Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company uses AWS Organizations and wants to allow certain accounts to use AWS Service Catalog for self-service provisioning. The IT team needs to control which products are available. Where should the product portfolio be shared?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Service Catalog portfolio sharing with other cross-account mechanisms like CloudFormation StackSets or IAM roles, failing to recognize that Service Catalog's native sharing via RAM is the correct way to control product availability for self-service provisioning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Share the portfolio with the target accounts from the Service Catalog console

AWS Service Catalog allows you to share a product portfolio directly with individual AWS accounts or organizational units (OUs) within AWS Organizations. By sharing the portfolio from the Service Catalog console, the IT team can control which products are available to specific accounts, enabling self-service provisioning while maintaining governance. This approach leverages Service Catalog's native portfolio sharing mechanism, which does not require additional infrastructure or cross-account IAM roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Share the portfolio with the target accounts from the Service Catalog console

    Why this is correct

    Sharing the portfolio from the Service Catalog console uses AWS RAM to grant target accounts access to the exact products selected. This satisfies the IT team's need to control which products each account can self-provision.

  • ✗

    Use AWS CloudFormation StackSets to deploy products to each account

    Why it's wrong here

    StackSets deploy CloudFormation templates across accounts; they do not share a Service Catalog portfolio, so product governance is bypassed. It is tempting because StackSets handle multi-account rollout, and would be correct for deploying baseline infrastructure, not for controlling which products accounts may provision.

  • ✗

    Use SCPs to allow specific accounts to use Service Catalog

    Why it's wrong here

    SCPs only set the maximum permissions boundary for accounts; they cannot share a Service Catalog portfolio, which requires portfolio sharing from the management account to specific accounts or OUs. SCPs are tempting because they govern account-level access, and would be right for restricting which AWS services or actions accounts may use.

  • ✗

    Create IAM roles in the central account that developers can assume

    Why it's wrong here

    IAM roles grant access to AWS APIs; they do not share a Service Catalog portfolio, so accounts still cannot provision the controlled products. It is tempting because cross-account roles are common for centralised access, and would be correct for delegating API permissions rather than portfolio distribution.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.