SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is expanding its AWS Organizations environment to include several new business units. The security team must ensure that all new accounts automatically have a baseline security configuration, including a VPC with specific flow logs enabled, an AWS Config recorder, and a set of IAM roles for cross-account access. They want to minimize manual effort and ensure consistency. Which two solutions should they use to achieve these goals? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse services that assess compliance (Config conformance packs) or require manual provisioning (Service Catalog) with those that automatically deploy and enforce baseline configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Control Tower to set up a landing zone and apply mandatory guardrails to new accounts.
AWS Control Tower automates the setup of a secure landing zone with preconfigured baselines and guardrails, while CloudFormation StackSets deploy resource templates across accounts and automatically target new accounts. Together, they provide automated, consistent baseline security configurations with minimal manual effort, meeting the requirements for VPC flow logs, Config recorders, and IAM roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Systems Manager Automation to run a runbook that configures each new account after creation.
Why it's wrong here
AWS Systems Manager Automation can execute runbooks to configure resources, but it must be triggered manually or via events. It does not natively integrate with AWS Organizations to automatically apply configurations to new accounts. Building and maintaining custom runbooks for baseline security adds operational overhead and is less consistent than using purpose-built services.
- ✓
Use AWS Control Tower to set up a landing zone and apply mandatory guardrails to new accounts.
Why this is correct
AWS Control Tower provides a landing zone with preconfigured blueprints, including VPCs with flow logs, AWS Config recorders, and IAM roles for cross-account access. It automates account provisioning and applies guardrails to ensure compliance. This reduces manual effort and ensures consistency across new accounts, directly meeting the baseline security requirements.
- ✓
Use AWS CloudFormation StackSets to deploy a baseline template to all accounts in the organization.
Why this is correct
AWS CloudFormation StackSets allow you to deploy a common set of resources, such as VPCs, flow logs, Config recorders, and IAM roles, across multiple accounts and Regions with a single operation. It can automatically deploy to new accounts when they are added to the organization, ensuring consistency and minimizing manual effort.
- ✗
Use AWS Service Catalog to create a portfolio of baseline products and share it with all accounts.
Why it's wrong here
AWS Service Catalog allows users to provision approved products, but it does not automatically deploy resources to new accounts. Users must manually launch products from the portfolio. This does not meet the requirement for automatic baseline configuration with minimal manual effort, as it relies on user action and lacks central enforcement.
- ✗
Use AWS Config conformance packs to deploy baseline configurations across all accounts.
Why it's wrong here
AWS Config conformance packs are used to assess compliance of existing resources against a set of Config rules. They do not deploy resources or enforce configurations. They can detect non-compliance but cannot create VPCs, flow logs, or IAM roles. Therefore, they do not meet the requirement to automatically establish a baseline security configuration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.