SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is designing a multi-account strategy using AWS Organizations. Which TWO benefits does this approach provide? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to confuse consolidated billing with direct cost reduction for EC2 instances, not realizing that aggregation only enables volume discounts and does not lower the per-instance price automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Centrally enforce policies using service control policies (SCPs).
Option A is correct because AWS Organizations lets you attach service control policies (SCPs) to the root, OUs, or individual member accounts, providing centralized permission guardrails that define the maximum available permissions for IAM principals in those accounts. Option D is correct because separate accounts create strong isolation boundaries: resources, IAM roles, and billing are distinct per account, which limits blast radius for security incidents and enables per-account cost tracking and budgets. Option B is not a built-in benefit of Organizations; VPC peering connections must be created and accepted manually (or via automation), and Organizations does not auto-create them. Option C is not provided by Organizations; RDS cross-region replication (e.g., cross-region read replicas) is configured per database and is unrelated to account structure. Option E is incorrect because EC2 usage is billed per account, and Organizations does not aggregate EC2 usage across accounts to reduce instance costs (though consolidated billing can aggregate volume discounts for some services, it does not reduce EC2 instance pricing in this manner).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Centrally enforce policies using service control policies (SCPs).
Why this is correct
SCPs attached to the root or OUs define the maximum permissions available to member accounts, letting the organisation apply guardrails once rather than replicating IAM policy in each account. This delivers the central governance benefit the multi-account design requires.
- ✗
Automatically create VPC peering connections between accounts.
Why it's wrong here
VPC peering connections must be created and accepted explicitly per pair of VPCs; Organizations does not automate them. It is tempting because centralised management sounds like it would connect networks, but peering is a networking task, whereas Organizations delivers consolidated billing and policy-based guardrails.
- ✗
Simplify cross-region replication for Amazon RDS databases.
Why it's wrong here
RDS cross-region replication is configured per database instance and is unaffected by account structure. It is tempting because Organizations centralises account management, but replication remains an RDS-level task; Organizations instead provides service control policies and centralised governance.
- ✓
Isolate workloads and provide a boundary for security and cost management.
Why this is correct
Separate accounts create hard blast-radius boundaries: IAM principals, service quotas and billing are scoped per account, so a compromise or runaway workload cannot reach other environments. This isolation underpins both the security and cost-management benefits sought.
- ✗
Reduce the total cost of EC2 instances by aggregating usage across accounts.
Why it's wrong here
Aggregated EC2 usage across accounts applies to Consolidated Billing discounts and Savings Plans sharing, not to the account-isolation and governance controls Organizations provides. It is tempting because billing consolidation is a genuine Organizations feature, but it is not the benefit described here.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.