Courseiva

CCNA Design Solutions for Organizational Complexity Questions

50 of 200 questions · Page 3/3 · Design Solutions for Organizational Complexity · Answers revealed

151
MCQmedium

A company has an AWS Organizations structure with a management account and 40 member accounts grouped into four OUs. The security team wants a single AWS account to receive all Amazon GuardDuty findings from every account and to view them in one place. They also need new accounts created under any OU to be automatically enrolled. Which solution meets these requirements with the LEAST operational overhead?

A.Designate a delegated administrator for GuardDuty in AWS Organizations and enable GuardDuty with auto-enable for all existing and new member accounts.
B.Create an organization trail in AWS CloudTrail and use CloudTrail Lake to query GuardDuty findings across all accounts.
C.Enable GuardDuty in each member account and create an Amazon EventBridge rule in each account that forwards findings to a central Amazon SNS topic.
D.Enable GuardDuty only in the management account and use AWS Resource Access Manager to share the detector with all member accounts.
AnswerA

GuardDuty integrates natively with AWS Organizations. Designating a delegated administrator lets that account manage GuardDuty across the organization, and auto-enable ensures every current and future member account is protected and its findings are aggregated in the delegated administrator account with no per-account scripting.

Why this answer

GuardDuty's native AWS Organizations integration is the intended mechanism for multi-account security monitoring. A delegated administrator account manages the service centrally, and auto-enable covers both existing accounts and accounts created later under any OU. This avoids building and maintaining per-account EventBridge and SNS forwarding pipelines while still delivering a consolidated findings view.

Exam trap

The trap here is assuming GuardDuty detectors can be shared across accounts with AWS Resource Access Manager instead of using the built-in Organizations delegated administrator and auto-enable features.

152
MCQmedium

A multinational corporation is deploying a multi-account AWS environment using AWS Organizations. The security team requires that all S3 buckets across all accounts be encrypted with a specific AWS KMS key managed by the security account. Which solution should the company implement to enforce this policy across the organization?

A.Create IAM policies in each account to enforce encryption
B.Attach a service control policy (SCP) to the root that denies S3 actions unless encryption conditions are met
C.Use AWS Config rules with auto-remediation in each account
D.Deploy a CloudFormation StackSet that creates S3 buckets with encryption
AnswerB

SCPs attached at the organisation root define the maximum permissions for every account, so a deny on S3 actions lacking the required KMS encryption condition blocks non-compliant bucket creation and uploads organisation-wide. This enforces the mandated key across all accounts without per-account policy management.

Why this answer

A service control policy (SCP) attached to the root of the AWS Organizations hierarchy can deny S3 PutObject or CreateBucket actions unless the request includes the specific KMS key ID (via the s3:x-amz-server-side-encryption-aws-kms-key-id condition key). This enforces encryption centrally across all accounts, as SCPs are inherited by all member accounts and cannot be overridden by IAM policies within those accounts.

Exam trap

The trap here is that candidates often choose AWS Config rules (Option C) thinking they provide preventive enforcement, but Config rules are detective and reactive, not preventive, whereas SCPs proactively block non-compliant API calls before the resource is created.

How to eliminate wrong answers

Option A is wrong because IAM policies in each account can be modified or bypassed by account administrators, and they do not provide centralized enforcement across the organization. Option C is wrong because AWS Config rules with auto-remediation are reactive (detect and fix non-compliant resources after creation) and do not prevent the initial creation of unencrypted buckets, plus they require per-account setup. Option D is wrong because a CloudFormation StackSet only creates buckets with encryption at deployment time but does not prevent users from creating unencrypted buckets outside of the StackSet, nor does it enforce encryption on existing or future buckets.

153
MCQeasy

A company has multiple AWS accounts and wants to centrally manage CloudWatch dashboards. Which solution should they use?

A.Use CloudWatch cross-account dashboards with a monitoring account.
B.Use AWS Config aggregator to view resources.
C.Use Amazon QuickSight with data sources from each account.
D.Use AWS CloudFormation StackSets to deploy dashboards in each account.
AnswerA

CloudWatch cross-account dashboards let a monitoring account display metrics from source accounts without duplicating resources, satisfying the centralised management requirement across multiple AWS accounts. Source accounts share data via CloudWatch cross-account observability, so dashboards remain unified while each account retains ownership of its own metrics.

Why this answer

CloudWatch cross-account dashboards allow you to create a single dashboard in a central monitoring account that displays metrics from multiple source accounts. This is the native AWS solution for centralized observability, requiring no additional data movement or custom code. The monitoring account uses the CloudWatch cross-account functionality to query metrics across accounts via IAM roles and the CloudWatch API.

Exam trap

The trap here is that candidates confuse AWS Config aggregator (which aggregates configuration data) with CloudWatch cross-account dashboards (which aggregate metric data), or assume CloudFormation StackSets provide a central view when they only replicate resources per account.

