Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company is designing a multi-account strategy using AWS Organizations. Which TWO benefits does this approach provide? (Choose TWO.)

⚠ Common exam trap

It's easy for candidates to confuse consolidated billing with direct cost reduction for EC2 instances, not realizing that aggregation only enables volume discounts and does not lower the per-instance price automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Centrally enforce policies using service control policies (SCPs).

Option A is correct because AWS Organizations lets you attach service control policies (SCPs) to the root, OUs, or individual member accounts, providing centralized permission guardrails that define the maximum available permissions for IAM principals in those accounts. Option D is correct because separate accounts create strong isolation boundaries: resources, IAM roles, and billing are distinct per account, which limits blast radius for security incidents and enables per-account cost tracking and budgets. Option B is not a built-in benefit of Organizations; VPC peering connections must be created and accepted manually (or via automation), and Organizations does not auto-create them. Option C is not provided by Organizations; RDS cross-region replication (e.g., cross-region read replicas) is configured per database and is unrelated to account structure. Option E is incorrect because EC2 usage is billed per account, and Organizations does not aggregate EC2 usage across accounts to reduce instance costs (though consolidated billing can aggregate volume discounts for some services, it does not reduce EC2 instance pricing in this manner).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Centrally enforce policies using service control policies (SCPs).

    Why this is correct

    SCPs attached to the root or OUs define the maximum permissions available to member accounts, letting the organisation apply guardrails once rather than replicating IAM policy in each account. This delivers the central governance benefit the multi-account design requires.

  • ✗

    Automatically create VPC peering connections between accounts.

    Why it's wrong here

    VPC peering connections must be created and accepted explicitly per pair of VPCs; Organizations does not automate them. It is tempting because centralised management sounds like it would connect networks, but peering is a networking task, whereas Organizations delivers consolidated billing and policy-based guardrails.

  • ✗

    Simplify cross-region replication for Amazon RDS databases.

    Why it's wrong here

    RDS cross-region replication is configured per database instance and is unaffected by account structure. It is tempting because Organizations centralises account management, but replication remains an RDS-level task; Organizations instead provides service control policies and centralised governance.

  • ✓

    Isolate workloads and provide a boundary for security and cost management.

    Why this is correct

    Separate accounts create hard blast-radius boundaries: IAM principals, service quotas and billing are scoped per account, so a compromise or runaway workload cannot reach other environments. This isolation underpins both the security and cost-management benefits sought.

  • ✗

    Reduce the total cost of EC2 instances by aggregating usage across accounts.

    Why it's wrong here

    Aggregated EC2 usage across accounts applies to Consolidated Billing discounts and Savings Plans sharing, not to the account-isolation and governance controls Organizations provides. It is tempting because billing consolidation is a genuine Organizations feature, but it is not the benefit described here.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.