Courseiva

CCNA Design Solutions for Organizational Complexity Questions

75 of 200 questions · Page 2/3 · Design Solutions for Organizational Complexity · Answers revealed

76
MCQhard

A company is migrating a legacy monolithic application to a microservices architecture on AWS. The application has strict latency requirements and must be deployed across multiple Availability Zones. Which design strategy BEST meets these requirements while minimizing operational overhead?

A.Use Amazon ECS with Fargate launch type, defining services across multiple AZs.
B.Use AWS Lambda functions for each microservice, triggered by API Gateway.
C.Deploy each microservice on Amazon EC2 instances in an Auto Scaling group across AZs.
D.Use Amazon EKS with worker nodes on EC2, and deploy microservices as Kubernetes pods.
AnswerA

Amazon ECS with Fargate removes EC2 instance management, satisfying the minimal operational overhead constraint. Defining services across multiple Availability Zones provides the required resilience, while Fargate's task placement and awsvpc networking keep inter-service latency low without patching or capacity planning.

Why this answer

Amazon ECS with Fargate is the best choice because it provides serverless container orchestration, automatically managing infrastructure and scaling. By deploying services across multiple Availability Zones, it ensures high availability and low-latency communication without the operational overhead of managing EC2 instances or Kubernetes control planes. AWS Lambda introduces cold start latency and a 15-minute execution limit, making it unsuitable for strict latency requirements and long-running microservices.

EC2 instances and EKS require more operational overhead for patching and scaling. Fargate minimizes that overhead while meeting latency and multi-AZ requirements.

Exam trap

The trap here is that candidates often choose Lambda for its serverless simplicity, but fail to consider the cold start latency and 15-minute execution limit that make it unsuitable for strict latency requirements and long-running microservices.

How to eliminate wrong answers

Option B is wrong because AWS Lambda functions have a maximum execution timeout of 15 minutes and are not designed for long-running or stateful microservices; they also introduce cold start latency that can violate strict latency requirements. Option C is wrong because managing EC2 instances in an Auto Scaling group requires significant operational overhead for patching, scaling, and capacity planning, which does not minimize operational overhead. Option D is wrong because Amazon EKS with worker nodes on EC2 requires managing the Kubernetes control plane and worker node lifecycle, adding operational complexity that contradicts the requirement to minimize operational overhead.

77
MCQeasy

A company wants to centralize AWS CloudTrail logs from all accounts in AWS Organizations into a single S3 bucket. Which configuration is required?

A.Configure each account's CloudTrail to send logs to a central CloudWatch Logs group
B.Create a CloudTrail trail in each account and deliver logs to the same S3 bucket
C.Create an organization trail in the management account that is enabled for all accounts
D.Use S3 replication to copy logs from individual account buckets to a central bucket
AnswerC

An organization trail created in the management account automatically applies to every account in AWS Organizations, delivering events to one central S3 bucket. This satisfies the requirement to centralise CloudTrail logs across all accounts without configuring individual trails per account, and it captures management events organisation-wide by default.

Why this answer

AWS Organizations supports creating an organization trail in the management account that automatically applies to all accounts in the organization. This centralizes CloudTrail logs from every account into a single S3 bucket without requiring per-account configuration, ensuring consistent logging and simplifying management.

Exam trap

The trap here is that candidates may think individual trails per account (Option B) are necessary or simpler, but AWS Organizations provides a native, centralized mechanism that automatically includes all accounts without per-account configuration.

How to eliminate wrong answers

Option A is wrong because CloudTrail cannot send logs directly to a CloudWatch Logs group; it can send events to CloudWatch Logs, but the question specifies centralizing logs into a single S3 bucket, not a CloudWatch Logs group. Option B is wrong because creating individual trails in each account and delivering to the same S3 bucket would require manual setup per account, does not leverage AWS Organizations integration, and may cause permission issues or log duplication without centralized management. Option D is wrong because S3 replication copies objects after they are written, but it does not address the initial delivery of CloudTrail logs from multiple accounts; each account would still need its own trail and bucket, adding complexity and cost.

78
MCQeasy

A company uses a single AWS account for development and production workloads. To improve security and cost allocation, the company decides to separate environments into multiple accounts. What is the PRIMARY benefit of using multiple accounts?

A.Reducing overall compute costs by sharing reserved instances across environments.
B.Simplifying backup and disaster recovery procedures.
C.Decreasing network latency between development and production environments.
D.Enabling centralized security controls and consolidated billing.
AnswerD

Multiple accounts let AWS Organizations apply service control policies centrally, enforcing security guardrails across every member account, while consolidated billing aggregates usage for volume discounts and cost allocation. This directly satisfies the stem's goals of improved security and cost allocation when separating development and production workloads.

Why this answer

Separating environments into multiple AWS accounts provides a strong security boundary (via AWS Organizations SCPs) and enables consolidated billing with cost allocation tags. This allows centralized security controls (e.g., guardrails, IAM policies) across accounts while aggregating usage for volume discounts, which is the primary benefit for improving security and cost allocation.

Exam trap

The trap here is that candidates confuse the secondary benefit of cost savings (shared RIs) with the primary benefit of security isolation and centralized governance, which is the core reason for multi-account strategies in the SAP-C02 exam.

How to eliminate wrong answers

Option A is wrong because sharing Reserved Instances across accounts is possible with consolidated billing, but this is a cost-saving benefit, not the primary security and cost allocation benefit of multi-account separation. Option B is wrong because backup and disaster recovery procedures are not inherently simplified by multiple accounts; they often require cross-account replication and additional orchestration. Option C is wrong because network latency between environments is not decreased by separate accounts; in fact, inter-account traffic typically adds latency compared to intra-VPC communication within a single account.

79
Multi-Selecteasy

A company wants to centrally manage IAM users across multiple AWS accounts using AWS IAM Identity Center (successor to AWS Single Sign-On). Which of the following are true? (Choose TWO.)

Select 2 answers
A.Users can be granted access to multiple accounts from a central location.
B.Users must be IAM users in each account.
C.Identity Center requires an on-premises Active Directory.
D.Permission sets are assigned to IAM roles in the management account.
E.Users can be created in the Identity Center directory.
AnswersA, E

AWS IAM Identity Center assigns users and groups to permission sets across every account in an AWS Organization from one administrative view, satisfying the centralised multi-account management requirement. This removes the need to create duplicate IAM users in each account, since identities exist once and are federated outward.

Why this answer

Option A is correct because IAM Identity Center is designed for centralized multi-account access: from the management account you create permission sets and assign users/groups to multiple AWS accounts, and users then access those accounts through the AWS access portal without per-account IAM users. Option E is correct because Identity Center includes a built-in Identity Center directory where you can create and manage users and groups directly, in addition to connecting external identity sources such as Active Directory or SAML/OIDC providers. Option B is incorrect because Identity Center federates users into accounts via IAM roles, so users do not need to exist as IAM users in each account.

Option C is incorrect because an on-premises Active Directory is optional, not required; the Identity Center directory or another external IdP can be used. Option D is incorrect because permission sets are not assigned to IAM roles in the management account; they are AWS-managed entities assigned to users/groups for target accounts, where Identity Center provisions corresponding IAM roles in those accounts.

Exam trap

The trap here is that candidates often confuse permission sets with IAM roles in the management account, but permission sets are actually applied to roles created in the member accounts, not the management account.

80
Matchingmedium

Match each AWS migration service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Track migration progress across multiple tools

Automate migration of on-premises servers to AWS

Migrate databases to AWS with minimal downtime

Rehost applications from physical or virtual servers

Simplify, automate, and accelerate moving data to AWS

Why these pairings

AWS Migration Hub centralizes tracking, SMS automates server replication, DMS handles database migration, and Application Discovery Service discovers on-premises assets.

81
MCQmedium

A company uses AWS Organizations and wants to centrally manage AWS Config rules across all member accounts. They have enabled AWS Config in the management account and used AWS Config aggregator to view compliance status across accounts. However, they want to enforce a specific Config rule in all accounts automatically. Which solution should they use?

A.Use AWS Config conformance packs with AWS Organizations to deploy the rule across all accounts.
B.Use the AWS Config aggregator to manually enable the rule in each account.
C.Use AWS CloudFormation StackSets to deploy a Config rule template to each account.
D.Create an SCP that requires all accounts to enable AWS Config.
AnswerA

Conformance packs bundle Config rules and remediation actions as a single deployable entity, and AWS Organizations integration pushes them to every member account automatically, satisfying the requirement to enforce the rule centrally without per-account manual deployment.

Why this answer

AWS Config conformance packs can be deployed across all accounts in an AWS Organization using the AWS Organizations integration. Conformance packs allow you to deploy a collection of AWS Config rules and remediation actions consistently. Option B is incorrect because the AWS Config aggregator only provides a central view of compliance status; it does not automatically enable rules in member accounts.

Option C is incorrect: while CloudFormation StackSets can deploy Config rules, conformance packs are the recommended and more straightforward method for deploying Config rules across an organization. Option D is incorrect because SCPs (Service Control Policies) are used to manage permissions and cannot directly enforce AWS Config rules.

82
MCQmedium

Refer to the exhibit. A company has created a CloudTrail trail named 'my-trail' in the management account of AWS Organizations. The trail is configured to deliver logs to a central S3 bucket. The security team wants to capture all management events from all accounts in the organization. Based on the exhibit, what is the most likely issue?

A.The trail is not a multi-region trail
B.The trail does not include global service events
C.The trail has log file validation enabled, which prevents cross-account delivery
D.The trail is not an organization trail
AnswerD

An organization trail is required to capture management events from every account in AWS Organizations automatically. A standard trail logs only the management account's events, so member accounts' activity never reaches the central S3 bucket, leaving the security team's organisation-wide visibility incomplete.

Why this answer

The exhibit shows that the CloudTrail trail 'my-trail' is not configured as an organization trail. In AWS Organizations, a trail must be explicitly created as an organization trail to automatically log management events from all member accounts. Without this setting, the trail only captures events from the management account, not the entire organization.

Exam trap

The trap here is that candidates may assume a trail created in the management account automatically covers all organization accounts, but CloudTrail requires explicit organization trail configuration to enable cross-account logging.

How to eliminate wrong answers

Option A is wrong because the exhibit does not indicate whether the trail is multi-region; even if it were single-region, that would not prevent cross-account delivery—it would only limit regional coverage. Option B is wrong because the question specifically asks about capturing management events from all accounts, and global service events (like IAM) are a subset of management events; excluding them would not prevent delivery from other accounts. Option C is wrong because log file validation is a security feature that ensures log integrity and does not block cross-account delivery; it is unrelated to organization trail configuration.

83
MCQhard

A company has a large AWS Organizations environment with 200 accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. They need to ensure that the roles are deployed to all existing and future accounts, and that any changes to the roles are automatically propagated. Which solution should they use?

A.Write a script using AWS CLI that iterates over all accounts and creates the IAM roles, and schedule it to run periodically to update roles.
B.Use AWS Resource Access Manager (RAM) to share the IAM roles from the central security account to all member accounts.
C.Use AWS CloudFormation StackSets with service-managed permissions to deploy the IAM roles to all accounts in the organization, and enable automatic deployment.
D.Create an IAM role in the management account and use AWS Single Sign-On (SSO) to grant access to the central security account.
AnswerC

CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to deploy stacks to all accounts. Enabling automatic deployment ensures that new accounts automatically receive the IAM roles, and updates to the stack are propagated to all accounts, meeting the requirements with minimal effort.

Why this answer

CloudFormation StackSets with service-managed permissions is the AWS-native way to deploy IAM roles across an organization. It automatically targets accounts in specified OUs and can be configured to deploy to new accounts as they are added. StackSet updates are rolled out to all stack instances, ensuring consistency.

This approach centralizes management and reduces operational overhead compared to manual or scripted methods.

Exam trap

The trap here is thinking that AWS RAM can share IAM roles, but RAM only supports a specific set of resource types and does not include IAM roles.

84
MCQeasy

A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a member account. Which step is required?

A.Enable IAM Identity Center in the management account and then register the member account as a delegated administrator.
B.Create a service control policy that allows the member account to manage IAM Identity Center.
C.Use AWS CloudFormation StackSets to deploy IAM Identity Center configurations to the member account.
D.Set up AWS Config rules to enforce IAM Identity Center settings in the member account.
AnswerA

Delegated administration requires the management account to enable IAM Identity Center first, since only that account can register a member account as delegated administrator. This satisfies the stem's constraint: administration is delegated to a member account, not the management account, while AWS Organizations integration remains intact.

Why this answer

To delegate administration of IAM Identity Center to a member account, you must first enable IAM Identity Center in the management account. Then, you can register the member account as a delegated administrator using the IAM Identity Center console or the RegisterDelegatedAdministrator API. This allows the member account to manage IAM Identity Center settings, users, and groups without requiring management account credentials.

Exam trap

The trap here is that candidates often confuse service control policies (SCPs) with delegation mechanisms, assuming an SCP can grant administrative rights, when in fact SCPs only deny or allow existing permissions and cannot delegate IAM Identity Center administration.

How to eliminate wrong answers

Option B is wrong because service control policies (SCPs) can only deny or allow actions at the account level, but they cannot delegate administrative permissions for IAM Identity Center; delegation requires explicit registration via the management account. Option C is wrong because AWS CloudFormation StackSets can deploy resources across accounts but cannot register a delegated administrator for IAM Identity Center, which is a management-plane operation. Option D is wrong because AWS Config rules can only evaluate and enforce compliance of resource configurations, not grant administrative delegation or manage IAM Identity Center settings.

85
Multi-Selectmedium

A company uses AWS Organizations and wants to establish a central logging solution. They need to collect CloudTrail logs from all accounts and store them in a central S3 bucket in the management account. Which TWO steps are required to achieve this?

Select 2 answers
A.Create an AWS Config rule to monitor CloudTrail configuration.
B.Apply a service control policy (SCP) to enforce CloudTrail logging.
C.Create a new CloudTrail trail in the management account with organization trail enabled.
D.Configure the trail to deliver logs to a central S3 bucket in the management account.
E.Enable CloudTrail in each member account individually.
AnswersC, D

An organisation trail created in the management account automatically applies to every account in AWS Organizations, delivering their CloudTrail events to the central S3 bucket. This single trail satisfies the requirement to aggregate logs from all member accounts without per-account configuration.

Why this answer

Option C is correct because creating a CloudTrail trail in the management account with the organization trail feature enabled automatically applies the trail to all accounts in the AWS Organization, capturing events across every member account without configuring each one separately. Option D is correct because the trail must be configured to deliver its log files to a central S3 bucket located in the management account, which fulfills the requirement of a single centralized logging destination. Option A is incorrect because an AWS Config rule only evaluates and reports on configuration compliance; it does not collect or centralize CloudTrail logs.

Option B is incorrect because an SCP governs the maximum available permissions for accounts but does not itself create trails or deliver logs to S3. Option E is incorrect because enabling CloudTrail individually in each member account is unnecessary and contrary to the centralized organization trail approach.

Exam trap

The trap is thinking that individual CloudTrail enablement in each member account is necessary. In reality, creating an organization trail in the management account automatically enables CloudTrail in all accounts.

86
MCQmedium

A company has a central IT team that manages AWS Organizations. The development team needs to create and manage their own AWS accounts for new projects. What is the BEST way to automate account creation while maintaining governance?

A.Create an AWS Service Catalog product that uses AWS Organizations APIs to create a new account, applies a baseline CloudFormation template, and moves the account to the correct OU.
B.Use AWS CloudFormation StackSets to create accounts in bulk.
C.Use the AWS Organizations console to manually create accounts and assign them to the appropriate OU.
D.Give the development team the credentials to the management account and let them create accounts directly.
AnswerA

An AWS Service Catalog product wrapping AWS Organizations APIs creates accounts programmatically, applies a baseline CloudFormation template, and places each account in the correct OU. This gives the development team self-service while the central team retains governance through the portfolio.