How to eliminate wrong answers

Option B is wrong because AWS Config aggregator is designed to aggregate resource configuration and compliance data, not CloudWatch metrics or dashboards; it cannot display time-series metric graphs. Option C is wrong because Amazon QuickSight is a business intelligence service for interactive dashboards and analytics, not a native CloudWatch dashboard viewer; it would require custom data pipelines to extract CloudWatch metrics into SPICE or S3, adding unnecessary complexity. Option D is wrong because AWS CloudFormation StackSets can deploy dashboard definitions across accounts, but each dashboard remains isolated in its own account; there is no central view or cross-account query capability, defeating the purpose of centralized management.

154
MCQmedium

A company is using AWS Organizations with a hierarchical OU structure. The security team wants to enforce that any new account created in the organization automatically inherits a baseline set of AWS Config rules and a VPC with a default CIDR block. What is the MOST efficient way to achieve this?

A.Use AWS CloudFormation StackSets with a stack that creates the VPC and Config rules, and trigger it via an SCP.
B.Create an SCP that denies creation of resources unless they comply with the baseline.
C.Enable AWS Control Tower and configure Account Factory to provision accounts with a baseline blueprint containing the VPC and Config rules.
D.Use AWS Config conformance packs with YAML templates deployed to all accounts via an SCP.
AnswerC

Control Tower Account Factory provisions new accounts through a baseline blueprint, automatically applying the VPC with the specified CIDR and the Config rules. This satisfies automatic inheritance for every new account without custom orchestration per account.

Why this answer

AWS Control Tower provides a managed service that automates the setup of a multi-account environment based on AWS best practices. By enabling Control Tower and configuring Account Factory, new accounts are automatically provisioned with a baseline blueprint that includes the desired VPC and AWS Config rules, ensuring consistent governance without manual intervention or custom orchestration.

Exam trap

The trap here is that candidates often confuse SCPs with automation tools, thinking they can enforce resource creation or trigger deployments, when in reality SCPs only restrict permissions and cannot provision resources or invoke AWS services.

How to eliminate wrong answers

Option A is wrong because SCPs cannot trigger AWS CloudFormation StackSets; SCPs are permission policies that control which AWS API actions are allowed, not event-driven automation triggers. Option B is wrong because an SCP that denies creation of resources unless they comply with a baseline would be impractical to enforce at the point of account creation and does not proactively create the required VPC and Config rules. Option D is wrong because AWS Config conformance packs are deployed to existing accounts to evaluate compliance, not to provision resources like a VPC, and SCPs cannot deploy conformance packs.

155
MCQmedium

A financial services company uses AWS Organizations with 60 accounts. The security team has enabled AWS CloudTrail organization trails in the management account and wants to prevent any member account administrator from disabling CloudTrail logging in their own account. Which solution will meet this requirement with the LEAST operational overhead?

A.Create an AWS CloudFormation StackSet that deploys a CloudTrail trail in every account and configure drift detection to alert when the trail is modified.
B.Create a service control policy in AWS Organizations that denies the cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail actions for all member accounts.
C.Configure an IAM permissions boundary on every IAM role in each member account that excludes the cloudtrail:StopLogging and cloudtrail:DeleteTrail actions.
D.Use AWS Config with a managed rule that detects when a CloudTrail trail is not logging, and trigger an AWS Lambda function to restart logging when the rule is noncompliant.
AnswerB

SCPs set the maximum permissions for accounts in an organization. Denying the actions that stop or delete a trail prevents member account administrators from disabling CloudTrail logging, and because SCPs apply organization-wide, no per-account scripting is required, meeting the least operational overhead requirement.

Why this answer

A service control policy in AWS Organizations denies the CloudTrail actions that stop, delete, or modify a trail, so member account administrators cannot disable logging even if their IAM policies allow those actions. Because SCPs apply at the organization level to all accounts, this is preventive and requires no per-account resources, satisfying both the security and least-overhead requirements.

Exam trap

The trap here is assuming that deploying a trail in each account or using detective controls such as AWS Config is enough, when only an organization-level service control policy can prevent member administrators from stopping logging.

156
MCQmedium

A media company has 200 AWS accounts in AWS Organizations. The networking team wants to provide each account with a shared VPC subnet from a central networking account. The central networking account owns the VPC and subnets. Workload accounts must be able to launch resources into the shared subnets, but they must not be able to modify the subnet configuration or delete the shared subnets. Which solution meets these requirements?

A.Create a VPC peering connection from each workload VPC to the central VPC, and grant each workload account IAM permissions to create subnets in the central VPC.
B.Use AWS Transit Gateway to attach each workload VPC to the central VPC, and create a route table entry that allows workloads to use the central subnets.
C.Create an AWS Direct Connect connection between each workload account and the central networking account, and configure a private virtual interface for subnet access.
D.Use AWS Resource Access Manager to share the subnets from the networking account to the organization, and attach a service control policy to workload accounts denying ec2:ModifySubnetAttribute and ec2:DeleteSubnet.
AnswerD

AWS RAM is the supported way to share VPC subnets across accounts in an organization. The participant accounts can launch resources into shared subnets but do not own the subnet. Adding a service control policy that denies subnet modification and deletion actions enforces the restriction that workload accounts cannot alter or remove the shared subnets, meeting both requirements.

