SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company uses AWS Organizations and wants to delegate administration of a specific service to a member account. The service must be able to perform actions across all accounts in the organization. Which steps should the company take?
⚠ Common exam trap
A common mix-up: candidates confuse delegated administration with creating cross-account IAM roles or using the OrganizationAccountAccessRole, not realizing that AWS Organizations provides a native, centralized registration mechanism for service-level delegation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Organizations to register the member account as a delegated administrator for the service.
AWS Organizations allows you to designate a member account as a delegated administrator for a specific AWS service. Once registered, that account can perform administrative actions (e.g., creating resources, managing policies) across all accounts in the organization on behalf of that service, without needing individual IAM roles or permissions in each account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS Organizations to register the member account as a delegated administrator for the service.
Why this is correct
Registering a member account as a delegated administrator via AWS Organizations grants that account's service the permissions to operate across every account in the organization, satisfying the cross-account requirement without sharing root credentials or building custom IAM roles.
- ✗
Create a service-linked role in each account to allow the service to perform actions.
Why it's wrong here
Service-linked roles are created automatically by the service in each account and cannot be used to delegate cross-account administration. They are tempting because they grant a service permissions in its own account, which is the right pattern for enabling a service, not for organisation-wide delegated admin.
- ✗
Grant the member account IAM permissions to assume the OrganizationAccountAccessRole in all accounts.
Why it's wrong here
OrganizationAccountAccessRole grants the management account administrative access to member accounts; it does not register a member account as the delegated administrator for a service. Assuming it is tempting for cross-account access, but delegated administration requires registering the account via AWS Organizations.
- ✗
Create an IAM role in each account with a trust policy that allows the service to assume it.
Why it's wrong here
Manually creating trust roles in every account does not register a delegated administrator, and the service cannot assume roles across the organisation this way. It is tempting because custom roles grant cross-account access, but AWS Organizations delegated administration uses service-specific registration instead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.