Why this answer

It uses AWS Service Catalog to provide a self-service portal for the development team, while the central IT team retains governance by embedding AWS Organizations API calls to create accounts, apply a baseline CloudFormation template for security and compliance, and automatically move the account to the correct Organizational Unit (OU). This approach enforces guardrails without granting direct management account access.

Exam trap

The trap here is that candidates often confuse CloudFormation StackSets with account creation, but StackSets only operate on existing accounts, not create new ones.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation StackSets deploy resources across existing accounts and regions; they cannot create new AWS accounts. Option C is wrong because manual creation via the AWS Organizations console is not automated and does not scale for new projects, violating the requirement for automation. Option D is wrong because giving development team credentials to the management account violates the principle of least privilege and central governance, exposing the organization to security risks and accidental changes.

87
MCQeasy

A company uses AWS Organizations and has a requirement that all Amazon S3 buckets must have versioning enabled. The company wants to automatically enable versioning on any bucket that is created without it. Which solution should be implemented?

A.Use AWS Config with a managed rule s3-bucket-versioning-enabled and configure auto-remediation using an AWS Systems Manager Automation document to enable versioning.
B.Use an SCP to deny s3:CreateBucket unless versioning is enabled.
C.Use AWS Config to detect buckets without versioning and send an SNS notification.
D.Use AWS CloudFormation StackSets to deploy a bucket with versioning enabled in each account.
AnswerA

AWS Config's s3-bucket-versioning-enabled managed rule detects buckets lacking versioning, then auto-remediation triggers a Systems Manager Automation document that calls PutBucketVersioning. This satisfies the automatic enablement requirement for any non-compliant bucket, whether created directly or via CloudFormation.

Why this answer

AWS Config can detect S3 buckets without versioning using the managed rule `s3-bucket-versioning-enabled`, and then automatically remediate the noncompliant resource by invoking an AWS Systems Manager Automation document that enables versioning on the bucket. This provides a fully automated, event-driven solution that meets the requirement without manual intervention or blocking bucket creation.

Exam trap

The trap here is that candidates often choose Option B (SCP) because they assume SCPs can enforce API-level conditions like versioning, but SCPs cannot evaluate request parameters that are not supported as condition keys in the IAM policy context.

How to eliminate wrong answers

Option B is wrong because SCPs cannot conditionally deny `s3:CreateBucket` based on whether versioning is enabled at creation time; the `s3:CreateBucket` API call does not support a condition key for versioning, so the SCP would either block all bucket creation or be ineffective. Option C is wrong because sending an SNS notification only alerts administrators but does not automatically enable versioning, failing the requirement to 'automatically enable versioning'. Option D is wrong because AWS CloudFormation StackSets can only deploy resources in accounts where they are explicitly applied; they cannot retroactively fix buckets created outside the StackSet or in accounts not included in the stack instance, leaving gaps in coverage.

88
MCQmedium

A company is using AWS Organizations with multiple accounts. The central IT team wants to enforce that all EC2 instances are launched with specific tags (e.g., CostCenter and Environment). The solution should prevent any untagged instances from being created. Which approach should be taken?

A.Use AWS Service Catalog to provision EC2 instances only from pre-configured products that include required tags.
B.Use an AWS Config rule to detect untagged instances and trigger a Lambda function to terminate them.
C.Create an SCP that denies the ec2:RunInstances action if the required tags are not specified in the request.
D.Create an IAM policy for each account that requires tags on instance creation.
AnswerC

SCPs set the maximum permissions for member accounts and are evaluated before IAM, so a deny on ec2:RunInstances with a Null condition on aws:RequestTag keys blocks untagged launches organisation-wide, satisfying the requirement to prevent creation rather than merely detect it afterwards.

Why this answer

AWS Organizations SCPs can centrally enforce tag requirements by denying the ec2:RunInstances action when required tags are not specified in the request. While IAM policies can also use condition keys like aws:RequestTag to enforce tags, managing individual IAM policies across many accounts is less efficient and harder to maintain. SCPs provide a preventive control that applies to all principals in an account, ensuring consistent enforcement without relying on detection and remediation.

Exam trap

The trap here is that candidates often choose a detective solution (like AWS Config with Lambda) because it seems automated, but the question explicitly requires a preventive control that blocks creation, which only SCPs can achieve at the organizational level.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog can enforce tags on provisioned products, but it does not prevent users from launching EC2 instances directly via the console, CLI, or SDK outside of Service Catalog, leaving a gap in enforcement. Option B is wrong because AWS Config rules are detective, not preventive; they can detect untagged instances and trigger a Lambda function to terminate them, but this allows a window of time where the untagged instance exists and may incur cost or security risk, and it does not block the creation in the first place. Option D is wrong because IAM policies must be applied individually to each account or user, and they can be overridden or bypassed by users with sufficient permissions (e.g., administrators), whereas SCPs provide a centralized, unmodifiable guardrail across all accounts in the organization.

89
MCQhard

A healthcare company operates a multi-account AWS environment with AWS Organizations. A central Security account runs Amazon GuardDuty and AWS Security Hub, and all member accounts are delegated administrators for those services. The company now wants to centrally manage Amazon Inspector findings across all accounts and ensure that new accounts are automatically covered. Which solution meets these requirements with the LEAST operational effort?

A.Designate the Security account as the delegated administrator for Amazon Inspector in AWS Organizations, then enable Inspector with organization-wide configuration so that all existing and future member accounts are automatically enrolled.
B.Enable Amazon Inspector in each member account individually, then configure each account to forward findings to the Security account using Amazon EventBridge rules and AWS Lambda.
C.Enable Amazon Inspector only in the Security account and use cross-account IAM roles to scan resources in member accounts from the Security account.
D.Use AWS CloudFormation StackSets to deploy Inspector enablement templates to all accounts and rely on AWS Config rules to detect accounts that are not enabled.
AnswerA

Amazon Inspector supports a delegated administrator model through AWS Organizations. Once the Security account is the delegated administrator, enabling Inspector at the organization level automatically enrolls existing accounts and any accounts added later. Findings aggregate in the delegated administrator account, eliminating per-account setup and meeting the automatic coverage requirement with minimal effort.

Why this answer

Amazon Inspector integrates with AWS Organizations through a delegated administrator. The Security account becomes the delegated administrator, and organization-wide enablement covers all current and future accounts automatically. Findings are aggregated centrally, which directly satisfies both the central management and automatic new-account coverage requirements without custom forwarding pipelines.

Exam trap

The trap here is assuming that Amazon Inspector findings must be forwarded manually across accounts, when the service already supports a delegated administrator model with organization-wide auto-enrollment.

90
Multi-Selectmedium

A company is implementing a multi-account strategy using AWS Organizations. They want to centralize CloudTrail logs from all accounts into a single S3 bucket in the management account. Which TWO steps are required to achieve this? (Choose two.)

Select 2 answers
A.Use S3 replication to copy logs from member account buckets to the central bucket.
B.Create an IAM role in each member account that allows CloudTrail to write to the central bucket.
C.Enable AWS Config in each member account to forward logs to the central bucket.
D.Create a CloudTrail trail in the management account with the 'Enable for all accounts in my organization' option.
E.Configure the S3 bucket policy to grant the CloudTrail service principal write access from all accounts.
AnswersD, E

Creating an organisation trail with 'Enable for all accounts in my organization' automatically applies the trail to every account, delivering their events to the central S3 bucket. This satisfies the centralisation requirement without configuring each account individually.

Why this answer

Option D is correct because creating an organization trail from the management account with 'Enable for all accounts in my organization' is the mechanism that makes CloudTrail log events from every member account into the specified S3 bucket, satisfying the centralized logging requirement. Option E is correct because the central S3 bucket must have a bucket policy granting the CloudTrail service principal (cloudtrail.amazonaws.com) permission to write objects, and it must account for the source accounts (via aws:SourceArn or organization conditions) so logs from all accounts can be delivered. Option A is not required because S3 replication copies objects between buckets and is unrelated to CloudTrail's native organization trail delivery.

Option B is not required because CloudTrail uses the service principal and bucket policy, not an IAM role in each member account, to deliver logs. Option C is not required because AWS Config records resource configuration changes and does not forward CloudTrail logs to S3.

Exam trap

The trap here is that candidates often assume cross-account access requires IAM roles (Option B) or replication (Option A), but CloudTrail's organization trail uses S3 bucket policies with the CloudTrail service principal, not IAM roles, to enable direct log delivery from all member accounts.

91
MCQmedium

A company is using AWS Organizations to manage multiple accounts. The security team requires that all newly created member accounts automatically have an AWS Config rule enabled that checks whether S3 buckets have default encryption enabled. Which solution should be used?

A.Use an SCP in the root to require encryption on S3 buckets.
B.Use AWS CloudFormation StackSets with automatic deployment to deploy the AWS Config rule across all accounts in the organization.
C.Create an AWS Config rule in the management account and delegate an admin account to apply it to all member accounts.
D.Configure AWS CloudTrail to automatically enable the AWS Config rule in new accounts.
AnswerB

StackSets with automatic deployment targets the organisation or OU, so the Config rule template is instantiated in each existing and newly created member account without manual intervention, satisfying the automatic enablement requirement for new accounts.

Why this answer

AWS CloudFormation StackSets with automatic deployment can deploy the AWS Config rule across all accounts in an AWS Organization, including newly created member accounts, by targeting the root organizational unit (OU). This ensures that the Config rule is automatically enabled in new accounts as they are created, meeting the security team's requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse SCPs (which only deny or allow actions) with actual configuration enforcement, or they assume CloudTrail can perform configuration actions, when in reality only automated deployment tools like CloudFormation StackSets can proactively enable Config rules in new accounts.

How to eliminate wrong answers

Option A is wrong because a Service Control Policy (SCP) can deny actions that disable encryption but cannot directly enable an AWS Config rule or enforce default encryption on existing S3 buckets; SCPs are permission boundaries, not configuration enforcement tools. Option C is wrong because while you can delegate an admin account for AWS Config, the management account cannot directly apply a Config rule to all member accounts automatically for new accounts; Config rules must be deployed via StackSets or similar automation to target new accounts. Option D is wrong because AWS CloudTrail does not have the capability to enable AWS Config rules; CloudTrail is for logging API activity, not for deploying or managing Config rules.

92
MCQhard

A company has a multi-account AWS environment with a central shared services VPC and multiple workload VPCs connected via AWS Transit Gateway. The security team wants to inspect all traffic between workload VPCs using a centralized firewall appliance in the shared services VPC. They need to ensure that traffic is inspected without modifying the workload VPC route tables. What should they do?

A.Create a VPC peering connection between each workload VPC and the shared services VPC, and update the route tables in each workload VPC to point to the shared services VPC for inter-VPC traffic.
B.Configure AWS Transit Gateway route tables to send all inter-VPC traffic to the shared services VPC, and enable appliance mode on the Transit Gateway attachment for the shared services VPC.
C.Use AWS PrivateLink to create endpoint services in the shared services VPC for each workload VPC, and configure the workload VPCs to use these endpoints for inter-VPC communication.
D.Configure AWS Transit Gateway route tables to send all inter-VPC traffic to the shared services VPC, and disable appliance mode on the Transit Gateway attachment for the shared services VPC.
AnswerB

By configuring Transit Gateway route tables to direct traffic to the shared services VPC and enabling appliance mode on that attachment, traffic between workload VPCs will be routed through the firewall appliance. Appliance mode ensures that flow symmetry is maintained for stateful inspection, and workload VPC route tables do not need to be modified.

Why this answer

To inspect traffic between workload VPCs without modifying their route tables, you can use AWS Transit Gateway route tables to direct traffic to a central shared services VPC. Enabling appliance mode on the Transit Gateway attachment for the shared services VPC ensures that flow symmetry is maintained for stateful inspection. This solution is scalable and does not require changes to workload VPC route tables.

Exam trap

The trap here is overlooking the need for appliance mode on the Transit Gateway attachment to maintain flow symmetry for stateful inspection.

93
MCQmedium

A company uses AWS Organizations and wants to allow certain accounts to use AWS Service Catalog for self-service provisioning. The IT team needs to control which products are available. Where should the product portfolio be shared?

A.Share the portfolio with the target accounts from the Service Catalog console
B.Use AWS CloudFormation StackSets to deploy products to each account
C.Use SCPs to allow specific accounts to use Service Catalog
D.Create IAM roles in the central account that developers can assume
AnswerA

Sharing the portfolio from the Service Catalog console uses AWS RAM to grant target accounts access to the exact products selected. This satisfies the IT team's need to control which products each account can self-provision.

Why this answer

AWS Service Catalog allows you to share a product portfolio directly with individual AWS accounts or organizational units (OUs) within AWS Organizations. By sharing the portfolio from the Service Catalog console, the IT team can control which products are available to specific accounts, enabling self-service provisioning while maintaining governance. This approach leverages Service Catalog's native portfolio sharing mechanism, which does not require additional infrastructure or cross-account IAM roles.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog portfolio sharing with other cross-account mechanisms like CloudFormation StackSets or IAM roles, failing to recognize that Service Catalog's native sharing via RAM is the correct way to control product availability for self-service provisioning.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation StackSets are used to deploy infrastructure across multiple accounts and regions, but they do not provide a self-service catalog for end users to provision products on demand; they are an automation tool, not a governance mechanism for product availability. Option C is wrong because Service Control Policies (SCPs) are used to restrict permissions at the AWS Organizations level, but they cannot control which specific Service Catalog products are available to an account; SCPs only allow or deny actions on the Service Catalog API, not portfolio-level sharing. Option D is wrong because creating IAM roles in the central account for developers to assume does not directly control which Service Catalog products are available in target accounts; it only grants cross-account access, but the portfolio must still be shared with the target account for the products to appear in that account's Service Catalog.

94
MCQhard

A company has a multi-account AWS environment with a central network account and multiple workload accounts. They want to use AWS Transit Gateway to connect VPCs across accounts. The network team has created a Transit Gateway in the network account and shared it using AWS Resource Access Manager (RAM) with the workload accounts. The workload accounts have created VPC attachments to the Transit Gateway. However, traffic is not flowing between the VPCs. The route tables in the workload VPCs have routes pointing to the Transit Gateway. What is the most likely cause?

A.The Transit Gateway is in a different AWS account, so route propagation is not automatic.
B.The Transit Gateway route tables do not have routes for the attached VPCs.
C.The security groups in the workload VPCs are blocking traffic.
D.VPC flow logs are not enabled.
AnswerB

Attachment alone does not enable routing. The Transit Gateway's route table must contain routes associating each VPC attachment, otherwise packets arriving from one VPC have no path to the other attachments, even though the workload VPC route tables correctly target the gateway.

Why this answer

For traffic to flow between VPCs attached to a Transit Gateway, the Transit Gateway route tables must have routes for the attached VPC CIDRs. When a VPC is attached, a route to the VPC is not automatically added to the Transit Gateway route table unless route propagation is enabled or a static route is created. The most likely cause is that the Transit Gateway route tables lack routes for the attached VPCs, preventing traffic from being forwarded between them.

Exam trap

SAP-C02 often tests the shared responsibility of Transit Gateway routing, and candidates may assume that attaching a VPC automatically adds routes to the Transit Gateway route table, when in fact propagation or static routes are required.

How to eliminate wrong answers

Option A is wrong because route propagation in Transit Gateway route tables is not automatic regardless of account ownership; it must be enabled on the attachment, and cross-account sharing via RAM does not change that. Option C is wrong because security groups could block traffic, but the question states that route tables in the workload VPCs have routes pointing to the Transit Gateway, and the most fundamental issue is the missing Transit Gateway route table routes; security groups are a secondary check. Option D is wrong because VPC flow logs are for logging, not for enabling traffic flow; they have no impact on connectivity.