Why this answer

Sharing subnets from a central VPC is done with AWS Resource Access Manager, which lets participant accounts launch resources into shared subnets while the owner retains control. To prevent participants from modifying or deleting the shared subnets, a service control policy denies the relevant EC2 subnet actions. Together these meet the requirements for shared use with owner-controlled configuration.

Exam trap

The trap here is assuming VPC peering or Transit Gateway grants subnet usage, when only AWS RAM shares subnets and only a service control policy prevents modification.

157
MCQeasy

A company needs to share a central Amazon S3 bucket containing common data files with multiple accounts in AWS Organizations. Which approach is most secure and scalable?

A.Make the bucket public with read-only access.
B.Generate presigned URLs for each account to access the bucket.
C.Create IAM roles in each account with permissions to assume a role in the central account.
D.Use an S3 bucket policy that grants access to the organization using aws:PrincipalOrgID condition key.
AnswerD

The aws:PrincipalOrgID condition restricts the bucket policy to principals belonging to the specified organisation, so any current or future member account gains access without editing the policy. This scales automatically as accounts are added and avoids wildcard principal exposure.

Why this answer

Using the `aws:PrincipalOrgID` condition key in an S3 bucket policy allows you to grant access to all principals (users, roles) within your AWS Organization without needing to list individual account IDs. This approach is both secure (no public access) and scalable (automatically includes new accounts added to the organization).

Exam trap

The trap here is that candidates often choose Option C (cross-account IAM roles) because it is a familiar pattern, but they overlook the simpler and more scalable centralized policy approach using the Organization ID condition key, which AWS specifically tests for centralized resource sharing scenarios.

How to eliminate wrong answers

Option A is wrong because making the bucket public with read-only access violates the principle of least privilege and exposes the data to any internet user, not just the intended accounts. Option B is wrong because presigned URLs are temporary and require manual generation and distribution for each account, which is not scalable for multiple accounts and does not provide a persistent, policy-based access control mechanism. Option C is wrong because creating IAM roles in each account with permissions to assume a role in the central account introduces cross-account trust complexity and requires managing role ARNs for every account, whereas the Organization ID condition key provides a simpler, centralized policy.

158
MCQhard

A company uses AWS Organizations with 50 accounts. The network team wants to centrally manage VPC flow logs for all accounts, storing them in a central S3 bucket in the security account. The flow logs must be encrypted with a KMS key managed by the security account. What is the MOST efficient way to configure this?

A.Manually create VPC flow logs in each account and point to the central S3 bucket
B.Use AWS CloudFormation StackSets to deploy a stack that creates VPC flow logs with the required configuration in all accounts
C.Use AWS Config rules to enforce flow log creation across accounts
D.Use AWS Systems Manager Automation to create flow logs in each account
AnswerB

CloudFormation StackSets deploys the flow-log stack across every organisation account in one operation, including the security-account KMS key ARN and central bucket destination. This satisfies the efficiency constraint by avoiding manual per-account configuration across 50 accounts.

Why this answer

AWS CloudFormation StackSets allows you to deploy a single CloudFormation template across multiple accounts and regions in an AWS Organization. By defining the VPC flow log resource with the central S3 bucket ARN and the KMS key from the security account (using a cross-account KMS key policy), StackSets can automatically create flow logs in all member accounts with the required encryption, making it the most efficient and centralized approach.

Exam trap

The trap here is that candidates often choose AWS Config rules (Option C) thinking they can enforce resource creation, but Config is a detective control, not a provisioning tool, and cannot directly create flow logs without additional automation.

How to eliminate wrong answers

Option A is wrong because manually creating VPC flow logs in each account is not scalable, error-prone, and violates the principle of central management for 50 accounts. Option C is wrong because AWS Config rules can only detect non-compliance (e.g., missing flow logs) and trigger remediation actions, but they cannot directly create or manage the flow log resources themselves; they rely on other services like AWS Systems Manager or Lambda for remediation, adding complexity. Option D is wrong because AWS Systems Manager Automation is designed for operational tasks on EC2 instances or on-premises machines, not for creating VPC flow logs across accounts; it lacks the native multi-account deployment capability that StackSets provides.

159
MCQeasy

A company has a central IT team that manages multiple AWS accounts. The team wants to allow developers to create resources in their own accounts but wants to restrict the use of certain expensive services like Amazon Redshift. The developers should not be able to launch Redshift clusters in any account. What is the MOST efficient way to achieve this?

