SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is using AWS Control Tower to manage a multi-account environment. The security team needs to ensure that all accounts have a specific AWS Config rule enabled and that any drift is automatically remediated. Which approach should be used?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Config conformance packs with enforcement mechanisms, assuming SCPs can mandate Config rules, when in fact SCPs only restrict permissions and cannot enforce the presence of specific AWS services or configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Control Tower lifecycle events and customizations to deploy the Config rule and set up automatic remediation.
AWS Control Tower provides lifecycle events and customizations (via AWS Control Tower Lifecycle Events and Customizations for AWS Control Tower) that allow you to automatically deploy and remediate AWS Config rules across all accounts in the organization. This approach ensures that the Config rule is applied consistently when new accounts are created or when drift is detected, meeting the security team's requirement for automatic remediation without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use EC2 Auto Scaling to apply the Config rule to all accounts.
Why it's wrong here
EC2 Auto Scaling is for compute resources, not Config rules.
- ✓
Use AWS Control Tower lifecycle events and customizations to deploy the Config rule and set up automatic remediation.
Why this is correct
Control Tower provides governance and drift detection.
- ✗
Use AWS CloudTrail to monitor for accounts without the Config rule and trigger a Lambda function to add it.
Why it's wrong here
CloudTrail logs API calls; it does not monitor Config rule status.
- ✗
Use AWS Config to create a conformance pack that applies the rule, and use an SCP to require it.
Why it's wrong here
SCPs cannot enforce Config rules.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 1,660-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.