95
Multi-Selecthard

A company is expanding its AWS Organizations environment to include several new business units. The security team must ensure that all new accounts automatically have a baseline security configuration, including a VPC with specific flow logs enabled, an AWS Config recorder, and a set of IAM roles for cross-account access. They want to minimize manual effort and ensure consistency. Which two solutions should they use to achieve these goals? (Choose two.)

Select 2 answers
A.Use AWS Systems Manager Automation to run a runbook that configures each new account after creation.
B.Use AWS Control Tower to set up a landing zone and apply mandatory guardrails to new accounts.
C.Use AWS CloudFormation StackSets to deploy a baseline template to all accounts in the organization.
D.Use AWS Service Catalog to create a portfolio of baseline products and share it with all accounts.
E.Use AWS Config conformance packs to deploy baseline configurations across all accounts.
AnswersB, C

AWS Control Tower provides a landing zone with preconfigured blueprints, including VPCs with flow logs, AWS Config recorders, and IAM roles for cross-account access. It automates account provisioning and applies guardrails to ensure compliance. This reduces manual effort and ensures consistency across new accounts, directly meeting the baseline security requirements.

Why this answer

AWS Control Tower automates the setup of a secure landing zone with preconfigured baselines and guardrails, while CloudFormation StackSets deploy resource templates across accounts and automatically target new accounts. Together, they provide automated, consistent baseline security configurations with minimal manual effort, meeting the requirements for VPC flow logs, Config recorders, and IAM roles.

Exam trap

The trap here is confusing services that assess compliance (Config conformance packs) or require manual provisioning (Service Catalog) with those that automatically deploy and enforce baseline configurations.

96
MCQeasy

A company wants to centralize management of AWS resources across multiple accounts using AWS Control Tower. What is a prerequisite for setting up Control Tower?

A.A pre-configured landing zone.
B.An AWS Organizations management account.
C.At least three organizational units (OUs).
D.Existing AWS Config rules in all accounts.
AnswerB

Control Tower is built on AWS Organizations and provisions its landing zone from the organisation's management account, which must exist and have all features enabled. Without that management account, Control Tower cannot create organisational units, accounts or guardrails.

Why this answer

AWS Control Tower requires an AWS Organizations management account because Control Tower uses Organizations to create and manage accounts, apply service control policies (SCPs), and enforce guardrails across the organization. The management account serves as the central point for all administrative actions, and without it, Control Tower cannot establish the necessary multi-account structure or landing zone.

Exam trap

The trap here is that candidates often confuse the prerequisite of an existing AWS Organizations management account with the need for a pre-configured landing zone, mistakenly thinking Control Tower requires an already-built environment rather than building it itself.

How to eliminate wrong answers

Option A is wrong because a pre-configured landing zone is not a prerequisite; Control Tower itself sets up the landing zone as part of its initial configuration. Option C is wrong because Control Tower does not require at least three organizational units (OUs); it creates a default OU structure (e.g., Security, Sandbox) but the minimum is one OU, and you can add more later. Option D is wrong because existing AWS Config rules in all accounts are not a prerequisite; Control Tower deploys and manages Config rules as part of its guardrails, and pre-existing rules could conflict with Control Tower's managed rules.

97
MCQeasy

A company uses AWS Organizations with a single OU for all accounts. The security team wants to prevent any account from leaving the organization without approval. What should they do?

A.Configure IAM policies on the root user of each account to deny leave actions.
B.Create an AWS Config rule to detect leave attempts.
C.Enable AWS CloudTrail to monitor leave events and send alerts.
D.Apply an SCP that denies the organizations:LeaveOrganization action.
AnswerD

Service control policies set the maximum available permissions for member accounts, and applying one that denies organizations:LeaveOrganization blocks the API call from every principal in the OU, including the account's own root user, satisfying the requirement that no account can depart without approval.

Why this answer

A Service Control Policy (SCP) applied at the root or OU level in AWS Organizations can explicitly deny the `organizations:LeaveOrganization` action for all member accounts. SCPs are the only mechanism that can centrally restrict what actions accounts can perform, including leaving the organization, regardless of the permissions granted by IAM policies within those accounts.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, thinking IAM can restrict root user actions, or they choose detective controls (Config or CloudTrail) instead of the preventive SCP that actually blocks the action.

How to eliminate wrong answers

Option A is wrong because IAM policies attached to the root user of each account cannot prevent the account from leaving the organization; the root user has full administrative access that overrides IAM policies, and the LeaveOrganization action is controlled by Organizations, not IAM. Option B is wrong because an AWS Config rule can only detect noncompliant resources or actions after they occur, but it cannot prevent the leave action from succeeding; by the time the rule triggers, the account may have already left. Option C is wrong because AWS CloudTrail logs events after they happen, so it can only provide visibility into a leave event after it has occurred, not block it proactively.

98
MCQhard

A global company uses a multi-account AWS Organizations structure with hundreds of accounts. The network team wants to centrally manage VPC flow logs for all accounts and send them to a centralized S3 bucket in the security account. Which solution is MOST scalable and operationally efficient?

A.Use AWS Config to detect VPCs without flow logs and trigger a Lambda function to enable them.
B.Use CloudFormation StackSets to deploy a stack that enables VPC flow logs in every account and region, sending logs to a centralized S3 bucket with appropriate bucket policies.
C.Write a script that uses the AWS API to enable VPC flow logs in each account and region, triggered by AWS Config rules.
D.Set up a VPN connection from each account to the security account and configure flow logs to use a S3 endpoint in the security account.
AnswerB

StackSets deploys the flow-log stack across every account and region from a single administration, using service-managed permissions so new accounts inherit it automatically. This satisfies the hundreds-of-accounts scale constraint, unlike per-account scripting, and centralises delivery to the security account's S3 bucket.

Why this answer

CloudFormation StackSets allow you to deploy a single CloudFormation template across multiple accounts and regions in an AWS Organization, making it the most scalable and operationally efficient solution for centrally enabling VPC Flow Logs. By including the appropriate S3 bucket policy in the security account, you can ensure logs from all accounts are delivered to a centralized bucket without manual intervention.

Exam trap

The trap here is that candidates often overcomplicate the solution by considering VPNs or custom scripts, when the most scalable and operationally efficient approach is to use CloudFormation StackSets with a service-managed permission model to deploy a standardized stack across the entire organization.

How to eliminate wrong answers

Option A is wrong because AWS Config can detect non-compliant VPCs, but relying on a Lambda function to enable flow logs introduces a single point of failure and is less scalable than a declarative, infrastructure-as-code approach like StackSets. Option C is wrong because writing a custom script that uses the AWS API to enable flow logs in each account and region is error-prone, requires ongoing maintenance, and does not provide the same level of consistency and rollback capabilities as StackSets. Option D is wrong because setting up a VPN connection from each account to the security account is unnecessary and adds significant complexity and cost; VPC Flow Logs can be delivered directly to a centralized S3 bucket using a bucket policy that grants cross-account access, without requiring network connectivity.

99
Multi-Selectmedium

A company is implementing a hybrid network architecture with multiple VPCs in different AWS accounts. They need to ensure private connectivity between the VPCs and their on-premises data center. Which TWO services should they use together to meet this requirement?

Select 2 answers
A.AWS Direct Connect
B.Amazon Route 53 Resolver
C.VPC peering
D.AWS Transit Gateway
E.AWS Client VPN
AnswersA, D

AWS Direct Connect provides a dedicated private network link from the on-premises data centre into AWS, bypassing the public internet. It supplies the private hybrid connectivity the scenario demands, terminating at a VPC or transit gateway.

Why this answer

AWS Direct Connect (A) is correct because it provides a dedicated private network connection from the on-premises data center to AWS, bypassing the public internet for consistent, low-latency private connectivity. AWS Transit Gateway (D) is correct because it acts as a central hub that connects multiple VPCs across different AWS accounts and attaches to the Direct Connect gateway, enabling transitive routing between all VPCs and on-premises. Together, Direct Connect provides the private on-premises link while Transit Gateway provides scalable many-to-many VPC interconnection across accounts.

Amazon Route 53 Resolver (B) only handles DNS resolution between on-premises and VPCs and does not provide the private network transport itself. VPC peering (C) connects only two VPCs at a time and does not scale to a hub-and-spoke multi-account topology or integrate natively with on-premises routing. AWS Client VPN (E) is a remote-user VPN solution for individual clients, not for site-to-site private connectivity between VPCs and a data center.

Exam trap

The trap here is that candidates often choose VPC peering (Option C) thinking it can connect multiple VPCs to on-premises directly, but VPC peering lacks transitive routing and cannot terminate a Direct Connect connection, making Transit Gateway the required central aggregation point.

100
MCQhard

A company has a VPC with a CIDR block of 10.0.0.0/16. They need to connect this VPC to an on-premises network that uses the CIDR block 10.0.0.0/8. The company wants to use AWS Site-to-Site VPN for the connection. They must avoid IP address conflicts. What is the MOST appropriate solution?

A.Use AWS Transit Gateway with a Site-to-Site VPN attachment and enable route propagation.
B.Configure the Site-to-Site VPN with static routes and use AWS PrivateLink to access on-premises services.
C.Use AWS Site-to-Site VPN with a virtual private gateway and implement NAT on the on-premises side to translate the VPC CIDR to a non-overlapping range.
D.Re-create the VPC with a non-overlapping CIDR block, such as 192.168.0.0/16, and then establish the Site-to-Site VPN.
AnswerD

The most straightforward way to avoid IP address conflicts is to ensure that the VPC CIDR does not overlap with the on-premises network. Re-creating the VPC with a non-overlapping CIDR like 192.168.0.0/16 eliminates the conflict entirely. While this may require migration effort, it is the most reliable and recommended solution for overlapping CIDRs.

Why this answer

IP address conflicts between a VPC and on-premises networks can cause routing failures and unpredictable behavior. The most appropriate solution is to use non-overlapping CIDR blocks. Re-creating the VPC with a CIDR that does not overlap with the on-premises 10.0.0.0/8 network ensures clean routing and avoids the need for complex NAT or translation.

While migration may be required, it is the most reliable long-term fix.

Exam trap

The trap here is assuming that AWS Transit Gateway or VPN configurations can automatically resolve overlapping CIDR blocks, but they cannot; the only true fix is to use non-overlapping IP ranges.

101
MCQhard

A financial services company uses AWS Organizations with all features enabled. A security account runs AWS CloudFormation StackSets with service-managed permissions to deploy guardrail resources into every account. Compliance requires that no member account administrator can disable AWS CloudTrail or delete the organization trail, even in accounts where they hold full administrative rights, and that new accounts automatically receive the guardrail. Which combination should the solutions architect recommend?

A.Create a trail in each member account with AWS CloudFormation StackSets and enable log file validation so tampering with delivered logs is detectable.
B.Deploy an organization trail from the management account and attach a service control policy that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail to all member accounts except the management account.
C.Enable AWS CloudTrail Lake in the security account and configure an event data store that ingests management events from all accounts through AWS Organizations.
D.Deploy a CloudFormation StackSet that creates a trail and an IAM policy denying cloudtrail:StopLogging, and attach the policy to every IAM role in each account.
AnswerB

An organization trail created in the management account applies to every account in the organization, and member accounts cannot alter or delete it. A service control policy that denies the stop and delete actions removes those permissions from every principal in member accounts, including administrators, because SCPs define the maximum available permissions. New accounts inherit both automatically, satisfying the guardrail requirement.

Why this answer

An organization trail owned by the management account extends logging to all accounts and cannot be modified or deleted by member accounts. Pairing it with a service control policy that denies the stop and delete actions on CloudTrail removes those capabilities from member-account administrators, because SCPs bound the permissions available to every principal in the account. Accounts created later automatically fall under the same trail and policy.

Exam trap

The trap here is assuming an IAM policy or log file validation can restrain an account administrator, when only a service control policy plus a management-account-owned organization trail removes the ability to disable logging.

102
MCQeasy

A startup has 25 AWS accounts in a single organization. A new compliance officer wants a single, read-only view of all resources and their configuration across every account, and wants to be alerted when an S3 bucket becomes publicly accessible. The team has no existing aggregation tooling. Which approach requires the least operational effort?

A.Enable AWS CloudTrail organization trails and use CloudTrail Lake queries to list all resources and detect public S3 buckets.
B.Use AWS Trusted Advisor in the management account with the organization view enabled and rely on the S3 bucket permissions check to detect public buckets.
C.Deploy a custom script on an EC2 instance in each account that calls the S3 and IAM APIs nightly and writes results to a central S3 bucket, then query the results with Amazon Athena.
D.Enable AWS Config in each account with a delegated administrator in a security account, deploy the s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited managed rules, and use the aggregator to view all accounts.
AnswerD

AWS Config supports a delegated administrator so one account can centrally manage recorders and rules for the whole organization, and the aggregator consolidates resource and compliance data across accounts and Regions. The two managed rules directly detect publicly accessible buckets and surface noncompliance.

Why this answer

AWS Config with a delegated administrator and a cross-account aggregator gives a single read-only view of resource configuration and compliance across all accounts, which is exactly what the compliance officer asked for. The managed S3 public-access rules provide continuous, change-driven detection of publicly accessible buckets.

Exam trap

The trap here is treating CloudTrail as a configuration inventory tool, when it records API calls and cannot report current resource state such as whether a bucket is public.

103
MCQmedium

A company has multiple AWS accounts and wants to use AWS CloudFormation StackSets to deploy a common set of resources across all accounts. The StackSet should be managed from the management account. What permissions are required?

A.Create IAM users in target accounts with AdministratorAccess.
B.Create an IAM role in each target account with a trust policy allowing the management account to assume it.
C.Use a CloudFormation service role in the management account.
D.Apply an SCP to allow CloudFormation actions across accounts.
AnswerB

StackSets needs a trust relationship in every target account so the management account can assume a role and deploy stacks. Creating an IAM role in each target account, with a trust policy naming the management account, satisfies the cross-account assumption requirement.

Why this answer

AWS CloudFormation StackSets require the management account to assume an IAM role in each target account to deploy resources. This role must have a trust policy that allows the management account's StackSets service-linked role (or a custom role) to assume it, granting the necessary permissions to create, update, or delete stack instances across accounts. Without this cross-account trust relationship, StackSets cannot perform operations in target accounts.

Exam trap

The trap here is that candidates often confuse a CloudFormation service role (used for stack operations within a single account) with the cross-account IAM roles required by StackSets, leading them to select Option C.

How to eliminate wrong answers

Option A is wrong because creating IAM users with AdministratorAccess in target accounts is not required and violates security best practices; StackSets use IAM roles, not users, for cross-account access. Option C is wrong because a CloudFormation service role in the management account only governs permissions within that account, not across target accounts; StackSets need roles in each target account. Option D is wrong because SCPs (Service Control Policies) are used to restrict permissions at the organizational unit or account level, but they do not grant the necessary cross-account trust or permissions for StackSets to assume roles; SCPs can only deny or allow actions, not establish trust relationships.

104
MCQhard

A company uses AWS Config to evaluate resource compliance across multiple accounts. The security team wants to automatically remediate non-compliant resources using AWS Systems Manager Automation documents. Which solution is MOST scalable and secure?

A.Create a Lambda function in each account that periodically checks Config rules and triggers remediation
B.Set up Amazon CloudWatch Events rules in each account to detect Config compliance changes and invoke remediation Lambda functions
C.Enable AWS Config rules with automatic remediation using SSM Automation documents in each account, and use an AWS Config aggregator to monitor compliance across all accounts
D.Use AWS Organizations service control policies to automatically remediate non-compliant resources
AnswerC

Automatic remediation must run locally in each account so SSM Automation can act on that account's resources without cross-account role sprawl; the aggregator then gives central visibility. This satisfies the scalability and security constraints by keeping remediation scoped per account while consolidating compliance monitoring.