A.Apply an SCP that denies redshift:CreateCluster to the organizational unit containing the developer accounts.
B.Use AWS CloudTrail to monitor cluster creation and alert the security team.
C.Create an IAM policy that denies redshift:CreateCluster and attach it to the developers' IAM groups in each account.
D.Use AWS Config rules to detect Redshift cluster creation and automatically delete them.
AnswerA

An SCP denying redshift:CreateCluster at the OU level applies to every principal in every member account, so developers cannot launch clusters regardless of their IAM permissions, meeting the organisation-wide restriction with one policy rather than per-account edits.

Why this answer

Service Control Policies (SCPs) in AWS Organizations are the most efficient way to enforce guardrails across multiple accounts. Applying an SCP that denies redshift:CreateCluster to the organizational unit containing developer accounts prevents any principal in those accounts from launching Redshift clusters, regardless of their IAM permissions. This is a centralized, preventive control that scales across all accounts in the OU.

Exam trap

SAP-C02 often tests the difference between preventive controls (SCPs) and detective controls (CloudTrail, Config)—candidates pick monitoring or remediation options because they sound operationally safe, but the question asks for the most efficient way to prevent the action.

How to eliminate wrong answers

Option B is wrong because CloudTrail only monitors and logs API activity—it is detective, not preventive, and does not stop cluster creation. Option C is wrong because attaching an IAM policy to each account's developer groups is decentralized and must be repeated per account, making it less efficient and prone to drift. Option D is wrong because AWS Config rules are detective and reactive; they can trigger remediation but do not prevent the initial creation, and auto-deletion is disruptive.

160
Multi-Selecteasy

A global e-commerce company is migrating its on-premises application to AWS. The application uses Active Directory for authentication and requires integration with AWS Managed Microsoft AD. The company has a multi-account strategy using AWS Organizations. Which TWO steps should the solutions architect take to ensure seamless authentication across the organization?

Select 2 answers
A.Configure an IAM identity provider to use the on-premises Active Directory.
B.Establish a two-way forest trust between the on-premises Active Directory and AWS Managed Microsoft AD.
C.Store AD credentials in AWS Systems Manager Parameter Store and retrieve them at runtime.
D.Use AWS Resource Access Manager to share the AWS Managed Microsoft AD directory with other accounts in the organization.
E.Deploy AWS Managed Microsoft AD in each account and configure replication.
AnswersB, D

This enables users to authenticate with their existing credentials.

Why this answer

Establishing a two-way forest trust between on-premises Active Directory and AWS Managed Microsoft AD allows users authenticated by the on-premises AD to access resources in the AWS cloud without needing separate credentials. This trust enables Kerberos and NTLM authentication to flow seamlessly between the two forests, supporting the company's requirement for integration with AWS Managed Microsoft AD.

Exam trap

The trap here is that candidates often confuse IAM identity providers (Option A) with Active Directory trust relationships, or they incorrectly assume that storing credentials in Parameter Store (Option C) is a valid authentication strategy for directory integration, when in fact the correct approach is to establish a forest trust and share the directory via RAM.

161
Multi-Selectmedium

A company is designing a multi-account strategy for its AWS environment. Which TWO considerations are important when using AWS Organizations?

Select 2 answers
A.Service control policies (SCPs) apply to all accounts in the organization, including the management account.
B.AWS CloudTrail can be enabled for all accounts from the management account using an organization trail.
C.Each account in an organization must have its own payment method.
D.Consolidated billing allows you to combine usage and receive volume discounts.
E.AWS Config rules cannot be applied across accounts via AWS Organizations.
AnswersB, D

An organisation trail created in the management account automatically applies to every member account, including accounts added later, and delivers events to a central bucket. This satisfies the multi-account consideration that activity logging be consistent and centrally governed rather than configured per account.

Why this answer

Option B is correct because AWS Organizations lets the management account create an organization trail in AWS CloudTrail that automatically applies to all member accounts, providing centralized logging of API activity across the organization. Option D is correct because consolidated billing aggregates usage from all member accounts into a single bill paid by the management account, and this combined usage can qualify for volume pricing discounts on services like S3 and data transfer. Option A is incorrect because SCPs do not apply to the management account; they only affect member accounts (and the management account is exempt to prevent lockout).

Option C is incorrect because AWS Organizations uses consolidated billing, so member accounts do not each need their own payment method—the management account pays the single bill. Option E is incorrect because AWS Config supports organization-wide rules and conformance packs deployed from the management account across member accounts via AWS Organizations.

Exam trap

The trap here is that candidates often assume SCPs apply to all accounts including the management account, but AWS explicitly excludes the management account from SCP effects to prevent accidental lockout of administrative access.

162
MCQhard

A large financial services company uses AWS Organizations with over 200 accounts. The security team has implemented a Service Control Policy (SCP) that denies access to all services except a whitelist that includes Amazon S3, Amazon DynamoDB, AWS Lambda, and Amazon CloudWatch. Recently, the DevOps team reported that they cannot create new EC2 instances in their development account, even though the administrator explicitly attached an IAM policy allowing ec2:RunInstances. The SCP does not explicitly deny EC2. What is the most likely cause of this issue?

