SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company uses AWS Organizations and wants to centrally manage Amazon GuardDuty across all accounts. Which TWO steps are required to enable GuardDuty in all accounts from a single management account?
⚠ Common exam trap
A common mix-up: candidates confuse service control policies (SCPs) with proactive enforcement, but SCPs only restrict permissions and cannot automatically enable a service; they also overlook that CloudFormation StackSets cannot enable a service like GuardDuty, which requires a specific API action rather than resource deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the GuardDuty delegated administrator account to enable GuardDuty for all accounts in the organization
The correct answers are E and D. First, you must designate a member account as the GuardDuty delegated administrator (option E) using the Organizations management account, which grants that account administrative authority over GuardDuty for the entire organization. Then, from that delegated administrator account, you enable GuardDuty for all accounts in the organization (option D), which automatically enables GuardDuty in every existing and newly added member account. Option A is incorrect because CloudFormation StackSets is not the mechanism GuardDuty uses for organization-wide enablement. Option B is incorrect because manual per-account enablement defeats the purpose of centralized management. Option C is incorrect because service control policies restrict permissions and cannot force a service like GuardDuty to be enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudFormation StackSets to deploy GuardDuty in each account
Why it's wrong here
StackSets deploys resources per account but does not use the Organizations-integrated delegated administrator mechanism that enables GuardDuty centrally from the management account. StackSets suit standardised multi-account resource rollouts, so it appears plausible, yet GuardDuty's own central management feature is the required route.
- ✗
Enable GuardDuty manually in each member account by logging into each account
Why it's wrong here
Logging into each member account defeats the requirement to manage GuardDuty centrally from a single management account. It is tempting because per-account enablement works in organisations without delegated administration, and it would be correct only where centralised administration is unavailable or explicitly not wanted.
- ✗
Create a service control policy to force GuardDuty to be enabled
Why it's wrong here
Service control policies only set permission guardrails in AWS Organizations; they cannot enable or configure GuardDuty, which requires delegated administrator registration and auto-enable settings. SCPs are tempting because they enforce organisational policy centrally, and would be correct for restricting services or actions across accounts.
- ✓
Use the GuardDuty delegated administrator account to enable GuardDuty for all accounts in the organization
Why this is correct
Designating a delegated administrator in GuardDuty lets that account enable and manage the service across every member account via AWS Organizations integration, satisfying the centralised single-account management constraint. The management account itself cannot serve as the GuardDuty delegated administrator, so a member account must be registered first.
- ✓
Designate a member account as the GuardDuty delegated administrator
Why this is correct
GuardDuty's delegated administrator model requires one member account to be designated, granting it administrative authority over all other accounts in the organization. This satisfies the requirement to manage GuardDuty centrally from a single account rather than configuring each member individually.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.