Why this answer

It leverages AWS Config's native automatic remediation feature, which directly associates SSM Automation documents with Config rules to remediate non-compliant resources as soon as they are detected. This approach is scalable as it operates within each account without requiring custom Lambda functions or external triggers, and it is secure because remediation actions are defined and controlled by the SSM Automation documents, which can be centrally managed. The use of an AWS Config aggregator provides a single-pane-of-glass view across all accounts for monitoring compliance, meeting the security team's requirements efficiently.

Exam trap

The trap here is that candidates often confuse AWS Config's automatic remediation with custom event-driven approaches (like Lambda or CloudWatch Events) or mistakenly think SCPs can remediate resources, when in fact SCPs only prevent non-compliant actions from being taken, not fix existing non-compliant resources.

How to eliminate wrong answers

Option A is wrong because periodically checking Config rules with a Lambda function introduces latency and inefficiency, as it relies on polling rather than event-driven detection, and it requires managing Lambda functions in every account, which is less scalable and secure than using native Config remediation. Option B is wrong because while CloudWatch Events (now Amazon EventBridge) can detect compliance changes, invoking a Lambda function for remediation adds unnecessary complexity and custom code, whereas AWS Config's built-in automatic remediation is more direct and secure, eliminating the need for additional event processing. Option D is wrong because AWS Organizations service control policies (SCPs) are used to restrict permissions and enforce guardrails, not to automatically remediate non-compliant resources; SCPs cannot trigger remediation actions on existing resources.

105
MCQeasy

A company has a centralized logging solution using Amazon S3 and AWS CloudTrail. They want to ensure that logs are immutable and cannot be deleted or modified by any user, including the root user. Which S3 feature should be enabled?

A.S3 Object Lock in compliance mode.
B.S3 Versioning with a lifecycle policy.
C.S3 bucket policy denying s3:DeleteObject.
D.S3 MFA Delete.
AnswerA

S3 Object Lock in compliance mode prevents any principal, including the account root user, from overwriting or deleting protected object versions for the retention period. This satisfies the immutability constraint that standard bucket policies or versioning alone cannot guarantee.

Why this answer

S3 Object Lock in compliance mode ensures that objects are write-once-read-many (WORM) and cannot be deleted or overwritten by any user, including the root user. Compliance mode locks the retention period and prevents any user, even the AWS account root user, from shortening or removing the retention settings, making logs truly immutable.

Exam trap

The trap here is that candidates often choose a bucket policy denying s3:DeleteObject, not realizing that the root user can bypass bucket policies by modifying them, whereas S3 Object Lock in compliance mode provides a true immutability guarantee that even the root user cannot override.

How to eliminate wrong answers

Option B is wrong because S3 Versioning alone does not prevent deletion; it only preserves previous versions of objects, and a user with sufficient permissions can still delete the current version or the entire object. Option C is wrong because a bucket policy denying s3:DeleteObject can be overridden by a user with administrative privileges (including the root user) who can modify or remove the policy itself. Option D is wrong because MFA Delete only adds an extra authentication factor for delete operations but does not prevent deletion by the root user if they have the MFA device; it also does not prevent overwrites or modifications.

106
MCQeasy

A company is designing a multi-account strategy for its development, testing, and production environments. The security team requires that all accounts share a centralized logging solution. Which approach meets this requirement with the LEAST administrative overhead?

A.Configure each account to write logs to its own S3 bucket and use AWS Glue to copy them to a central bucket.
B.Use AWS CloudTrail to deliver logs to a central S3 bucket in the logging account.
C.Use Amazon CloudWatch Logs in each account and view logs from a central account via cross-account access.
D.Use Amazon Kinesis Data Firehose in each account to stream logs to a central Amazon OpenSearch Service.
AnswerB

CloudTrail can deliver events from every account in an organisation to one central S3 bucket using an organisation trail, requiring only a bucket policy and no per-account configuration, which minimises administrative overhead across development, testing and production.

Why this answer

AWS CloudTrail can be configured to deliver logs from multiple accounts to a single central S3 bucket in a logging account by setting up a CloudTrail trail in each account that points to the same bucket. This approach requires minimal administrative overhead as it leverages native AWS cross-account logging capabilities without additional data movement or transformation services.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing options that involve additional services (Glue, Kinesis, OpenSearch) or partial centralization (CloudWatch cross-account access), missing the simplicity and native support of CloudTrail's direct cross-account S3 delivery.

How to eliminate wrong answers

Option A is wrong because it introduces unnecessary complexity and administrative overhead by requiring each account to write logs to its own S3 bucket and then using AWS Glue to copy them to a central bucket; Glue is a serverless ETL service not designed for simple log replication, and this adds cost and management burden. Option C is wrong because while cross-account CloudWatch Logs access is possible, it requires setting up IAM roles and resource policies for each account and log group, and viewing logs from a central account does not centralize the logs themselves—logs remain in source accounts, increasing management overhead and potential access issues. Option D is wrong because using Kinesis Data Firehose in each account to stream logs to a central OpenSearch Service adds significant complexity, cost, and administrative overhead compared to a simple S3 bucket delivery, and OpenSearch Service is not a centralized logging solution by default—it requires additional configuration for log indexing and retention.

107
MCQmedium

A company is implementing a multi-account strategy using AWS Organizations. They need to centralize logging of all API calls across accounts. Which solution meets this requirement with the least operational overhead?

A.Enable CloudWatch Logs in each account and stream to a central log group.
B.Create a CloudTrail trail in each account and aggregate logs to a central S3 bucket.
C.Create an organization trail in the management account with CloudTrail.
D.Enable S3 server access logs on all accounts and send to a central bucket.
AnswerC

An organisation trail created in the management account automatically applies to every member account, including future ones, capturing all API activity into a single S3 bucket. This satisfies the centralised logging requirement with minimal operational overhead, since no per-account configuration or maintenance is needed.

Why this answer

AWS Organizations supports creating an organization trail in the management account that automatically logs API calls for all member accounts without requiring per-account configuration. This centralizes logging with minimal operational overhead, as CloudTrail handles the aggregation across the organization.

Exam trap

The trap here is that candidates often think they need to configure CloudTrail in each account individually (Option B) or use CloudWatch Logs streaming (Option A), missing the organization trail feature that automatically centralizes logging with zero per-account effort.

How to eliminate wrong answers

Option A is wrong because streaming CloudWatch Logs from each account to a central log group requires per-account setup and additional log delivery infrastructure, increasing operational overhead. Option B is wrong because creating individual CloudTrail trails per account and aggregating to a central S3 bucket still requires manual configuration in each account and does not leverage the automatic organization-wide trail feature. Option D is wrong because S3 server access logs capture only S3-specific requests, not all API calls across services, and they require per-bucket configuration, failing to meet the requirement of centralizing all API calls.

108
MCQeasy

A company uses AWS Organizations with multiple accounts. The central IT team wants to restrict the use of specific EC2 instance types across all accounts to control costs. Which approach should the team use?

A.Use AWS Budgets to send alerts when costs exceed a threshold.
B.Configure Amazon CloudWatch Events to detect launches and terminate instances.
C.Attach an IAM policy to each account's root user to deny the ec2:RunInstances action for certain instance types.
D.Create a service control policy (SCP) that denies the ec2:RunInstances action for prohibited instance types and apply it to the organization.
AnswerD

An SCP applied at the organisation root enforces the instance-type restriction across every member account, satisfying the requirement to govern all accounts centrally. The ec2:RunInstances deny with a condition on instance type blocks launches regardless of each account's IAM permissions, since SCPs define the maximum available permissions.

Why this answer

Service control policies (SCPs) are the correct mechanism to centrally restrict permissions across all accounts in an AWS Organization. By creating an SCP that denies the ec2:RunInstances action for specific instance types and applying it to the organization (or relevant OUs), the central IT team can enforce this restriction globally, preventing any IAM principal in any account from launching prohibited instance types, regardless of their IAM permissions.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, thinking that attaching a deny policy to the root user or individual IAM users is sufficient, but SCPs are the only mechanism that can enforce restrictions across all principals in an AWS Organization account, including the root user.

How to eliminate wrong answers

Option A is wrong because AWS Budgets only sends cost alerts and does not enforce restrictions on resource creation; it cannot prevent the launch of specific instance types. Option B is wrong because Amazon CloudWatch Events can detect instance launches and trigger a Lambda function to terminate them, but this is a reactive, non-deterministic approach that incurs cost and latency, and instances may run briefly before termination. Option C is wrong because attaching an IAM policy to each account's root user does not prevent other IAM users or roles in the account from launching instances, and it is not scalable across many accounts; SCPs are the only way to apply a deny across all principals in an account.

109
MCQhard

A financial services company uses AWS Organizations with 300 member accounts. The security team wants to ensure that all AWS API activity in every account is logged to a central Amazon S3 bucket owned by the management account. The logs must be immutable for 7 years and protected from deletion by any member account administrator. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

A.Enable AWS Config in all accounts with a conformance pack that checks for CloudTrail logging, and configure an AWS Lambda function to copy trail logs to a central S3 bucket with a lifecycle policy.
B.Create an individual trail in each member account that delivers to a central S3 bucket, and use a bucket policy that denies s3:DeleteObject to all principals except the management account.
C.Create an organization trail in the management account that applies to all accounts, configure the trail to deliver to a central S3 bucket, and enable S3 Object Lock in compliance mode with a 7-year retention period on the bucket.
D.Use AWS CloudTrail Lake in the management account to ingest events from all member accounts, and configure a 7-year retention period on the event data store.
AnswerC

An organization trail created in the management account automatically applies to all existing and future accounts in the organization, eliminating per-account configuration. Delivering to a central S3 bucket with S3 Object Lock in compliance mode enforces immutability for the retention period, and member account administrators cannot override or delete the objects, satisfying both centralization and protection requirements.

Why this answer

An organization trail in the management account automatically applies to all current and future accounts, providing centralized logging with minimal effort. Delivering to a central S3 bucket with S3 Object Lock in compliance mode ensures that logs cannot be deleted or altered by any user, including the root user, for the specified retention period. This meets the immutability and centralization requirements with the least operational overhead.

Exam trap

The trap here is assuming that a bucket policy denying delete operations provides the same immutability as S3 Object Lock, but bucket policies can be modified by administrators with sufficient permissions.

110
MCQmedium

A company is using AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a specific member account. What must be done?

A.Create an IAM role in the member account with permissions to manage Identity Center
B.Use the AWS Organizations console to register the member account as a delegated administrator for IAM Identity Center
C.Attach an SCP to the member account allowing Identity Center actions
D.Create a new user in the management account with admin privileges
AnswerB

Registering the member account as a delegated administrator for IAM Identity Center, through the AWS Organizations console or `register-delegated-administrator`, grants that account permission to manage Identity Center centrally. This satisfies the stem's requirement to delegate administration while retaining management from the organisation's management account.

Why this answer

To delegate administration of IAM Identity Center to a specific member account in AWS Organizations, you must register that account as a delegated administrator using the AWS Organizations console or API. This grants the member account the necessary permissions to manage Identity Center settings, users, and groups without requiring the management account to perform all tasks. Option B is correct because it follows the official AWS mechanism for delegating administrative control of Identity Center to a member account.

Exam trap

The trap here is that candidates often confuse delegating administration with simply granting IAM permissions via roles or SCPs, not realizing that AWS requires a specific registration process through Organizations to enable delegated administration for Identity Center.

How to eliminate wrong answers

Option A is wrong because creating an IAM role in the member account with permissions to manage Identity Center does not establish the required delegation relationship; Identity Center delegation must be registered at the Organizations level, not via a local IAM role. Option C is wrong because attaching a service control policy (SCP) to the member account only restricts or allows actions at the account level but does not delegate administrative authority for Identity Center; SCPs are for permission boundaries, not delegation. Option D is wrong because creating a new user in the management account with admin privileges does not delegate administration to a member account; it keeps all control in the management account and does not enable the member account to manage Identity Center independently.

111
MCQeasy

A company wants to allow developers to assume a role in a production account from their development account using AWS IAM. What is needed for this cross-account access?

A.A role in the dev account with permissions to access production resources.
B.An IAM user in the production account with permissions to switch roles.
C.A role in the production account with a trust policy allowing the dev account, and an IAM policy in the dev account allowing sts:AssumeRole.
D.An SCP that allows sts:AssumeRole from the dev account.
AnswerC

Cross-account role assumption needs two grants: the production role's trust policy must name the development account as principal, and the development identity needs an IAM policy permitting sts:AssumeRole on that role's ARN. Both halves are required for the call to succeed.

Why this answer

Cross-account IAM role access requires a role in the target (production) account with a trust policy that explicitly lists the source (development) account as a trusted principal, and an IAM policy in the source account that grants the sts:AssumeRole action for that role's ARN. This two-part configuration establishes a secure delegation path where the dev account's users or roles can request temporary credentials from the production account via the AWS Security Token Service (STS).

Exam trap

The trap here is that candidates often confuse the direction of the trust relationship, mistakenly thinking the role must be in the source account (dev) rather than the target account (production), or they overlook that both a trust policy and an IAM permissions policy are required for cross-account access.

How to eliminate wrong answers

Option A is wrong because a role in the dev account cannot directly access production resources; cross-account access requires the role to be in the production account, not the dev account. Option B is wrong because an IAM user in the production account with permissions to switch roles would only allow that user to assume roles within the same account, not from an external dev account; cross-account access requires a trust policy on the production role that authorizes the dev account. Option D is wrong because an SCP (Service Control Policy) is an organization-level policy that can restrict actions but cannot grant permissions; it can only deny or allow actions at the account level, and it does not establish the trust relationship needed for cross-account role assumption.

112
MCQmedium

A company is using AWS Organizations with consolidated billing. The company has a production account and a development account. The security team needs to ensure that developers cannot create IAM users in the development account. Which option is the MOST effective?

A.Apply an SCP to the development account that denies iam:CreateUser.
B.Create an IAM group for developers with a policy that denies iam:CreateUser.
C.Enable AWS CloudTrail to monitor iam:CreateUser calls.
D.Attach an IAM policy to each developer user that denies iam:CreateUser.
AnswerA

SCPs are effective even for users with full administrative permissions.

Why this answer

Service Control Policies (SCPs) are the most effective way to enforce permissions boundaries across entire accounts in AWS Organizations. An SCP applied to the development account will deny the `iam:CreateUser` action for all principals (including the root user) in that account, regardless of any IAM policies attached to users or roles. This ensures developers cannot create IAM users, even if they have full administrative access within the account.

Exam trap

The trap here is that candidates often confuse IAM policies (which are account-specific and can be overridden) with SCPs (which are organization-wide and cannot be bypassed by account administrators), leading them to choose an IAM-based solution that is less effective for cross-account control.

How to eliminate wrong answers

Option B is wrong because an IAM group policy only applies to users who are members of that group; developers could be added to other groups or have inline policies that grant `iam:CreateUser`, bypassing the restriction. Option C is wrong because AWS CloudTrail only logs API calls for auditing purposes and does not prevent the `iam:CreateUser` action from being executed. Option D is wrong because an IAM policy attached to each developer user is not scalable and can be overridden by other policies (e.g., a full-admin policy) that grant the same action; it also does not prevent a developer from creating a new user with a different set of permissions.

113
MCQmedium

A financial services company has an AWS Organizations structure with a management account, a dedicated network account, and 40 workload accounts. Each workload account has its own VPC, and all VPCs must be able to reach a shared services VPC in the network account. The security team requires that all inter-VPC traffic be inspected by a central firewall appliance before reaching the shared services. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS PrivateLink to expose the shared services as endpoint services, and have each workload VPC create an interface VPC endpoint to access them.
B.Deploy a VPN connection from each workload VPC to the shared services VPC using AWS Site-to-Site VPN, and route traffic through the VPN tunnels.
C.Create a VPC peering connection between each workload VPC and the shared services VPC, and route traffic through the shared services VPC where a firewall appliance is deployed.
D.Attach all workload VPCs to a central AWS Transit Gateway in the network account, use a separate route table for the shared services VPC, and associate a firewall appliance VPC with a dedicated inspection route table.
AnswerD

AWS Transit Gateway provides transitive routing and centralized management. By using separate route tables and associating the firewall VPC with an inspection route table, traffic from workload VPCs can be forced through the firewall before reaching the shared services VPC. This is the standard hub-and-spoke inspection pattern and scales to many accounts with minimal per-VPC configuration.