A.The IAM role used by the DevOps team has a trust policy that does not allow EC2 actions
B.The EC2 service has been disabled via AWS Config in that account
C.The development account is in an organizational unit (OU) with a different SCP that denies EC2
D.The SCP denies all services not explicitly allowed, and EC2 is not on the whitelist
AnswerD

The SCP uses a whitelist model: its default is implicit denial of every service not named. Because EC2 is absent from the allowed list, ec2:RunInstances is blocked regardless of the attached IAM policy, since SCPs cap effective permissions.

Why this answer

The SCP uses a deny-all approach with a whitelist of allowed services. Since EC2 is not on that whitelist, the SCP implicitly denies all EC2 actions, overriding any IAM policy that explicitly allows ec2:RunInstances. SCPs act as a guardrail that cannot be bypassed by account-level IAM policies.

Exam trap

The trap here is that candidates may think an explicit IAM allow can override an SCP, but SCPs set the maximum permissions boundary, so any action not explicitly allowed by the SCP is implicitly denied.

How to eliminate wrong answers

Option A is wrong because a trust policy controls which principals can assume a role, not the actions the role can perform; the issue is about authorization, not trust. Option B is wrong because AWS Config is a compliance and monitoring service, not a service control mechanism that can disable EC2; it cannot prevent API calls. Option C is wrong because the question states the SCP does not explicitly deny EC2, and the SCP described is the only one mentioned; while an OU-level SCP could cause this, the most direct and likely cause given the whitelist design is that EC2 is simply not allowed.

163
MCQeasy

A company uses AWS Organizations with multiple OUs. The DevOps team needs to allow developers to launch EC2 instances only of type t3.micro in the dev OU. Which action should the team take?

A.Create an IAM role with a policy that allows only t3.micro, and attach it to users in the dev OU.
B.Use AWS CloudFormation templates that specify t3.micro.
C.Apply a Service Control Policy (SCP) to the dev OU that denies ec2:RunInstances with instance type not equal to t3.micro.
D.Use AWS Config rules to terminate non-compliant instances.
AnswerC

SCPs define the maximum available permissions for principals in member accounts and apply at the OU level, so attaching this policy to the dev OU blocks RunInstances for any instance type other than t3.micro across every account beneath it, satisfying the OU-wide restriction without per-account IAM edits.

Why this answer

A Service Control Policy (SCP) applied to the dev OU can centrally restrict which EC2 instance types can be launched by all accounts within that OU. The SCP uses a Deny effect with a condition key ec2:InstanceType not equal to t3.micro, which prevents any IAM principal in the OU from launching non-compliant instances, regardless of their IAM permissions. This is the most effective way to enforce a hard boundary at the organization level.

Exam trap

The trap here is that candidates often choose AWS Config rules (Option D) thinking they can prevent launches, but Config is detective, not preventive; SCPs are the correct preventive control at the organization level.

How to eliminate wrong answers

Option A is wrong because an IAM role attached to users does not apply to all principals in the OU; users could still launch instances via other roles or services, and the role does not enforce the restriction across all accounts in the OU. Option B is wrong because CloudFormation templates are not an enforcement mechanism; developers could bypass the template and launch instances manually via the console or CLI. Option D is wrong because AWS Config rules only detect and report non-compliance after the instance is launched; they do not prevent the launch, and terminating instances after creation is reactive and can incur costs and operational overhead.

164
MCQmedium

A company has an AWS Organizations setup with a management account and several member accounts. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account for incident response. They need to ensure that the roles can be assumed only by specific IAM principals in the security account and that the permissions are consistent across all member accounts. Which approach meets these requirements with the LEAST operational overhead?

A.Use AWS IAM Identity Center (successor to AWS Single Sign-On) to create a permission set that grants access to the security account, and assign it to all member accounts.
B.Use AWS CloudFormation StackSets to deploy a standardized IAM role in each member account with a trust policy that allows assumption by the security account's incident response role, and manage updates centrally.
C.Implement a custom AWS Lambda function that uses the AWS SDK to create the IAM role in each member account upon a scheduled trigger.
D.Create an IAM role in each member account manually and use AWS Organizations SCPs to enforce that only the security account can assume it.
AnswerB

CloudFormation StackSets allow you to deploy and update IAM roles across all member accounts from a central location. The trust policy can specify the exact security account principal, ensuring only that principal can assume the role. This provides consistency and minimal operational overhead because updates are applied automatically to all accounts.

Why this answer

CloudFormation StackSets provide a centralized, scalable way to deploy and update IAM roles across multiple accounts with consistent trust policies. This ensures only the specified security account principal can assume the roles, and updates are managed from a single place, minimizing operational overhead.

Exam trap

The trap here is assuming that SCPs can restrict which principals can assume an IAM role, when they actually only limit permissions for principals within the account.

