SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A large enterprise is consolidating 300 AWS accounts under AWS Organizations. The security team needs a way to centrally define and deploy IAM roles that grant break-glass access, must ensure the roles can be assumed only by members of a specific federated group, and must be able to update the roles across all accounts without logging into each account. (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse IAM Identity Center permission sets with a mechanism for distributing an arbitrary custom role, when permission sets only generate their own auto-created roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define the role trust policy to require the SAML provider and a condition on the group attribute from the identity provider, so only the specified federated group can assume the role.
StackSets with service-managed permissions is the supported way to deploy and update IAM roles across many organization accounts, and a trust policy conditioned on the federated group attribute is what limits assumption to the intended users. Together they satisfy both the centralized deployment and the scoped-access requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create the break-glass role in the management account and grant cross-account access to every workload account using an IAM group with an inline policy that lists each account ID.
Why it's wrong here
A single role in the management account does not create the role in each workload account, and a cross-account trust still requires a role in the target account. Managing a list of 300 account IDs inline is also operationally fragile and does not meet the centralized update requirement.
- ✗
Attach an SCP at the root that allows iam:CreateRole only from the management account and rely on that as the deployment mechanism for the break-glass role.
Why it's wrong here
An SCP is a guardrail that bounds permissions, not a deployment mechanism. It cannot create roles or distribute a trust policy, so it does not achieve the rollout goal. It also restricts legitimate role creation by workloads, which is broader than intended.
- ✓
Define the role trust policy to require the SAML provider and a condition on the group attribute from the identity provider, so only the specified federated group can assume the role.
Why this is correct
An IAM role trust policy can require sts:AssumeRoleWithSAML and include a condition key such as SAML:aud or a custom attribute mapped from the IdP, which restricts assumption to members of the named group. This is the standard way to scope federated access to a specific group rather than the whole directory.
- ✗
Use IAM Identity Center permission sets with a custom inline policy that embeds the break-glass trust policy, and assign the permission set to the federated group.
Why it's wrong here
IAM Identity Center permission sets create their own roles in target accounts, but they cannot define the trust policy of a separate, named break-glass role, and they do not deploy a custom role template. This does not satisfy the requirement to centrally distribute a specific role with a specific trust policy.
- ✓
Use AWS CloudFormation StackSets with service-managed permissions and automatic deployment enabled to deploy the break-glass role to every account in the target OUs.
Why this is correct
StackSets with service-managed permissions integrate with Organizations and can target OUs, automatically deploying the stack to new accounts as they are added. This satisfies the requirement to roll out and update the role across all accounts without per-account console access, and updates propagate when the template changes.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.