Why this answer

A central AWS Transit Gateway with separate route tables allows all workload VPCs to route traffic through a firewall VPC in the network account before reaching shared services. This hub-and-spoke inspection model is scalable, requires minimal per-account configuration, and meets the security requirement for central inspection. Other options either lack transitivity, do not enforce inspection, or are not designed for inter-VPC routing at scale.

Exam trap

The trap here is assuming that VPC peering or PrivateLink can provide centralized traffic inspection, when they are either non-transitive or service-specific and cannot force all traffic through a firewall.

114
MCQmedium

A company has a multi-account AWS environment with a centralized security account. The security team needs to have read-only access to all Amazon S3 buckets across all accounts for auditing purposes. Which solution is the MOST secure and scalable?

A.Create an IAM role in each account with read-only S3 permissions and a trust policy that allows the security account to assume the role.
B.Attach a bucket policy to each S3 bucket that grants read-only access to the security team's IAM user in the security account.
C.Use the root user of each account to access the buckets.
D.Create an IAM user in each account with read-only S3 permissions and share the credentials with the security team.
AnswerA

A cross-account IAM role with a trust policy scoped to the security account lets auditors assume read-only S3 permissions without distributing long-term credentials. This satisfies the security and scalability constraints by centralising access through role assumption across every account.

Why this answer

It uses IAM roles with cross-account trust policies, which is the most secure and scalable approach for granting read-only S3 access across multiple accounts. The security account assumes the role in each target account, avoiding long-term credentials and allowing centralized control via AWS Organizations or manual role creation.

Exam trap

The trap here is that candidates may choose Option B thinking bucket policies are simpler, but they overlook the scalability and maintenance burden of managing individual bucket policies across hundreds or thousands of buckets, and the fact that bucket policies do not support cross-account access without explicitly listing the principal ARN, which is less flexible than IAM roles.

How to eliminate wrong answers

Option B is wrong because attaching bucket policies to each S3 bucket individually is not scalable for large environments and requires managing policies per bucket, which can lead to policy size limits and complexity. Option C is wrong because using root users violates the principle of least privilege, is not auditable, and is insecure due to shared static credentials. Option D is wrong because creating IAM users in each account with shared credentials introduces long-term access keys that must be rotated and managed, increasing security risk and operational overhead compared to role-based access.

115
Multi-Selectmedium

Which TWO actions improve the security of an S3 bucket that stores sensitive data?

Select 2 answers
A.Enable default encryption with SSE-S3 or SSE-KMS.
B.Block all public access using the S3 Block Public Access feature.
C.Enable S3 Transfer Acceleration.
D.Configure a lifecycle policy to transition objects to Glacier.
E.Enable S3 Select to filter data.
AnswersA, B

SSE-S3 or SSE-KMS encrypts objects at rest, so data written to the bucket is unreadable without the corresponding key. This directly satisfies the sensitive-data protection requirement, mitigating exposure if storage media or snapshots are compromised.

Why this answer

Option A is correct because enabling default encryption with SSE-S3 or SSE-KMS ensures that all objects written to the bucket are encrypted at rest automatically, protecting sensitive data even if individual PUT requests omit encryption headers. Option B is correct because the S3 Block Public Access feature overrides bucket policies and ACLs to prevent any public exposure of the bucket or its objects, which is a critical safeguard for sensitive data. Option C is not a security control; S3 Transfer Acceleration only speeds up uploads and downloads via AWS edge locations.

Option D addresses cost and storage-class optimization, not security, since Glacier transition does not itself restrict access. Option E is a query capability for filtering object data with SQL, not a security mechanism.

Exam trap

The trap here is that candidates may confuse performance or cost features (Transfer Acceleration, Glacier lifecycle, S3 Select) with security controls, leading them to select options that do not actually protect data confidentiality or integrity.

116
MCQmedium

A company uses AWS Organizations with multiple accounts. The finance team needs to track costs by department, where each department uses resources across several accounts. What is the BEST way to allocate costs accurately?

A.Use AWS Cost Explorer to view costs by linked account.
B.Define cost allocation tags for each department and enable them in the Billing and Cost Management console.
C.Set up AWS Budgets for each department with alerts.
D.Create AWS Resource Groups for each department and use AWS Config to track costs.
AnswerB

Cost allocation tags must be activated in the Billing and Cost Management console before they appear in Cost Explorer and billing reports. Defining department tags and enabling them lets finance attribute spend across accounts to each department, meeting the cross-account tracking requirement.

Why this answer

Cost allocation tags allow you to tag AWS resources with department-specific metadata (e.g., 'Department: Finance') and then activate those tags in the Billing and Cost Management console. Once enabled, AWS Cost Explorer and cost reports can filter and group costs by these tags, providing accurate per-department cost tracking across multiple accounts in AWS Organizations. This is the most precise method because it directly associates resource usage with the department responsible, regardless of which account hosts the resource.

Exam trap

The trap here is that candidates often confuse account-level grouping (Option A) with tag-based allocation, assuming that each department has its own AWS account, but the question explicitly states departments use resources across several accounts, making tag-based allocation the only accurate method.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer viewing costs by linked account only shows costs per AWS account, not per department; a single department may span multiple accounts, and a single account may host resources for multiple departments, so account-level grouping cannot accurately allocate costs to departments. Option C is wrong because AWS Budgets are used for setting cost thresholds and sending alerts, not for allocating or tracking historical costs by department; they do not provide a mechanism to assign costs to departments. Option D is wrong because AWS Resource Groups are logical groupings of resources based on tags or other criteria, and AWS Config tracks resource configuration changes and compliance, not cost allocation; neither service provides cost tracking or allocation capabilities.

117
MCQeasy

A company uses AWS Organizations and wants to centrally manage backups of EC2 instances across multiple accounts. Which service should they use?

A.AWS CloudEndure Disaster Recovery
B.Amazon S3 Glacier
C.AWS Storage Gateway
D.AWS Backup
AnswerD

AWS Backup provides a central backup policy that spans accounts in AWS Organizations, letting you define and monitor backup plans for EC2 instances across the entire organisation from one place, which satisfies the centralised multi-account management requirement.

Why this answer

AWS Backup is the correct service because it provides a fully managed, policy-based backup solution that integrates with AWS Organizations to centrally manage backups across multiple accounts. It allows you to define backup policies that automatically apply to EC2 instances and other supported resources across all member accounts, ensuring compliance and centralized monitoring without requiring per-account manual configuration.

Exam trap

The trap here is that candidates may confuse AWS Backup with disaster recovery services like CloudEndure, not realizing that AWS Backup is purpose-built for centralized, policy-driven backup management across multiple accounts, while CloudEndure focuses on continuous replication for failover, not scheduled backups.

How to eliminate wrong answers

Option A is wrong because AWS CloudEndure Disaster Recovery is designed for continuous replication and rapid failover for disaster recovery scenarios, not for scheduled, policy-based backup management across multiple accounts. Option B is wrong because Amazon S3 Glacier is a storage class for long-term archival of objects, not a service for orchestrating or managing backups of EC2 instances across accounts. Option C is wrong because AWS Storage Gateway provides hybrid cloud storage access (e.g., file, volume, tape gateways) for on-premises environments, not centralized backup management of EC2 instances within AWS Organizations.

118
MCQeasy

A company uses AWS Control Tower to manage a multi-account environment. The security team needs to ensure that all accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket. What is the BEST way to achieve this?

A.Use an AWS Lambda function that runs periodically to enable CloudTrail in accounts where it is disabled.
B.Create an AWS Config rule in each account to enable CloudTrail if it is disabled.
C.Use an SCP to require CloudTrail to be enabled in each account.
D.Use the AWS CloudTrail setup provided by Control Tower, which automatically enables a trail for all accounts in the organization.
AnswerD

Control Tower's built-in CloudTrail configuration creates an organisation-wide trail delivering logs to the central S3 bucket it provisions, covering every account including future ones. This satisfies the requirement for CloudTrail across all accounts with centralised log delivery without custom automation.

Why this answer

AWS Control Tower provides an integrated CloudTrail setup that automatically creates and manages a central trail for all accounts in the organization. This trail is deployed using AWS CloudFormation StackSets and delivers logs to a centralized S3 bucket, ensuring compliance without manual intervention or custom automation. This is the best approach because it is native, fully managed, and aligns with Control Tower's governance model.

Exam trap

The trap here is that candidates often assume SCPs can enforce service enablement (like enabling CloudTrail), but SCPs only control permissions—they cannot enable services or resources; they can only prevent disabling of existing configurations.

How to eliminate wrong answers

Option A is wrong because using a periodic Lambda function is reactive, introduces latency, and does not prevent accounts from disabling CloudTrail between runs; it also adds operational overhead and potential single points of failure. Option B is wrong because an AWS Config rule can only detect non-compliance and trigger remediation (e.g., via auto-remediation), but it cannot enforce the setting across all accounts proactively; it also requires Config to be enabled in each account first. Option C is wrong because SCPs can only deny or allow API actions, not enable services; an SCP cannot force CloudTrail to be enabled—it can only prevent disabling of an already-enabled trail or block certain CloudTrail API calls.

119
Multi-Selecthard

A company is using AWS Organizations with hundreds of accounts. The central IT team needs to deploy a common set of AWS resources (e.g., VPCs, subnets, security groups) to all accounts in a specific organizational unit (OU). The solution must be automated and ensure that new accounts added to the OU automatically receive the resources. Which three steps should the team take? (Choose three.)

Select 3 answers
A.Create a StackSet with the template and target the OU, enabling automatic deployment.
B.Create an AWS CloudFormation template that defines the common resources.
C.Use AWS Config rules to detect missing resources and deploy them via Lambda.
D.Enable AWS CloudFormation StackSets trusted access with AWS Organizations.
E.Create an SCP that requires the creation of those resources.
AnswersA, B, D

StackSets deploy a CloudFormation template across many accounts in one operation, and targeting the OU with automatic deployment enabled means any account later added to that OU inherits the resources without manual intervention, satisfying the automation constraint.

Why this answer

Option B is correct because the common resources (VPCs, subnets, security groups) must first be codified in an AWS CloudFormation template, which serves as the reusable artifact for automated, consistent deployment across accounts. Option D is correct because CloudFormation StackSets must be granted trusted access with AWS Organizations so the management account can deploy stack instances into member accounts and target OUs directly. Option A is correct because creating a StackSet from that template and targeting the specific OU with automatic deployment enabled ensures existing accounts receive the resources and any new account added to the OU is provisioned automatically.

Option C is incorrect because AWS Config rules only detect and evaluate resource compliance; they do not natively deploy resources, and using Lambda for remediation is a custom, reactive approach rather than the automated StackSet mechanism required. Option E is incorrect because an SCP only sets permission guardrails (allowing or denying actions); it cannot create or require the actual provisioning of VPCs, subnets, or security groups.

Exam trap

The trap here is confusing AWS Config (a detective control) with a provisioning tool, and assuming SCPs can create resources when they only enforce permission boundaries.

120
MCQeasy

A company has a production AWS account and a development AWS account. The development team needs to assume an IAM role in the production account to deploy resources. What is the correct way to set up this cross-account access?

A.Create an IAM role in the production account with a trust policy that specifies the development account as a trusted entity
B.Apply a service control policy to allow cross-account access
C.Create an IAM user in the production account and share the credentials with the development team
D.Configure security group rules to allow access from the development account
AnswerA

A trust policy in the production account naming the development account as principal establishes the cross-account relationship, satisfying the requirement that the development team assume a role in production. The development team then attaches a policy allowing sts:AssumeRole for that role's ARN, completing the two-sided configuration.

Why this answer

Cross-account IAM role access requires creating an IAM role in the production (trusting) account with a trust policy that explicitly lists the development (trusted) account as a principal. The development team then assumes that role using the AWS STS AssumeRole API, which returns temporary security credentials. This follows the AWS recommended pattern for delegating access without sharing long-term credentials.

Exam trap

The trap here is that candidates confuse network-level controls (security groups) or organizational policies (SCPs) with IAM-based cross-account trust, or mistakenly think sharing IAM user credentials is acceptable for cross-account access.

How to eliminate wrong answers

Option B is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an AWS Organization; they do not grant cross-account access themselves and cannot be used to allow role assumption between accounts. Option C is wrong because sharing IAM user credentials violates the principle of least privilege and security best practices; it exposes long-term access keys that are not scoped or temporary, increasing risk. Option D is wrong because security group rules control network traffic at the instance level, not IAM-based access; they cannot grant API-level permissions to assume roles or deploy resources.

121
MCQeasy

A company has 30 AWS accounts in AWS Organizations. The finance team wants to receive a single consolidated bill for all accounts and apply volume discounts across the organization. Which action should a solutions architect take?

A.Create an AWS Cost and Usage Report in each account and use AWS Cost Explorer to merge the reports into a single view.
B.Enable consolidated billing by inviting all accounts to join the organization, and designate one account as the management account.
C.Use AWS Resource Access Manager to share a billing resource across all accounts and enable cost allocation tags.
D.Configure AWS Budgets in the management account to aggregate spend from all member accounts and send a single invoice.
AnswerB

Consolidated billing is a feature of AWS Organizations where the management account pays for all member accounts and receives a single bill. It also aggregates usage for volume pricing tiers and Reserved Instance and Savings Plans sharing, which meets the finance team's requirement for one bill and volume discounts.

Why this answer

Consolidated billing in AWS Organizations makes the management account responsible for paying all charges and produces one bill for the organization. It also combines usage across accounts for volume pricing and allows sharing of Reserved Instances and Savings Plans, which is exactly what the finance team needs.

Exam trap

The trap here is confusing cost visibility tools such as AWS Cost Explorer or AWS Budgets with the billing consolidation that AWS Organizations consolidated billing actually provides.

122
MCQhard

A company has a complex AWS environment with multiple accounts and VPCs. The company wants to ensure that all outbound traffic from VPCs goes through a centralized inspection VPC for security monitoring. The company uses AWS Transit Gateway. Which solution should be implemented?

A.Deploy AWS Network Firewall in each VPC and configure routing to send outbound traffic through the firewall.
B.Use VPC peering to connect all VPCs to the inspection VPC and configure routes.
C.Use Route 53 Resolver to forward all outbound DNS queries to the inspection VPC.
D.Create a Transit Gateway with route tables. Attach the inspection VPC as a central hub. Configure the route tables of the transit gateway to point the default route (0.0.0.0/0) to the inspection VPC attachment. Then attach all other VPCs and configure their route tables to send traffic to the Transit Gateway.
AnswerD

Transit Gateway route tables let you steer the default route (0.0.0.0/0) to the inspection VPC attachment, forcing all spoke VPC egress through the central hub for inspection. Attaching every VPC to the same Transit Gateway satisfies the centralised inspection constraint without complex peering.

Why this answer

It uses AWS Transit Gateway with centralized route tables to force all outbound traffic from attached VPCs through the inspection VPC. By configuring the Transit Gateway route table with a default route (0.0.0.0/0) pointing to the inspection VPC attachment, all outbound traffic from other VPCs is routed to the inspection VPC for security monitoring before leaving the network. This design meets the requirement of a single, centralized inspection point without requiring VPC peering or per-VPC firewall deployments.