165
MCQeasy

A company uses AWS Organizations and wants to delegate administrative tasks for specific AWS services to a member account. Which AWS feature should be used?

A.AWS Control Tower
B.Delegated administrator for AWS services
C.Cross-account IAM roles
D.AWS CloudTrail organization trail
AnswerB

Registering a member account as delegated administrator for a service transfers that service's organisation-wide administrative permissions to it, so the management account no longer needs to perform those tasks. This satisfies the requirement to delegate service administration without granting full organisation control.

Why this answer

Delegated administrator for AWS services allows you to designate a member account in AWS Organizations to perform administrative tasks for specific AWS services, such as AWS IAM Access Analyzer or AWS Security Hub, without granting full organization management access. This feature centralizes control while distributing operational responsibilities, making it the correct choice for delegating administrative tasks for specific services.

Exam trap

The trap here is that candidates often confuse the broad, role-based access of cross-account IAM roles (Option C) with the specific, service-level delegation model of delegated administrators, leading them to overlook the AWS Organizations-native feature designed for this exact purpose.

How to eliminate wrong answers

Option A is wrong because AWS Control Tower is a service for setting up and governing a multi-account environment using pre-built blueprints and guardrails, not for delegating administrative tasks for specific AWS services to a member account. Option C is wrong because cross-account IAM roles provide broad, role-based access to resources in another account but are not designed for the specific, service-level delegation model that AWS Organizations supports for delegated administrators. Option D is wrong because AWS CloudTrail organization trail logs API activity across all accounts in the organization for auditing, not for delegating administrative tasks for specific services.

166
MCQhard

A company uses AWS Organizations and has deployed a multi-account strategy. The security team wants to enforce that all S3 buckets have versioning enabled. They create an SCP that denies the PutBucketVersioning action if versioning is not enabled. However, they find that the SCP is not preventing users in member accounts from disabling versioning on existing buckets. What is the most likely reason?

A.The SCP is overridden by a service control policy that allows the action.
B.The SCP does not have an explicit deny; it uses a default deny.
C.SCPs cannot evaluate the current state of a resource; they can only deny actions based on request parameters.
D.The SCP is not applied to the root organizational unit.
AnswerC

SCPs are evaluated statically against the request's action and parameters, so a condition cannot read whether versioning is currently enabled on the bucket. The deny therefore never matches, letting users disable versioning on existing buckets.

Why this answer

The most likely reason is option C: SCPs cannot evaluate the current state of a resource; they can only deny actions based on request parameters. SCPs do not have visibility into the current configuration of resources like S3 bucket versioning. Therefore, an SCP that attempts to deny PutBucketVersioning if versioning is not enabled cannot work because it cannot check the bucket's current versioning status.

This allows users to disable versioning. Option A is incorrect because SCPs are hierarchical and cannot be overridden by another SCP unless there is an explicit allow, but the core issue is the condition evaluation. Option B is incorrect because SCPs use explicit deny, not a default deny.

Option D is incorrect because applying the SCP to the root OU would not resolve the fundamental limitation that SCPs cannot check resource state.

167
Multi-Selectmedium

A company is designing a multi-account strategy using AWS Organizations. Which TWO benefits does this approach provide? (Choose TWO.)

Select 2 answers
A.Centrally enforce policies using service control policies (SCPs).
B.Automatically create VPC peering connections between accounts.
C.Simplify cross-region replication for Amazon RDS databases.
D.Isolate workloads and provide a boundary for security and cost management.
E.Reduce the total cost of EC2 instances by aggregating usage across accounts.
AnswersA, D

SCPs attached to the root or OUs define the maximum permissions available to member accounts, letting the organisation apply guardrails once rather than replicating IAM policy in each account. This delivers the central governance benefit the multi-account design requires.

Why this answer

Option A is correct because AWS Organizations lets you attach service control policies (SCPs) to the root, OUs, or individual member accounts, providing centralized permission guardrails that define the maximum available permissions for IAM principals in those accounts. Option D is correct because separate accounts create strong isolation boundaries: resources, IAM roles, and billing are distinct per account, which limits blast radius for security incidents and enables per-account cost tracking and budgets. Option B is not a built-in benefit of Organizations; VPC peering connections must be created and accepted manually (or via automation), and Organizations does not auto-create them.

Option C is not provided by Organizations; RDS cross-region replication (e.g., cross-region read replicas) is configured per database and is unrelated to account structure. Option E is incorrect because EC2 usage is billed per account, and Organizations does not aggregate EC2 usage across accounts to reduce instance costs (though consolidated billing can aggregate volume discounts for some services, it does not reduce EC2 instance pricing in this manner).

Exam trap

The trap here is that candidates often confuse consolidated billing with direct cost reduction for EC2 instances, not realizing that aggregation only enables volume discounts and does not lower the per-instance price automatically.

168
MCQhard

A company has a multi-account environment with AWS Organizations. The security team wants to enforce that all EC2 instances launched in any account must have a specific tag key 'CostCenter'. Which approach should be used?

