✗
Create an SCP that denies IAM role creation and modification.
Why it's wrong here
An SCP denying IAM role creation and modification blocks the API calls entirely, so nothing is logged or alerted — it prevents rather than detects. SCPs are tempting because they enforce guardrails across every account in the organisation, which is the right use when the goal is prevention, not monitoring.
- ✓
Enable CloudTrail management events with CloudWatch Logs integration in all accounts.
Why this is correct
CloudTrail management events capture IAM role creation and modification API calls, satisfying the logging requirement across every account. Streaming them to CloudWatch Logs enables metric filters and alarms, delivering the alerting half of the requirement. Without this integration, events remain in CloudTrail only, so no automated alert fires.
- ✗
Enable IAM Access Analyzer to monitor IAM role usage.
Why it's wrong here
IAM Access Analyzer identifies resources shared with external entities and unused permissions; it does not record or alert on IAM role creation and modification API calls. It is tempting because it analyses IAM policy risk, which suits reviewing existing permissions rather than detecting configuration-change events.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.