Courseiva
Design Solutions for Organizational ComplexityhardMultiple ChoiceObjective-mapped

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A financial services company uses AWS Organizations with a multi-account structure: a central security account, a shared services account, and multiple workload accounts. The security team needs to centrally manage and audit all changes to security groups across all accounts. They have implemented AWS Config with an aggregator in the security account. However, they notice that changes to security groups in workload accounts are not appearing in the aggregator. The workload accounts have AWS Config enabled and are recording security group changes. The security account has the necessary cross-account permissions. What is the most likely cause and solution?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The security account is not authorized in each workload account's Config settings. The security team must add the security account as an authorized aggregator in each workload account.

AWS Config aggregator requires an authorized aggregator account that is set up in each source account. Without this authorization, the aggregator cannot collect data. Option B is wrong because Config is recording changes. Option C is wrong because CloudTrail is not needed for Config aggregation. Option D is wrong because SCPs do not block Config aggregation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The security account is not authorized in each workload account's Config settings. The security team must add the security account as an authorized aggregator in each workload account.

    Why this is correct

    Config aggregator requires explicit authorization from source accounts.

  • AWS CloudTrail is not enabled in workload accounts. The security team must enable CloudTrail.

    Why it's wrong here

    CloudTrail is not required for Config aggregation.

  • Service Control Policies are blocking cross-account access. The security team must modify SCPs to allow Config aggregation.

    Why it's wrong here

    SCPs do not block Config aggregation by default.

  • AWS Config in workload accounts is not recording security group changes. The security team must enable recording for security groups.

    Why it's wrong here

    The stem says Config is recording changes.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 1,660 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.