Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users are created in member accounts. All access must be through federated roles. Which approach should they use?

⚠ Common exam trap

Test-takers frequently confuse detective controls (like AWS Config or CloudTrail) with preventive controls (like SCPs), assuming that monitoring or alerting can effectively enforce a policy, whereas only SCPs can proactively block the action across all accounts in an organization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an SCP to the root OU that denies the iam:CreateUser action.

Service Control Policies (SCPs) in AWS Organizations allow the security team to centrally restrict permissions across all member accounts. By applying an SCP to the root organizational unit (OU) that denies the `iam:CreateUser` action, no IAM users can be created in any member account, ensuring all access must come from federated roles. SCPs are evaluated before IAM policies and cannot be overridden by account administrators, making them the most effective preventive control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply an SCP to the root OU that denies the iam:CreateUser action.

    Why this is correct

    An SCP attached at the root OU is inherited by every member account and denies iam:CreateUser at the API level, regardless of identity-based policies. This enforces federated-only access across the organisation, satisfying the requirement that no IAM users exist in member accounts.

  • ✗

    Set an IAM password policy in each account that requires strong passwords.

    Why it's wrong here

    A password policy only governs credential complexity and rotation for IAM users; it cannot prevent their creation. The requirement is to block IAM users entirely, which needs a service control policy denying iam:CreateUser across member accounts. Password policies are the right control when strengthening existing user credentials, not eliminating them.

  • ✗

    Use AWS Config rules to detect IAM users and automatically delete them.

    Why it's wrong here

    AWS Config rules evaluate resources after creation and remediation deletes the user afterwards, leaving a window where credentials exist. Detection-and-delete is tempting as automated enforcement, but the requirement is prevention; a service control policy denying iam:CreateUser stops creation before any user exists.

  • ✗

    Use AWS CloudTrail to monitor for CreateUser and alert the security team.

    Why it's wrong here

    CloudTrail only records CreateUser calls after they occur, so it detects violations rather than preventing IAM users from existing. It is tempting as a monitoring control, but the requirement is preventive: a service control policy denying iam:CreateUser across member accounts blocks creation outright.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.