Exam trap

The trap here is that candidates often confuse VPC peering with Transit Gateway, assuming peering can achieve transitive routing, but AWS VPC peering explicitly does not support transitive routing, making Option B invalid for centralized inspection.

How to eliminate wrong answers

Option A is wrong because deploying AWS Network Firewall in each VPC creates a decentralized inspection model, not a centralized one, and does not leverage Transit Gateway for traffic flow. Option B is wrong because VPC peering does not support transitive routing; each peering connection is a one-to-one relationship, so traffic cannot be centrally routed through a single inspection VPC without complex full-mesh peering. Option C is wrong because Route 53 Resolver only handles DNS queries, not general outbound traffic (e.g., HTTP, HTTPS, or other IP protocols), and thus cannot enforce security monitoring on all outbound traffic.

123
MCQmedium

A company has a production AWS account and a development AWS account under AWS Organizations. The development team wants to deploy a CloudFormation stack that creates an S3 bucket with a bucket policy that grants access to the production account's IAM roles. The development account has an SCP that denies all s3:PutBucketPolicy actions. The development team has full administrator access in their account. When they try to create the stack, it fails. What is the most likely reason and how should they proceed?

A.The development team does not have IAM permissions to create buckets. They need to attach an IAM policy that allows s3:PutBucketPolicy.
B.The SCP denies s3:PutBucketPolicy and overrides the administrator permissions. They need to request an exception to the SCP from the security team.
C.CloudFormation service role is missing. They need to create a service role with appropriate permissions.
D.The production account's IAM roles are not trusted. They need to update the trust policy.
AnswerB

SCPs set the maximum available permissions for accounts in an organisation, so they override even administrator access. The deny on s3:PutBucketPolicy blocks the stack's bucket policy creation; only the security team can grant an SCP exception.

Why this answer

SCPs apply to all principals in the account, including administrators, and deny actions even if IAM policies allow them. Since the SCP denies s3:PutBucketPolicy, the development team cannot create the bucket policy despite having full admin access. Option A is incorrect because the team does have IAM permissions (admin), but the SCP overrides them.

Option C is incorrect because CloudFormation's service role is not the issue; the SCP restriction affects all principals, including CloudFormation. Option D is incorrect because the trust policy of the production account's IAM roles is unrelated to the SCP in the development account.

124
MCQmedium

A healthcare company has a multi-account AWS environment with a central audit account. The security team needs to ensure that all API activity across all accounts is logged and that logs are stored immutably for 7 years. They also need to be able to search logs across all accounts quickly. Which solution meets these requirements with the LEAST operational overhead?

A.Enable AWS CloudTrail in each account individually, deliver logs to a central S3 bucket with a bucket policy that denies deletion, and use Amazon CloudWatch Logs Insights to search logs.
B.Use AWS Config to record API activity across all accounts and deliver snapshots to a central S3 bucket with S3 Object Lock in governance mode, and use Amazon QuickSight for search.
C.Create an organization trail in AWS CloudTrail that logs to a central S3 bucket with S3 Object Lock in compliance mode, and use Amazon Athena to query the logs.
D.Create an organization trail that logs to a central S3 bucket with versioning and MFA delete enabled, and use AWS Glue to catalog logs for search.
AnswerC

An organization trail automatically logs API activity for all accounts in the organization to a central S3 bucket. S3 Object Lock in compliance mode prevents deletion or modification for the retention period, meeting immutability. Athena can query logs directly from S3 without loading them into a separate system, providing fast search with minimal operational overhead.

Why this answer

An organization trail simplifies logging across all accounts, including future accounts. S3 Object Lock in compliance mode ensures logs cannot be deleted or altered for the retention period, even by the root user. Amazon Athena allows direct SQL queries on S3 data, providing fast search without additional infrastructure.

This solution minimizes operational overhead while meeting immutability and search requirements.

Exam trap

The trap here is underestimating the strength of S3 Object Lock compliance mode versus governance mode or bucket policies, and assuming that AWS Config records API activity.

125
Multi-Selectmedium

A company has a multi-account AWS environment and wants to implement a secure, scalable cross-account network architecture using AWS Transit Gateway. Which TWO steps should be taken?

Select 2 answers
A.Deploy VPC endpoints in each account for communication
B.Create a Transit Gateway in a central networking account and share it with other accounts using AWS Resource Access Manager
C.Create VPC attachments in each account to connect to the shared Transit Gateway
D.Establish VPC peering connections between each account and the central networking account
E.Set up AWS Direct Connect between all accounts
AnswersB, C

RAM allows sharing the Transit Gateway with other accounts.

Why this answer

AWS Transit Gateway must be created in a central networking account and then shared with other accounts using AWS Resource Access Manager (RAM) to enable cross-account connectivity without VPC peering. This centralizes routing and simplifies network management across multiple VPCs and accounts.

Exam trap

The trap here is that candidates confuse VPC endpoints (used for service access) with Transit Gateway (used for VPC-to-VPC routing), or assume VPC peering is sufficient for multi-account scalability despite its non-transitive nature and management overhead.

126
MCQmedium

A company has a multi-account AWS environment using AWS Organizations with 50 accounts. The accounts are organized into OUs based on environment: Production, Staging, and Development. The central IT team uses AWS CloudFormation StackSets to deploy a baseline network configuration (VPC, subnets, security groups) to all accounts. Recently, the network team updated the stack set to add a new subnet to the VPC. After the update, they noticed that the stack set operation failed for 10 accounts. The error message indicates that the stack set cannot update because a resource already exists. What is the MOST LIKELY cause of this failure?

A.The accounts are in different OUs and the stack set is not configured to deploy to all OUs.
B.Some accounts have manually created resources that conflict with the stack set template's resources.
C.The network team does not have sufficient IAM permissions to update stacks in those accounts.
D.The stack set was previously drift-detected and the drift is preventing updates.
AnswerB

StackSets fail when a resource declared in the template already exists outside CloudFormation's control. Manually created subnets or VPCs in those ten accounts cause the update to abort with an already-exists error, since CloudFormation cannot adopt unmanaged resources.

Why this answer

StackSets deploy a common template across accounts. If a resource defined in the template (e.g., a subnet with a specific CIDR) already exists in an account due to manual creation or prior configuration, the update fails with a 'resource already exists' error. Option A is incorrect because OU configuration affects initial deployment, not updates, and the error is about resource conflict, not OU coverage.

Option C is incorrect because IAM permissions would cause an 'access denied' error, not a resource conflict. Option D is incorrect because drift detection does not prevent updates; it only reports differences.

127
MCQmedium

A media company uses AWS Organizations with a central shared services account that hosts a Transit Gateway. Workload accounts in two OUs must be able to route traffic through the Transit Gateway to on-premises networks via AWS Site-to-Site VPN, but must not be able to route traffic to each other. A solutions architect needs to enforce this segmentation centrally. What should the architect do?

A.Apply a service control policy to each OU that denies ec2:CreateRoute for routes pointing to the other OU's CIDR ranges.
B.Enable Transit Gateway Inter-Region Peering between the two OUs and configure static routes to block traffic between them.
C.Create separate Transit Gateway route tables for each OU, associate the workload VPC attachments with their respective route tables, and only propagate the VPN attachment into both route tables.
D.Configure VPC peering between each workload VPC and the shared services VPC, and use security groups to deny traffic between the OUs.
AnswerC

Transit Gateway route tables control which attachments can reach which destinations. By associating each OU's VPC attachments with a separate route table and propagating only the VPN attachment, traffic can flow to on-premises but not between the OUs. This provides centralized, network-layer segmentation without relying on account-level controls.

Why this answer

Transit Gateway route tables are the correct mechanism for centralized network segmentation. By giving each OU its own route table that propagates only the VPN attachment, workload VPCs can reach on-premises but cannot reach each other. SCPs, Inter-Region peering, and VPC peering with security groups do not provide the required centralized, route-level isolation.

Exam trap

The trap here is reaching for service control policies to enforce network segmentation, when SCPs control API permissions and cannot filter or block data-plane traffic between attached VPCs.

128
MCQeasy

A company has a single AWS account with multiple VPCs. They want to connect all VPCs to a central VPC for shared services, such as Active Directory and DNS, without using a complex mesh of VPC peering connections. They also want to minimize costs. Which solution should they use?

A.Use AWS PrivateLink to connect each VPC to the shared services VPC.
B.Create a full mesh of VPC peering connections between all VPCs.
C.Use AWS Transit Gateway to connect all VPCs and the shared services VPC.
D.Create a VPN connection between each VPC and the shared services VPC.
AnswerC

AWS Transit Gateway acts as a central hub to connect multiple VPCs and on-premises networks. It simplifies network architecture by eliminating complex peering meshes. With Transit Gateway, you can connect all VPCs to a single gateway, and the shared services VPC can be accessed by all. This is scalable and cost-effective compared to multiple peering connections.

Why this answer

AWS Transit Gateway provides a central hub to connect multiple VPCs and shared services. It simplifies network architecture, reduces management overhead, and is cost-effective compared to a full mesh of VPC peering connections. It allows all VPCs to access the shared services VPC without complex peering arrangements.

Exam trap

The trap here is assuming that VPC peering is always the cheapest option, but for multiple VPCs, Transit Gateway can be more cost-effective and manageable.

129
MCQhard

A multinational enterprise uses AWS Organizations with 300 accounts. The network team wants to centrally manage VPC IP address allocation and share subnets across multiple accounts to simplify connectivity. They also need to ensure that when a new account is created, it automatically receives a VPC with a predefined CIDR that does not overlap with existing VPCs. Which combination of AWS services should they use?

A.AWS Resource Access Manager (RAM) to share subnets and AWS Service Catalog to provision VPCs with predefined CIDRs.
B.AWS Transit Gateway to connect VPCs and AWS Direct Connect to manage IP allocation.
C.AWS Resource Access Manager (RAM) to share subnets and Amazon VPC IP Address Manager (IPAM) to allocate non-overlapping CIDRs automatically.
D.AWS CloudFormation StackSets to deploy VPCs with predefined CIDRs and VPC peering to connect them.
AnswerC

AWS RAM allows sharing subnets across accounts within an organization, centralizing subnet management. Amazon VPC IPAM provides automated CIDR allocation from a central pool, ensuring non-overlapping address ranges across VPCs and accounts. Together, they meet the requirements for centralized IP management and subnet sharing, with minimal manual effort and built-in scalability.

Why this answer

AWS RAM enables subnet sharing across accounts, centralizing subnet management. Amazon VPC IPAM automates CIDR allocation from a central pool, preventing overlaps and simplifying IP address management at scale. This combination directly addresses the need for centralized IP allocation and subnet sharing, and it scales across many accounts without manual tracking.

Exam trap

The trap here is assuming that AWS Transit Gateway or CloudFormation StackSets handle IP address management, when they do not; IPAM is the dedicated service for automated CIDR allocation.

130
MCQmedium

A company has 200 AWS accounts in AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security tooling account. The roles must be created consistently in every account, and any change to the role trust policy must propagate automatically. Which approach requires the LEAST ongoing effort?

A.Create an IAM role in each account using a script that assumes a role in each account and calls CreateRole, and schedule the script to run weekly.
B.Use AWS Resource Access Manager to share an IAM role from the security tooling account to all other accounts.
C.Create a single IAM role in the management account and use AWS Single Sign-On permission sets to map users to that role in all accounts.
D.Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack set containing the IAM role to all accounts in the organization, and update the stack set when the trust policy changes.
AnswerD

CloudFormation StackSets with service-managed permissions automatically deploy and update stacks across all accounts in an organization, including new accounts as they are added. Updating the stack set propagates the new trust policy to every account without manual intervention, providing consistent role creation and low ongoing effort.

Why this answer

CloudFormation StackSets with service-managed permissions is designed for organization-wide deployment of resources such as IAM roles. It automatically targets all accounts, including new ones, and a stack set update rolls the new trust policy to every account. This yields consistent role definitions and minimal ongoing operational effort compared with scripts or unsupported sharing mechanisms.

Exam trap

The trap here is assuming AWS Resource Access Manager can share IAM roles or that IAM Identity Center permission sets are the right tool for a service-to-service cross-account role, when StackSets is the managed deployment mechanism.

131
Multi-Selecteasy

A company is designing a multi-account strategy for development, testing, and production environments. They want to ensure that developers can deploy resources in development and testing accounts but not in production. Which TWO methods should the company use to achieve this? (Choose TWO.)

Select 2 answers
A.Enable AWS CloudTrail to monitor and alert on production changes.
B.Apply an SCP to the production OU that denies all actions to non-approved IAM roles.
C.Use resource tags to identify development and production resources and enforce policies via SCPs.
D.Create IAM roles in production with no permissions, and allow only a central CI/CD role to assume a privileged role.
E.Use AWS Config rules to detect unauthorized deployments in production.
AnswersB, D

An SCP attached to the production OU denies actions for every principal except approved roles, giving a hard permissions boundary that developers cannot bypass. This satisfies the constraint that developers deploy only in development and testing accounts.

Why this answer

Option B is correct because AWS Organizations Service Control Policies (SCPs) applied at the production OU level set the maximum permissions for all accounts within that OU, so a deny statement targeting non-approved IAM roles (for example, denying all actions unless the principal is an approved role) blocks developers from deploying in production while leaving development and testing OUs unaffected. Option D is correct because creating production IAM roles with no permissions and allowing only a central CI/CD role to assume a privileged role enforces least privilege and separation of duties, ensuring developers cannot directly deploy to production and only the controlled pipeline can. Option A is not correct because CloudTrail only records and can alert on API activity after the fact; it is detective, not preventive, so it does not stop developers from deploying to production.

Option C is not correct because resource tags combined with SCPs are not a reliable enforcement mechanism for this requirement; SCPs do not evaluate resource tags for most services, and tag-based authorization is better handled with IAM policies and conditions, not as the primary control here. Option E is not correct because AWS Config rules are detective controls that flag noncompliant resources after deployment, not preventive controls that block deployments.

Exam trap

The trap here is that candidates often confuse detective controls (CloudTrail, Config) with preventive controls (SCPs, IAM policies), leading them to select options that only alert or audit rather than block the action entirely.

132
Multi-Selectmedium

A company is using AWS Organizations to manage 50 accounts. They want to centralize billing and also allow a central team to manage IAM roles across all accounts. The central team needs to be able to assume a role in any member account to perform administrative tasks. They have already enabled all features in Organizations. Which two steps are required to allow the central team to assume roles in member accounts? (Choose two.)

Select 2 answers
A.Create an IAM role in each member account that trusts the central team's account, and attach the necessary permissions.
B.Use AWS Organizations to create a service control policy (SCP) that allows sts:AssumeRole.
C.Create an organization trail in AWS CloudTrail to log the role assumptions.
D.Enable AWS Single Sign-On (SSO) and configure permission sets for each member account.
E.Attach an IAM policy to the central team's users or roles that allows sts:AssumeRole for the member account roles.
AnswersA, E

To allow the central team to assume a role in a member account, you must create an IAM role in that member account. The role's trust policy must specify the central team's AWS account as a trusted principal. The central team's users or roles can then assume this role. This is a fundamental step for cross-account access.

Why this answer

To enable cross-account role assumption, you need two things: a role in the target account that trusts the source account, and an IAM policy in the source account that allows the principal to call sts:AssumeRole on that role. These two steps establish the trust and the permission. Other services like AWS SSO or CloudTrail are helpful but not required for this specific access pattern.

Exam trap

The trap here is thinking that SCPs can grant permissions or that enabling Organizations automatically allows cross-account access.