A.Create an IAM policy in each account that requires the tag for ec2:RunInstances.
B.Use a Service Control Policy (SCP) that denies ec2:RunInstances unless the request includes the required tag.
C.Use AWS Config rules to detect untagged instances and trigger an AWS Lambda function to tag them.
D.Configure the EC2 service to automatically add the tag to all instances.
AnswerB

An SCP denying ec2:RunInstances unless aws:RequestTag/CostCenter is present enforces the requirement centrally across every account in the organisation, satisfying the multi-account constraint without per-account tooling. Because SCPs gate IAM permissions at the organisation level, no principal in any member account can bypass the tag condition.

Why this answer

A Service Control Policy (SCP) applied at the AWS Organizations root or OU level can centrally deny the ec2:RunInstances action unless the request includes the required 'CostCenter' tag. This enforces the tagging requirement across all accounts in the organization without needing per-account IAM policies, and it cannot be overridden by account administrators.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config) with preventive controls (like SCPs), or assume that IAM policies in each account are sufficient for centralized enforcement, overlooking the fact that SCPs are the only mechanism that can enforce policies across all accounts in an organization without being overridden.

How to eliminate wrong answers

Option A is wrong because IAM policies in each account can be modified or removed by account administrators, so they do not provide centralized enforcement across a multi-account environment. Option C is wrong because AWS Config rules are detective, not preventive; they can detect untagged instances after launch but cannot block the creation of untagged instances, which violates the security team's requirement to enforce tagging at launch time. Option D is wrong because the EC2 service does not have a native feature to automatically add tags to all instances; tags must be explicitly provided in the RunInstances request or added via automation after launch.

169
Drag & Dropmedium

Drag and drop the steps to set up a Direct Connect private virtual interface in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order is: first create the virtual interface in AWS, then configure the on-premises router, establish BGP, verify availability, and finally update route tables.

170
MCQhard

A company has a multi-account AWS environment with hundreds of accounts. The security team needs to centrally manage IAM roles for cross-account access. They want to ensure that when a role is created in a member account, it automatically adheres to the principle of least privilege and is auditable. What solution should they implement?

A.Use AWS CloudFormation StackSets to deploy IAM roles from a central template in each account.
B.Use AWS Organizations service control policies (SCPs) to deny creation of IAM roles except through AWS CloudFormation, and use a centrally managed CloudFormation template via StackSets.
C.Configure AWS Config rules to detect non-compliant roles and trigger a Lambda function to remove them.
D.Create a Lambda function that monitors CloudTrail events for role creation and sends alerts.
AnswerB

SCPs restrict member accounts to creating roles only via CloudFormation, and StackSets deploys one centrally governed template across the organisation. This enforces least privilege consistently and keeps every role creation auditable, meeting the multi-account requirement.

Why this answer

AWS Organizations SCPs can be used to deny the creation of IAM roles except through AWS CloudFormation, ensuring that roles are only created via a centrally managed template. By combining this with AWS CloudFormation StackSets, the security team can deploy IAM roles from a single template across all member accounts, enforcing the principle of least privilege and providing full auditability through CloudFormation stack events and AWS CloudTrail.

Exam trap

The trap here is that candidates often choose Option A, thinking that CloudFormation StackSets alone provide enforcement, but they miss the critical need for a preventive control (SCPs) to block manual role creation outside the template.

How to eliminate wrong answers

Option A is wrong because using CloudFormation StackSets alone to deploy IAM roles does not prevent users from creating roles manually outside the template, so it fails to enforce the principle of least privilege or ensure auditability. Option C is wrong because configuring AWS Config rules to detect non-compliant roles and trigger a Lambda function to remove them is a reactive approach that does not prevent the creation of non-compliant roles in the first place, leading to potential security gaps and operational overhead. Option D is wrong because creating a Lambda function that monitors CloudTrail events for role creation and sends alerts is also reactive; it only notifies after a role is created, without enforcing least privilege or preventing non-compliant roles from being created.

171
MCQhard

A company has a multi-account AWS environment with a central shared services VPC in a networking account. They want to allow resources in workload accounts to access a shared Amazon RDS database in the shared services VPC. The RDS database is in a private subnet. The company uses AWS Transit Gateway to connect all VPCs. They have set up a route in the workload VPC route table pointing to the Transit Gateway for the shared services VPC CIDR. However, resources in the workload accounts cannot connect to the RDS database. What is the most likely cause?

A.The security group on the RDS database does not allow inbound traffic from the workload VPC CIDR.
B.The route table associated with the subnet where the RDS database resides does not have a route back to the workload VPC CIDR via the Transit Gateway.
C.The Transit Gateway attachment for the shared services VPC is not associated with the correct Transit Gateway route table.
D.The RDS database is not publicly accessible, and the workload resources are using public IP addresses.
AnswerB

For traffic to flow between VPCs through a Transit Gateway, both the source and destination subnets must have route table entries pointing to the Transit Gateway for the other VPC's CIDR. The workload VPC has a route to the shared services VPC, but the shared services VPC subnet's route table may lack a route back to the workload VPC CIDR. This asymmetric routing causes the return traffic to be dropped, preventing the connection.

