Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A startup is using a single AWS account for development, testing, and production. They want to isolate environments and improve security. What is the most aligned AWS best practice?

⚠ Common exam trap

SAP-C02 often tests the misconception that VPCs or IAM policies provide sufficient isolation; the best practice is to use separate AWS accounts for strong security boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create separate AWS accounts for each environment using AWS Organizations.

AWS best practice for isolating environments is to use separate AWS accounts for each environment (development, testing, production) managed under AWS Organizations. This provides strong security boundaries, simplifies billing, and allows for centralized governance and service control policies (SCPs).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use separate VPCs within the same account.

    Why it's wrong here

    Separate VPCs segment network traffic but share IAM, service quotas, and billing, so a compromised development credential still reaches production resources. It is tempting because VPC isolation is quick and needs no new accounts, which suits segmenting workloads that already share a trust boundary.

  • ✗

    Use IAM policies to restrict access per environment.

    Why it's wrong here

    IAM policies control identity permissions, not network or account boundaries, so workloads still share one account's blast radius. IAM is the right tool for least-privilege access within an account, which is why it tempts, but isolation requires separate accounts.

  • ✓

    Create separate AWS accounts for each environment using AWS Organizations.

    Why this is correct

    Separate accounts give each environment its own blast radius, IAM boundaries and service quotas, satisfying the isolation and security requirement. AWS Organizations centrally manages billing and governance through service control policies, while consolidated billing retains volume discounts. A single account cannot enforce hard environment boundaries, since IAM policies alone permit cross-environment access.

  • ✗

    Use resource tagging to separate environments.

    Why it's wrong here

    Tags are metadata for cost allocation and organisation, providing no security or network boundary between environments. Tagging is correct for billing and governance reporting, but it cannot prevent a development change from affecting production resources in the same account.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.