SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A multinational company is adopting AWS Organizations to manage multiple accounts across business units. The security team requires that specific IAM roles be automatically deployed to all existing and future member accounts. Which solution should the company use?
⚠ Common exam trap
Many exam-takers confuse AWS Config's remediation actions with direct resource creation, or they assume Service Catalog's sharing mechanism automatically deploys resources, when in fact only CloudFormation StackSets with automatic deployment provides native, organization-wide, and future-proof resource deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation StackSets with automatic deployment enabled in the organization.
AWS CloudFormation StackSets with automatic deployment enabled allows you to deploy IAM roles across all accounts in an AWS Organization, including future accounts, by specifying the organization root or OUs as targets. This ensures consistent role creation without manual intervention, as StackSets automatically provisions stacks in new accounts as they join the organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to enforce the role creation in each account.
Why it's wrong here
AWS Config rules evaluate resource configuration against desired states and flag drift; they detect non-compliant accounts but do not create IAM roles themselves. Config is the right choice for continuous compliance auditing and remediation triggers, not for deploying baseline roles across an organisation.
- ✓
Use AWS CloudFormation StackSets with automatic deployment enabled in the organization.
Why this is correct
CloudFormation StackSets with automatic deployment targets an organisation or OU, so the required IAM roles are provisioned into every existing account and any account added later. This satisfies the automatic deployment requirement for both current and future member accounts.
- ✗
Use AWS Service Catalog to create a portfolio with the IAM role product and share it with all accounts.
Why it's wrong here
Service Catalog shares portfolios only with accounts you explicitly grant access to, and products are launched manually by users, so roles are not pushed automatically to existing and future member accounts. It suits governed self-service provisioning of approved products, not organisation-wide baseline deployment.
- ✗
Use AWS Lambda functions triggered by AWS CloudTrail events to create the role in each account.
Why it's wrong here
CloudTrail-triggered Lambda reacts to API events and cannot reliably provision roles into existing accounts or guarantee coverage of future ones. It is tempting because Lambda automates account actions, and would be correct for event-driven remediation, not declarative role deployment, which AWS Organizations and CloudFormation StackSets handle.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.