133
MCQmedium

A financial services company has an AWS Organizations structure with a management account, a dedicated Network account, and 40 workload accounts. The Network team wants to share a single AWS Transit Gateway with all workload accounts so that each account can attach its own VPCs. Workload accounts must not be able to modify the Transit Gateway route tables owned by the Network account. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

A.Create a separate Transit Gateway in each workload account and peer them together using static routes in each account's route tables.
B.Create the Transit Gateway in the Network account and create a VPC peering connection from each workload VPC to a shared services VPC that hosts the Transit Gateway.
C.Create the Transit Gateway in the management account and grant each workload account an IAM role that allows creating attachments in the management account.
D.Create the Transit Gateway in the Network account and use AWS Resource Access Manager (AWS RAM) to share it with the organization. In each workload account, create a transit gateway attachment for the VPC and associate it with the shared transit gateway route table.
AnswerD

Sharing the Transit Gateway through AWS RAM with the organization allows every workload account to create attachments without duplicating the Transit Gateway. The Network account retains ownership of the route tables, so workload accounts can associate attachments but cannot modify the Network-owned route tables unless explicitly granted. This minimizes overhead and preserves the required boundaries.

Why this answer

AWS RAM is the native mechanism to share a Transit Gateway across an organization. The owner account keeps control of the Transit Gateway and its route tables, while participant accounts create VPC attachments. This satisfies both the sharing requirement and the restriction that workload accounts cannot alter Network-owned route tables, with minimal ongoing administration.

Exam trap

The trap here is assuming that sharing a Transit Gateway via AWS RAM also shares administrative control of its route tables, when in fact ownership and route table modification rights remain with the owner account.

134
MCQmedium

A company has a management account in AWS Organizations and wants to share a central Amazon VPC subnet with multiple member accounts for a shared services VPC. Which AWS service should be used to share the subnet?

A.VPC peering connection
B.AWS Resource Access Manager
C.AWS PrivateLink
D.Service control policy
AnswerB

AWS Resource Access Manager (RAM) shares subnets directly between accounts via resource shares, letting member accounts launch resources into the central VPC subnet. This satisfies the cross-account subnet sharing requirement without VPC peering or Transit Gateway, which cannot share subnets themselves.

Why this answer

AWS Resource Access Manager (RAM) is the correct service because it enables you to share a central VPC subnet from a management account with multiple member accounts in AWS Organizations without requiring VPC peering or transit gateways. With RAM, you create a resource share that includes the subnet and specify the member accounts or organizational units (OUs) to grant them access, allowing those accounts to launch resources directly into the shared subnet while maintaining centralized network management.

Exam trap

The trap here is that candidates often confuse VPC peering (which connects entire VPCs) with subnet sharing (which allows direct resource placement into a shared subnet), leading them to select VPC peering instead of AWS Resource Access Manager.

How to eliminate wrong answers

Option A (VPC peering connection) is wrong because VPC peering connects entire VPCs at the network layer using private IP addresses, but it does not allow you to share a subnet; it only enables routing between VPCs, and each account still needs its own subnet. Option C (AWS PrivateLink) is wrong because PrivateLink provides private connectivity to services via interface VPC endpoints powered by AWS PrivateLink, not for sharing subnets or VPC resources across accounts. Option D (Service control policy) is wrong because SCPs are used to manage permissions and enforce guardrails across accounts in AWS Organizations, not for sharing infrastructure resources like subnets.

135
MCQhard

A company has multiple VPCs across different AWS accounts and wants to establish private connectivity between them. They also need to centrally manage network traffic for security inspection. Which architecture should they use?

A.Create VPC peering connections between all VPCs and use security groups for inspection
B.Configure a VPN between each VPC and a central virtual appliance
C.Deploy an AWS Transit Gateway with a central inspection VPC that hosts security appliances, and configure route tables to route traffic through the inspection VPC
D.Use AWS Direct Connect to connect all VPCs to a common router
AnswerC

Transit Gateway acts as a regional hub, giving transitive routing between many VPCs and accounts without full-mesh peering. Attaching a central inspection VPC and steering route tables through it forces east-west traffic across the security appliances, meeting the centralised inspection requirement.

Why this answer

AWS Transit Gateway acts as a central hub to interconnect multiple VPCs across accounts, and by deploying a dedicated inspection VPC with security appliances (e.g., firewalls, IDS/IPS), you can centrally route all inter-VPC traffic through those appliances for security inspection. This is achieved by configuring Transit Gateway route tables to propagate routes from the inspection VPC and using static routes to force traffic through the inspection VPC's attachments, enabling granular traffic steering without complex peering meshes.

Exam trap

The trap here is that candidates often confuse VPC peering (which is simple but unscalable and lacks central inspection) with Transit Gateway, or they incorrectly assume that Direct Connect or VPNs are designed for inter-VPC connectivity rather than hybrid connectivity to on-premises.

How to eliminate wrong answers

Option A is wrong because VPC peering creates a full-mesh topology that does not scale beyond a few VPCs, and security groups cannot inspect traffic between VPCs (they are stateful firewalls at the instance/ENI level, not a central inspection point). Option B is wrong because configuring a VPN between each VPC and a central virtual appliance introduces bandwidth limitations, latency from encryption overhead, and operational complexity for routing and failover; it also does not leverage native AWS networking constructs for high availability. Option D is wrong because AWS Direct Connect provides dedicated physical connectivity to on-premises networks, not private connectivity between VPCs; it would require additional routing and does not inherently provide centralized traffic inspection.

136
MCQmedium

A company has multiple AWS accounts and wants to share a centrally managed Amazon VPC subnet for workloads that require low latency. The VPC is in the networking account. Which solution meets these requirements with the LEAST operational overhead?

A.Create a separate VPC in each account and connect them with VPC peering.
B.Use AWS Resource Access Manager (RAM) to share the subnet with the workload accounts.
C.Set up an AWS Transit Gateway and attach the VPCs from each account.
D.Create VPC peering connections between the networking account and each workload account.
AnswerB

AWS RAM shares the existing subnet in place, so workload accounts launch resources directly into it without duplicating VPCs or peering. This satisfies the low-latency requirement because resources remain in one subnet, and it minimises operational overhead since no additional networking infrastructure is provisioned or maintained.

Why this answer

AWS Resource Access Manager (RAM) allows you to share a subnet from a central VPC in the networking account with other AWS accounts without creating separate VPCs or complex networking. This enables workload accounts to launch resources directly into the shared subnet, achieving low latency by keeping them in the same VPC and Availability Zone. RAM handles the cross-account sharing with minimal operational overhead, as it does not require additional network appliances or routing configuration.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing Transit Gateway or VPC peering, thinking they need to interconnect VPCs, when the simplest and most cost-effective approach is to share the existing subnet directly using AWS RAM.

How to eliminate wrong answers

Option A is wrong because creating separate VPCs in each account and connecting them with VPC peering introduces additional complexity, does not share a single subnet, and VPC peering is not transitive, requiring full mesh connectivity for multiple accounts. Option C is wrong because AWS Transit Gateway adds operational overhead for managing attachments, route tables, and potentially higher costs, while the requirement is simply to share a subnet, not to interconnect multiple VPCs. Option D is wrong because VPC peering connections between the networking account and each workload account would require managing multiple peering connections and routing updates, and does not allow direct sharing of a subnet; resources would still be in separate VPCs, potentially increasing latency.

137
MCQeasy

A company is designing a network architecture for a multi-account AWS environment. They need to establish a central inspection VPC through which all traffic between VPCs in different accounts must pass. Which AWS service should be used to route traffic between VPCs through the inspection VPC?

A.AWS Direct Connect gateway
B.VPC peering with full mesh connectivity
C.Elastic Load Balancer
D.AWS Transit Gateway
AnswerD

AWS Transit Gateway acts as a regional hub, attaching VPCs across accounts and routing inter-VPC traffic through a central inspection VPC via route tables. This satisfies the requirement that all cross-account traffic pass through the inspection VPC.

Why this answer

AWS Transit Gateway (D) is the correct service because it acts as a central hub that can route traffic between multiple VPCs across different accounts, and it supports route tables that can force all inter-VPC traffic through a dedicated inspection VPC (e.g., using a blackhole route or a network appliance). This enables transitive routing without requiring full mesh peering, and it integrates with AWS Resource Access Manager (RAM) for cross-account sharing.

Exam trap

The trap here is that candidates often confuse VPC peering with transitive routing, assuming that a full mesh of peering connections can achieve the same centralized inspection as Transit Gateway, but VPC peering explicitly does not support transitive routing (per AWS documentation), making it impossible to force all traffic through a single inspection VPC without additional, unsupported workarounds.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect gateway is used to connect on-premises networks to AWS via Direct Connect, not for routing traffic between VPCs in different accounts. Option B is wrong because VPC peering with full mesh connectivity does not support transitive routing—each peering connection is a one-to-one relationship, so traffic cannot be forced through a central inspection VPC without complex, non-scalable configurations. Option C is wrong because Elastic Load Balancer is a traffic distribution service for applications, not a routing service for inter-VPC traffic; it cannot route packets between VPCs or enforce inspection paths.

138
Multi-Selectmedium

A company is designing a multi-account strategy using AWS Organizations. They want to enforce that no one can disable AWS CloudTrail in any account. Which TWO methods can achieve this?

Select 2 answers
A.Use AWS Trusted Advisor to alert when CloudTrail is disabled.
B.Attach a Service Control Policy (SCP) that denies disabling or deleting CloudTrail.
C.Use AWS Shield Advanced to protect CloudTrail.
D.Use AWS Config rules with auto-remediation to re-enable CloudTrail if disabled.
E.Use IAM permissions boundaries to restrict user permissions.
AnswersB, D

SCPs define the maximum permissions for principals in member accounts, so a deny statement for cloudtrail:StopLogging and DeleteTrail blocks the action at the Organizations level before IAM is evaluated, satisfying the requirement that no one in any account can disable CloudTrail.

Why this answer

Option B is correct because an SCP attached at the organization, OU, or account level in AWS Organizations can explicitly deny the CloudTrail actions that stop or delete a trail (for example cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail), which centrally prevents any principal in member accounts from disabling CloudTrail. Option D is correct because AWS Config can evaluate CloudTrail configuration with a managed rule such as cloudtrail-enabled and trigger automatic remediation (for example via SSM Automation) to re-enable logging if a trail is stopped or deleted, restoring the desired state. Option A is not correct because Trusted Advisor only provides advisory checks and alerts; it cannot enforce or prevent the disabling of CloudTrail.

Option C is not correct because AWS Shield Advanced is a DDoS protection service and has no role in controlling CloudTrail configuration. Option E is not correct because IAM permissions boundaries only limit the maximum permissions of an IAM entity and do not by themselves enforce organization-wide denial of CloudTrail changes across all accounts.

Exam trap

The trap here is that candidates often confuse IAM permissions boundaries or Trusted Advisor alerts as preventive controls, but only SCPs provide a true preventive guardrail that cannot be overridden by account administrators.

139
Multi-Selecthard

A company is using AWS Organizations with a centralized networking account that hosts a transit gateway. The company wants to ensure that all traffic between VPCs in different accounts flows through the transit gateway. Which THREE steps are required to implement this architecture?

Select 3 answers
A.Attach the VPCs in member accounts to the transit gateway.
B.Update the route tables of the VPCs to point to the transit gateway for inter-VPC traffic.
C.Create VPC endpoints for the transit gateway in each VPC.
D.Create VPC peering connections between each VPC and the networking VPC.
E.Share the transit gateway with the member accounts using AWS Resource Access Manager.
AnswersA, B, E

Transit gateway attachments are the prerequisite for any VPC to send traffic through it. Each member-account VPC must be attached, either directly or via shared attachment, before route tables can reference the gateway as a target for inter-VPC traffic.

Why this answer

Option A is correct because each VPC that must send traffic through the transit gateway needs a transit gateway attachment in its own account (or a shared attachment), which is created by attaching the VPC to the transit gateway. Option B is correct because the VPC route tables must contain routes that direct inter-VPC traffic (for example, the remote VPC CIDR) to the transit gateway attachment; without these routes, traffic will not be forwarded to the transit gateway. Option E is correct because AWS Resource Access Manager (RAM) is used to share the transit gateway from the centralized networking account with the member accounts, allowing those accounts to create attachments to the shared transit gateway.

Option C is incorrect because VPC endpoints are for private connectivity to AWS services or VPC endpoint services, not for routing traffic through a transit gateway. Option D is incorrect because VPC peering creates direct VPC-to-VPC connectivity that bypasses the transit gateway, which contradicts the requirement that all inter-VPC traffic flow through the transit gateway.

Exam trap

The trap here is that candidates often confuse VPC endpoints (used for AWS service access) with transit gateway attachments, or mistakenly think VPC peering is required when the transit gateway already provides the necessary connectivity.

140
MCQeasy

A company has a management account in AWS Organizations. It wants to delegate administration of AWS IAM Identity Center to a member account for user management. What is the correct way to achieve this?

A.Use AWS Resource Access Manager to share the IAM Identity Center instance with the member account.
B.Use the IAM Identity Center console to add the member account as a delegated administrator.
C.Use a service control policy to allow the member account to manage IAM Identity Center.
D.Create an IAM role in the management account and allow the member account to assume it.
AnswerB

IAM Identity Center supports delegated administration, letting the management account register a member account directly through the console. That member then manages users and permission sets without needing management account access, satisfying the delegation requirement natively.

Why this answer

AWS IAM Identity Center allows you to designate a member account as a delegated administrator directly from the IAM Identity Center console in the management account. This grants the member account the necessary permissions to manage users, groups, and permission sets without requiring cross-account roles or resource sharing.

Exam trap

The trap here is that candidates often confuse delegation with resource sharing via RAM or assume that SCPs can grant permissions, when in fact delegation is a specific AWS Organizations feature that must be configured through the IAM Identity Center console or API for that service.

How to eliminate wrong answers

Option A is wrong because AWS Resource Access Manager (RAM) is used to share resources like subnets or license configurations, not to delegate administrative control of IAM Identity Center; IAM Identity Center instances are not shareable via RAM. Option C is wrong because service control policies (SCPs) are used to restrict permissions across accounts in an organization, not to grant or delegate administrative capabilities; SCPs cannot enable a member account to manage IAM Identity Center. Option D is wrong because creating an IAM role in the management account for the member account to assume would provide access to the management account's IAM Identity Center configuration, but it does not delegate administration; the member account would still operate under the management account's context, not as a delegated administrator with its own management scope.

141
Multi-Selecthard

A company has an AWS Organizations environment with a management account, a central log archive account, and many workload accounts. The security team must prevent workload accounts from disabling AWS CloudTrail, deleting the central log bucket, or leaving the organization, while still allowing account administrators to manage their own resources. (Choose two.)

Select 2 answers
A.Enable AWS Config in every workload account and create a managed rule that flags noncompliant trails.
B.Enable Amazon GuardDuty in the management account to alert on attempts to disable logging.
C.Use IAM permissions boundaries on all roles in workload accounts to remove the ability to modify CloudTrail.
D.Create an S3 bucket policy on the central log bucket that denies s3:DeleteBucket and s3:DeleteObject to all principals except a tightly scoped log archive role.
E.Attach a service control policy to the workload OUs that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and organizations:LeaveOrganization.
AnswersD, E

A resource-based bucket policy on the central log bucket restricts destructive S3 actions to a specific role, so workload accounts cannot delete the bucket or its objects even if their identity policies allow S3 access. This complements the organization-level controls by protecting the log destination itself.

Why this answer

Preventive guardrails require controls that block actions rather than merely detect them. Service control policies applied to the workload OUs deny trail modification and organization departure for all principals in those accounts, while an S3 bucket policy protects the central log bucket from deletion. Together they enforce the security team's requirements without removing account administrators' ability to manage other resources.

Exam trap

The trap here is choosing detective controls such as AWS Config rules or GuardDuty findings when the requirement is to prevent the actions from succeeding.

142
MCQmedium

A company has a multi-account AWS environment with over 500 accounts. The security team uses AWS Config to evaluate resource compliance across all accounts. They have set up an AWS Config aggregator in the security account to collect configuration snapshots from all member accounts. Recently, the team noticed that some member accounts are not showing up in the aggregator. The accounts are active and have AWS Config enabled. What should the security team do to troubleshoot this issue?

