Courseiva

Enforcing Standard VPC CIDR and Subnet Configurations Across AWS Accounts

A company is using AWS Organizations with hundreds of accounts. The central IT team needs to deploy a common set of AWS resources (e.g., VPCs, subnets, security groups) to all accounts in a specific organizational unit (OU). The solution must be automated and ensure that new accounts added to the OU automatically receive the resources. Which three steps should the team take? (Choose three.)

⚠ Common exam trap

Many exam-takers confuse AWS Config (a detective control) with a provisioning tool, and assuming SCPs can create resources when they only enforce permission boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a StackSet with the template and target the OU, enabling automatic deployment.

Option B is correct because the common resources (VPCs, subnets, security groups) must first be codified in an AWS CloudFormation template, which serves as the reusable artifact for automated, consistent deployment across accounts. Option D is correct because CloudFormation StackSets must be granted trusted access with AWS Organizations so the management account can deploy stack instances into member accounts and target OUs directly. Option A is correct because creating a StackSet from that template and targeting the specific OU with automatic deployment enabled ensures existing accounts receive the resources and any new account added to the OU is provisioned automatically. Option C is incorrect because AWS Config rules only detect and evaluate resource compliance; they do not natively deploy resources, and using Lambda for remediation is a custom, reactive approach rather than the automated StackSet mechanism required. Option E is incorrect because an SCP only sets permission guardrails (allowing or denying actions); it cannot create or require the actual provisioning of VPCs, subnets, or security groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a StackSet with the template and target the OU, enabling automatic deployment.

    Why this is correct

    StackSets deploy a CloudFormation template across many accounts in one operation, and targeting the OU with automatic deployment enabled means any account later added to that OU inherits the resources without manual intervention, satisfying the automation constraint.

  • ✓

    Create an AWS CloudFormation template that defines the common resources.

    Why this is correct

    AWS CloudFormation templates provide the declarative resource definitions that StackSets deploy across accounts. This satisfies the automation requirement, since the same template applied to every account in the OU guarantees identical VPCs, subnets and security groups, and new accounts joining the OU inherit them automatically.

  • ✗

    Use AWS Config rules to detect missing resources and deploy them via Lambda.

    Why it's wrong here

    This is a custom solution, not as automated as StackSets.

  • ✓

    Enable AWS CloudFormation StackSets trusted access with AWS Organizations.

    Why this is correct

    Enabling trusted access lets StackSets create, update and delete stack instances across every account in the target OU without manual per-account role assumption. This satisfies the automation requirement and, combined with automatic deployment, ensures accounts joining the OU later inherit the common VPC, subnet and security group resources.

  • ✗

    Create an SCP that requires the creation of those resources.

    Why it's wrong here

    SCPs cannot create resources.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.