Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A healthcare company operates a multi-account AWS environment with AWS Organizations. A central Security account runs Amazon GuardDuty and AWS Security Hub, and all member accounts are delegated administrators for those services. The company now wants to centrally manage Amazon Inspector findings across all accounts and ensure that new accounts are automatically covered. Which solution meets these requirements with the LEAST operational effort?

⚠ Common exam trap

The trap here is assuming that Amazon Inspector findings must be forwarded manually across accounts, when the service already supports a delegated administrator model with organization-wide auto-enrollment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Designate the Security account as the delegated administrator for Amazon Inspector in AWS Organizations, then enable Inspector with organization-wide configuration so that all existing and future member accounts are automatically enrolled.

Amazon Inspector integrates with AWS Organizations through a delegated administrator. The Security account becomes the delegated administrator, and organization-wide enablement covers all current and future accounts automatically. Findings are aggregated centrally, which directly satisfies both the central management and automatic new-account coverage requirements without custom forwarding pipelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Designate the Security account as the delegated administrator for Amazon Inspector in AWS Organizations, then enable Inspector with organization-wide configuration so that all existing and future member accounts are automatically enrolled.

    Why this is correct

    Amazon Inspector supports a delegated administrator model through AWS Organizations. Once the Security account is the delegated administrator, enabling Inspector at the organization level automatically enrolls existing accounts and any accounts added later. Findings aggregate in the delegated administrator account, eliminating per-account setup and meeting the automatic coverage requirement with minimal effort.

  • ✗

    Enable Amazon Inspector in each member account individually, then configure each account to forward findings to the Security account using Amazon EventBridge rules and AWS Lambda.

    Why it's wrong here

    Enabling Inspector account by account and building custom EventBridge forwarding is exactly the manual, high-overhead approach the scenario wants to avoid. It also fails to automatically cover newly created accounts because each new account would need its own enablement and forwarding configuration, creating drift and inconsistent coverage across the organization.

  • ✗

    Enable Amazon Inspector only in the Security account and use cross-account IAM roles to scan resources in member accounts from the Security account.

    Why it's wrong here

    Amazon Inspector is a regional, account-scoped service that evaluates resources within the account where it is enabled. Cross-account IAM roles do not let one account's Inspector scan another account's EC2 instances, Lambda functions, or container images. This approach cannot provide the required organization-wide coverage and would leave member accounts unscanned.

  • ✗

    Use AWS CloudFormation StackSets to deploy Inspector enablement templates to all accounts and rely on AWS Config rules to detect accounts that are not enabled.

    Why it's wrong here

    StackSets can deploy resources across accounts, but Amazon Inspector enablement is better handled through the native delegated administrator integration. Using Config rules to detect non-compliance adds monitoring without automatic remediation, and StackSets must be updated for new accounts. This creates unnecessary custom tooling compared with the built-in organization-wide enablement.

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.