Courseiva
Design Solutions for Organizational ComplexitymediumMultiple SelectObjective-mapped

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company wants to implement AWS Organizations with multiple OUs to isolate development, testing, and production workloads. The company needs to ensure that production workloads are not impacted by changes in other OUs. Which TWO practices should the company follow? (Choose two.)

⚠ Common exam trap

Many candidates confuse logical isolation (like tagging or VPC sharing) with the strong, account-level isolation required for production workloads, and may overlook that SCPs are the correct mechanism to enforce different security policies per OU.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use separate AWS accounts for each environment to provide strong isolation.

Using separate AWS accounts for each environment provides strong isolation at the AWS account boundary, which is the most secure and recommended practice for preventing production workloads from being impacted by changes in other environments. Account-level isolation ensures that IAM policies, resource limits, and service quotas are independent, and that no cross-account resource sharing can accidentally affect production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Allow all users to assume cross-account roles for easier management.

    Why it's wrong here

    This could blur isolation boundaries.

  • Share the same VPC across all OUs to simplify networking.

    Why it's wrong here

    Sharing a VPC could lead to cross-environment impacts.

  • Use separate AWS accounts for each environment to provide strong isolation.

    Why this is correct

    Separate accounts provide the best isolation between environments.

  • Use resource tagging to isolate environments instead of accounts.

    Why it's wrong here

    Tags do not provide strong isolation.

  • Apply separate SCPs to each OU to enforce different security policies.

    Why this is correct

    SCPs can be applied at the OU level to enforce boundaries.

About these practice questions

One of 1,660 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.