A.Ensure that the member accounts have enabled AWS Config in the same region as the aggregator.
B.Check if the member accounts have exceeded the AWS Config resource limits.
C.Check if the AWS Config recorder in the member accounts is configured to record all resource types.
D.Verify that the AWS Config aggregator in the security account has the correct authorization to assume a role in each member account.
AnswerD

The aggregator needs a cross-account IAM role it can assume in every member account to read configuration data. If that role or its trust policy is missing or misconfigured, accounts silently fail to appear, so verify the authorisation first.

Why this answer

AWS Config aggregators require cross-account authorization to collect configuration data from member accounts. Even if AWS Config is enabled in member accounts, the aggregator in the security account must have the correct IAM role permissions (via an IAM role in each member account) to assume and retrieve configuration snapshots. Without this authorization, the aggregator cannot access the member accounts' data, causing them to not appear.

Exam trap

The trap here is that candidates assume enabling AWS Config in member accounts is sufficient, overlooking the critical cross-account authorization step required by the aggregator to pull data from those accounts.

How to eliminate wrong answers

Option A is wrong because AWS Config aggregators can collect data from multiple regions, and the issue is about accounts not showing up, not regions; the aggregator can aggregate across regions if configured correctly. Option B is wrong because exceeding AWS Config resource limits would cause errors or throttling, not a complete absence of accounts in the aggregator; the accounts are active and Config is enabled, so limits are not the likely cause. Option C is wrong because the AWS Config recorder configuration (recording all resource types or specific ones) affects what resources are recorded, not whether the account appears in the aggregator; the aggregator shows accounts regardless of the recorder's scope.

143
MCQmedium

A company has multiple AWS accounts and wants to centralize CloudTrail logs from all accounts into a single S3 bucket in the audit account. Which configuration is required?

A.Configure CloudWatch Events cross-account to forward logs to a central S3 bucket.
B.Create an organization trail in the management account that delivers logs to the central S3 bucket in the audit account, and set the bucket policy to allow CloudTrail from the organization.
C.Use AWS Organizations to automatically create a CloudTrail trail in the management account that logs all accounts.
D.Create a CloudTrail trail in each account that delivers logs to the central S3 bucket, with a bucket policy that grants write access to each account's CloudTrail service.
AnswerB

An organisation trail created in the management account automatically applies to every account in AWS Organizations and delivers events to the specified S3 bucket. The bucket policy must permit CloudTrail from the organisation so the audit account accepts logs, satisfying the centralised-logging requirement.

Why this answer

AWS Organizations allows you to create an organization trail in the management account that automatically applies to all accounts in the organization. By configuring the trail to deliver logs to a central S3 bucket in the audit account, and setting the bucket policy to grant CloudTrail service access from the organization, you centralize logging without needing per-account trails. This approach ensures that new accounts added to the organization are automatically covered.

Exam trap

The trap here is that candidates often assume they must create individual trails per account (Option D) or use CloudWatch Events (Option A), missing the simpler and more robust organization trail feature that automatically covers all accounts in the organization.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events cross-account forwarding is not designed to aggregate CloudTrail logs into S3; it forwards events to targets like Lambda or SQS, not directly to S3, and would require custom processing. Option C is wrong because AWS Organizations does not automatically create a CloudTrail trail; you must explicitly create an organization trail in the management account. Option D is wrong because while it could work technically, it is not the simplest or most scalable solution; it requires configuring a trail in every account and managing individual bucket policies, which does not leverage the organizational trail feature that automatically includes all accounts.

144
MCQeasy

A solutions architect needs to design a network architecture for a multi-account AWS environment using AWS Transit Gateway. The company requires that all traffic between VPCs be inspected by a central security appliance. What is the MOST efficient way to achieve this?

A.Use AWS Direct Connect to connect all VPCs to a central on-premises firewall.
B.Use a Network Load Balancer in each VPC to forward traffic to a firewall instance.
C.Attach all VPCs to a Transit Gateway and route traffic through a central inspection VPC.
D.Create VPC peering connections between all VPCs and route traffic through a security VPC.
AnswerC

Attaching every VPC to the Transit Gateway and steering inter-VPC traffic through a central inspection VPC satisfies the mandated inspection constraint using native Transit Gateway route table segmentation. Appliance VPC attachments and separate route tables force all spokes through the security stack, avoiding complex peering meshes or per-VPC firewall deployments.

Why this answer

AWS Transit Gateway enables a hub-and-spoke architecture where all VPCs attach to a central Transit Gateway, and a dedicated inspection VPC (with the security appliance) acts as the central inspection point. By configuring route tables in the Transit Gateway to route all inter-VPC traffic through the inspection VPC, you achieve mandatory traffic inspection without complex peering or performance bottlenecks.

Exam trap

The trap here is that candidates may assume VPC peering is simpler or more direct, but they overlook that VPC peering lacks transitive routing, making it impossible to force all inter-VPC traffic through a single inspection point without a full mesh and complex routing.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection to on-premises, not a mechanism to connect VPCs to each other or to a central firewall; it would introduce unnecessary latency and dependency on on-premises infrastructure for VPC-to-VPC traffic. Option B is wrong because a Network Load Balancer (NLB) operates at Layer 4 and cannot inspect or forward traffic for security purposes; it is designed for load balancing, not traffic inspection or routing. Option D is wrong because VPC peering does not support transitive routing, so you would need a full mesh of peering connections (which does not scale) and still cannot force all traffic through a central inspection VPC without complex routing and additional appliances.

145
MCQhard

A company has a multi-account strategy with a dedicated audit account. The audit account needs to have read-only access to all resources in all other accounts. The security team wants to use IAM roles. What is the MOST scalable way to set up this cross-account access?

A.Use AWS Single Sign-On (SSO) to grant the audit team access to each account.
B.Create an IAM user in the audit account and allow that user to assume a role in each account.
C.Manually create an IAM role in each account and attach a read-only policy.
D.Use AWS CloudFormation StackSets to deploy a stack containing an IAM role with the required trust and permissions.
AnswerD

CloudFormation StackSets deploy the IAM role with its trust policy and read-only permissions to every account simultaneously, satisfying the scalable cross-account access requirement. The audit account assumes the role in each target account, avoiding per-account manual role creation.

Why this answer

AWS CloudFormation StackSets allows you to deploy a consistent IAM role with a read-only policy and a trust policy that grants the audit account access across all target accounts in a single, automated, and scalable operation. This approach eliminates manual effort, ensures consistency, and scales to hundreds of accounts without requiring per-account configuration.

Exam trap

The trap here is that candidates often choose manual role creation (Option C) because it seems straightforward, but they overlook the scalability and automation benefits of StackSets, which is the most efficient solution for managing cross-account roles across many accounts in a multi-account strategy.

How to eliminate wrong answers

Option A is wrong because AWS Single Sign-On (SSO) is designed for federated user access to the AWS Management Console and does not provide a mechanism to grant programmatic cross-account IAM role access for a dedicated audit account; it also does not natively enforce read-only permissions across all resources. Option B is wrong because creating an IAM user in the audit account and allowing that user to assume roles in each account is not scalable—it requires manual creation of roles and trust policies in every account, and IAM users are a security anti-pattern for cross-account access compared to role-based access. Option C is wrong because manually creating an IAM role in each account with a read-only policy is not scalable for a multi-account environment with many accounts; it introduces human error, inconsistency, and operational overhead.

146
MCQhard

Refer to the exhibit. A solutions architect is troubleshooting why EC2 instances launched in subnet-11111111 cannot access the internet. The subnet is in a VPC with an internet gateway attached. The route table for the subnet has a default route (0.0.0.0/0) pointing to the internet gateway. What is the MOST likely cause?

A.The subnet's auto-assign public IP setting is disabled
B.The internet gateway is not attached to the VPC
C.The subnet needs a NAT gateway for internet access
D.The subnet's route table does not have a route to the internet gateway
AnswerA

A subnet with a default route to an internet gateway still requires each instance to hold a public IPv4 address or elastic IP for NAT to occur. With auto-assign public IP disabled, instances receive only private addresses, so the internet gateway drops their traffic, satisfying the stem's connectivity failure.

Why this answer

The most likely cause is that the subnet's auto-assign public IP setting is disabled. Even though the subnet has a default route (0.0.0.0/0) pointing to an internet gateway, EC2 instances launched in that subnet will not receive a public IP address automatically unless the subnet's 'Auto-assign public IPv4 address' setting is enabled. Without a public IP (or an Elastic IP), the instance cannot communicate with the internet through the internet gateway, as the internet gateway requires a public IP for return traffic routing.

Exam trap

The trap here is that candidates often assume a route to an internet gateway is sufficient for internet access, overlooking the requirement that the instance must have a public IP address for the internet gateway to route traffic correctly.

How to eliminate wrong answers

Option B is wrong because the question explicitly states the VPC has an internet gateway attached, so this is not the issue. Option C is wrong because a NAT gateway is only needed for private subnets to access the internet; this subnet has a route to an internet gateway, indicating it is intended to be a public subnet, and a NAT gateway would not solve the lack of a public IP. Option D is wrong because the question states the route table for the subnet has a default route (0.0.0.0/0) pointing to the internet gateway, so the route is present.

147
MCQeasy

A company is adopting AWS Organizations and wants a baseline set of IAM roles, a standard VPC, and a security agent deployed automatically into every new account the moment it is created. The operations team does not want to run scripts manually after each account creation. Which AWS service should they use to meet this requirement?

A.AWS Control Tower Account Factory for Terraform pipelines triggered per account.
B.AWS CloudFormation StackSets with automatic deployment enabled for the organization.
C.AWS Service Catalog portfolios shared with each organizational unit.
D.AWS Config conformance packs applied at the organization level.
AnswerB

StackSets deploy a CloudFormation template to many accounts and Regions from a single administration account, and with automatic deployment enabled, new accounts joining the organization receive the baseline stacks without manual intervention. It is the standard mechanism for provisioning consistent resources such as roles, VPCs, and agents across an organization.

Why this answer

AWS CloudFormation StackSets is designed for multi-account, multi-Region provisioning from a central administrator account. Enabling automatic deployment ties stack deployment to organization membership, so each newly created account automatically receives the baseline IAM roles, VPC, and security agent. This removes the need for manual or scripted post-creation steps.

Exam trap

The trap here is assuming AWS Config conformance packs or Service Catalog deploy resources, when they only evaluate compliance or offer on-demand products.

148
MCQeasy

A company wants to implement a data lake on AWS with data from multiple sources. They need to store data in its raw format and allow multiple teams to query it using different tools. Which service should be used as the central storage layer?

A.Amazon DynamoDB
B.Amazon Redshift
C.Amazon S3
D.Amazon RDS
AnswerC

Amazon S3 provides durable, schema-on-read object storage that keeps data in its native raw format, satisfying the requirement to preserve source fidelity. Its decoupling from compute lets Athena, Redshift Spectrum and EMR query the same objects independently, which no single-purpose analytics engine allows.

Why this answer

Amazon S3 is the correct choice because it provides a highly durable, scalable, and cost-effective object storage service that can store data in its raw, native format (e.g., CSV, JSON, Parquet, images). It supports multiple query engines like Amazon Athena, Amazon Redshift Spectrum, and AWS Glue, allowing diverse teams to query the same data using different tools without data movement.

Exam trap

The trap here is that candidates often confuse a data lake's raw storage layer with a data warehouse (Redshift) or a transactional database (RDS, DynamoDB), failing to recognize that a data lake requires schema-on-read, object storage, and multi-engine query support, which only S3 provides.

How to eliminate wrong answers

Option A is wrong because Amazon DynamoDB is a NoSQL key-value and document database designed for low-latency, transactional workloads, not for storing raw, schema-less data lake files or supporting SQL-based analytics at scale. Option B is wrong because Amazon Redshift is a petabyte-scale data warehouse that requires data to be loaded and transformed into a structured, columnar format; it is not designed to store raw, unprocessed data from multiple sources. Option D is wrong because Amazon RDS is a relational database service that enforces a fixed schema and is optimized for OLTP workloads, making it unsuitable for storing diverse raw data formats and supporting ad-hoc queries from multiple analytics tools.

149
MCQhard

A financial services company uses AWS Organizations with a central networking account. Workload accounts need to reach an on-premises data center over AWS Site-to-Site VPN, and the network team wants to enforce that all inter-VPC traffic flows through a central inspection VPC. Which combination of components should the network team deploy to route traffic through the inspection VPC while keeping the architecture scalable?

A.Create a VPC peering mesh between all workload VPCs and the inspection VPC, and attach a virtual private gateway to each workload VPC.
B.Use AWS PrivateLink endpoints in each workload VPC to reach the inspection VPC, and route on-premises traffic through the endpoints.
C.Create a transit gateway in each workload account and peer the transit gateways together, then attach the VPN to one of them.
D.Use AWS Transit Gateway with a central transit gateway in the networking account, attach the inspection VPC and workload VPCs to it, and use a separate route table per segment with the inspection VPC as the next hop.
AnswerD

A central transit gateway provides hub-and-spoke connectivity with transitive routing, and separate transit gateway route tables let the network team force traffic through the inspection VPC. Attaching the VPN to the transit gateway keeps on-premises access centralized while scaling to many workload accounts without per-pair peering.

Why this answer

A single central AWS Transit Gateway in the networking account, with workload VPC attachments and segment-specific route tables pointing to the inspection VPC, delivers scalable hub-and-spoke routing and centralized inspection. Attaching the Site-to-Site VPN to the same transit gateway keeps on-premises traffic in the same controlled path and avoids per-account VPN or peering sprawl.

Exam trap

The trap here is reaching for VPC peering or PrivateLink for general inter-VPC and on-premises routing when only a transit gateway provides transitive, centrally governed connectivity.

150
MCQmedium

A company uses AWS Organizations and wants to delegate administration of AWS IAM Identity Center (successor to AWS SSO) to a member account. Which step is required to set this up?

A.Use the management account to designate the member account as a delegated administrator for IAM Identity Center.
B.Enable AWS Organizations and create an admin role in the member account.
C.Create a new OU for the delegated administrator account.
D.Attach an SCP to allow IAM Identity Center actions in the member account.
AnswerA

Delegating IAM Identity Center administration requires the management account to register a member account as delegated administrator, which then gains administrative control over Identity Center. Without this organisation-level designation, the member account cannot manage Identity Center centrally.

Why this answer

To delegate administration of IAM Identity Center to a member account, you must use the AWS Organizations management account to register that member account as a delegated administrator for IAM Identity Center. This is done via the AWS Organizations console or API (RegisterDelegatedAdministrator), which grants the member account the necessary permissions to manage IAM Identity Center settings, users, and groups without requiring full management account access. Only the management account can designate delegated administrators, and this action is specific to IAM Identity Center within AWS Organizations.

Exam trap

The trap here is that candidates often confuse generic cross-account role delegation (like creating an IAM role in a member account) with the specific AWS Organizations delegated administrator feature, which requires explicit registration from the management account and is not achieved by simply creating roles or policies.

How to eliminate wrong answers

Option B is wrong because enabling AWS Organizations and creating an admin role in the member account is a generic step for cross-account access, but it does not specifically delegate IAM Identity Center administration; delegated administration requires explicit registration via the management account, not just role creation. Option C is wrong because creating a new OU for the delegated administrator account is not required; delegated administrators can be any member account in any OU, and OUs are for organizational structure and policy application, not for enabling delegation. Option D is wrong because attaching an SCP to allow IAM Identity Center actions in the member account is unnecessary and incorrect; SCPs are used to restrict permissions, not to grant them, and delegation is controlled by the management account's registration, not by SCPs.

← PreviousPage 2 of 3 · 200 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design Solutions for Organizational Complexity questions.