SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company wants to implement AWS Organizations with multiple OUs to isolate development, testing, and production workloads. The company needs to ensure that production workloads are not impacted by changes in other OUs. Which TWO practices should the company follow? (Choose two.)
⚠ Common exam trap
Many candidates confuse logical isolation (like tagging or VPC sharing) with the strong, account-level isolation required for production workloads, and may overlook that SCPs are the correct mechanism to enforce different security policies per OU.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use separate AWS accounts for each environment to provide strong isolation.
Option C is correct because using separate AWS accounts for each environment (development, testing, production) provides the strongest isolation boundary in AWS Organizations, since accounts are the primary security and billing boundary and prevent changes in one environment from affecting another. Option E is correct because Service Control Policies (SCPs) applied at the OU level let the company enforce distinct permission guardrails per OU, ensuring that actions allowed in development or testing OUs cannot be applied to production accounts. Options A and B are incorrect because sharing cross-account role assumptions broadly or sharing a single VPC across all OUs weakens isolation and increases the blast radius of misconfigurations. Option D is incorrect because resource tagging is only a labeling and governance mechanism, not a security boundary, so it cannot provide the strong isolation that separate accounts and SCPs deliver.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow all users to assume cross-account roles for easier management.
Why it's wrong here
Blanket cross-account role assumption grants every user reach into production accounts, so a compromised development identity can alter production resources. It is tempting when simplifying administration across many accounts, where scoped, audited role assumption is the correct pattern.
- ✗
Share the same VPC across all OUs to simplify networking.
Why it's wrong here
A shared VPC couples the OUs through common subnets, route tables and peering, so a change in one OU's networking propagates to production. It is tempting when centralising connectivity and reducing VPC sprawl, where shared networking is genuinely the correct design.
- ✓
Use separate AWS accounts for each environment to provide strong isolation.
Why this is correct
Separate AWS accounts create hard security and blast-radius boundaries: IAM, quotas, and service limits are per-account, so a misconfiguration or quota exhaustion in development cannot affect production. This satisfies the stem's requirement that production workloads remain unaffected by changes in other OUs.
- ✗
Use resource tagging to isolate environments instead of accounts.
Why it's wrong here
Tags are mutable metadata, not a security boundary; IAM policies keyed on tags can be bypassed by retagging resources, leaving production exposed to other OUs' changes. It is tempting for cost allocation and inventory reporting, where tag-based grouping is genuinely appropriate.
- ✓
Apply separate SCPs to each OU to enforce different security policies.
Why this is correct
SCPs attached to an OU apply to every account within it and define the maximum permissions boundary, so distinct policies per OU let production carry stricter guardrails than development. This satisfies the isolation requirement by preventing development-oriented policy changes from loosening production controls.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.