Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company uses AWS Organizations with a single OU for all accounts. The security team wants to prevent any account from leaving the organization without approval. What should they do?

⚠ Common exam trap

Many candidates confuse IAM policies with SCPs, thinking IAM can restrict root user actions, or they choose detective controls (Config or CloudTrail) instead of the preventive SCP that actually blocks the action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an SCP that denies the organizations:LeaveOrganization action.

A Service Control Policy (SCP) applied at the root or OU level in AWS Organizations can explicitly deny the `organizations:LeaveOrganization` action for all member accounts. SCPs are the only mechanism that can centrally restrict what actions accounts can perform, including leaving the organization, regardless of the permissions granted by IAM policies within those accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure IAM policies on the root user of each account to deny leave actions.

    Why it's wrong here

    IAM policies cannot restrict AWS Organizations actions such as LeaveOrganization; only service control policies applied at the root or OU can. It is tempting because IAM policies do govern most AWS API permissions, and would be correct for controlling ordinary resource access.

  • ✗

    Create an AWS Config rule to detect leave attempts.

    Why it's wrong here

    An AWS Config rule only evaluates and reports configuration compliance after the fact; it cannot block an account from leaving, and no AWS Config managed rule detects Organizations leave events. It is tempting because Config is the standard service for continuous compliance auditing, and would be correct for flagging non-compliant resource configurations.

  • ✗

    Enable AWS CloudTrail to monitor leave events and send alerts.

    Why it's wrong here

    CloudTrail records the LeaveOrganization API call only after the account has already departed, so it provides detection rather than prevention. It is tempting because CloudTrail is the default mechanism for auditing Organizations activity, and would be correct when the requirement is retrospective alerting on membership changes rather than blocking them.

  • ✓

    Apply an SCP that denies the organizations:LeaveOrganization action.

    Why this is correct

    Service control policies set the maximum available permissions for member accounts, and applying one that denies organizations:LeaveOrganization blocks the API call from every principal in the OU, including the account's own root user, satisfying the requirement that no account can depart without approval.

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.