Why this answer

When connecting VPCs through a Transit Gateway, routing must be symmetric. The workload VPC has a route to the Transit Gateway for the shared services VPC CIDR, but the shared services VPC subnet's route table must also have a route back to the workload VPC CIDR via the Transit Gateway. Without this return route, the response packets cannot find their way back, and the connection fails.

This is a common pitfall in multi-VPC designs.

Exam trap

The trap here is focusing only on the forward path and forgetting that return traffic requires a route in the destination subnet's route table.

172
MCQhard

A company has a production AWS account that is part of an AWS Organization. The account has a VPC with a NAT gateway for internet access. The security team wants to ensure that all outbound traffic to the internet flows through a centralized inspection VPC in the security account for traffic inspection. Which architecture should be used?

A.Use AWS Cloud WAN to connect the VPCs and route all outbound traffic through the inspection VPC.
B.Create a VPC peering connection between the production VPC and the inspection VPC, and route all outbound traffic through the peered connection.
C.Create a transit gateway, attach both VPCs, and configure the production VPC's route table to send all internet-bound traffic to the transit gateway, then route it through the inspection VPC's firewall.
D.Place a NAT gateway in the inspection VPC and have the production VPC route internet traffic to the NAT gateway.
AnswerC

A transit gateway provides transitive routing between the production and inspection VPCs, letting the production route table forward 0.0.0.0/0 to the inspection VPC's firewall before egress. This satisfies the requirement that all internet-bound traffic be inspected centrally.

Why this answer

A transit gateway allows you to centralize outbound internet traffic by attaching both the production VPC and the inspection VPC, then configuring the production VPC's route table to send 0.0.0.0/0 traffic to the transit gateway. The inspection VPC can then route that traffic through its firewall (e.g., a third-party appliance or AWS Network Firewall) before it reaches an internet gateway, enabling full traffic inspection while maintaining a single egress point.

Exam trap

The trap here is that candidates often assume VPC peering can be used for transitive routing or that a NAT gateway provides inspection capabilities, but VPC peering is non-transitive and NAT gateways only perform address translation, not deep packet inspection.

How to eliminate wrong answers

Option A is wrong because AWS Cloud WAN is designed for global network connectivity across multiple regions and on-premises locations, not for routing internet-bound traffic through a centralized inspection VPC within a single region; it lacks the granular route table controls needed to force internet traffic through a specific inspection VPC. Option B is wrong because VPC peering does not support transitive routing—traffic from the production VPC to the internet would need to go through the peered connection to the inspection VPC, but the inspection VPC cannot forward that traffic to its internet gateway because VPC peering does not allow a VPC to act as a transit hub for internet-bound traffic. Option D is wrong because placing a NAT gateway in the inspection VPC and routing production VPC traffic to it would require the production VPC to send internet-bound traffic directly to the NAT gateway's private IP, which is not routable across VPC boundaries without additional infrastructure; moreover, the NAT gateway itself does not provide traffic inspection capabilities.

173
MCQmedium

A company is centralizing its logging across multiple AWS accounts using a central logging account. Each application account delivers its CloudTrail logs and VPC Flow Logs to an S3 bucket in the logging account. The security team needs to query these logs using Amazon Athena. The logs are currently in separate S3 prefixes per account. The team wants to create a single Athena table that can query logs from all accounts without having to modify the table definition every time a new account is added. The logs are in CSV format for VPC Flow Logs and JSON format for CloudTrail. What is the MOST efficient solution?

A.Create a view that unions all the tables for each account, and update the view DDL when a new account is added.
B.Use AWS Glue crawlers configured to crawl the S3 bucket with a partition structure based on account ID and log type. Enable partition indexing to improve query performance.
C.Create an Athena table with partitions manually for each account and use MSCK REPAIR TABLE to add new partitions.
D.Convert all logs to Parquet format using AWS Glue ETL jobs and store them in a single prefix.
AnswerB

Glue crawlers discover new account prefixes automatically and register partitions in the Data Catalog, so the single Athena table needs no manual edits as accounts are added. Partition indexing speeds lookups. This satisfies the requirement to query all accounts without modifying the table definition.

Why this answer

Using AWS Glue crawlers configured to crawl the S3 bucket with a partition structure based on account ID and log type allows automatic discovery of new partitions as new accounts are added. The crawler can be scheduled to run periodically, updating the table metadata without manual intervention. Partition indexing improves query performance by reducing the amount of data scanned.

Option A is incorrect because updating a view requires manual DDL changes each time a new account is added. Option C is incorrect because manually managing partitions and using MSCK REPAIR TABLE still requires manual effort to add new partitions. Option D is incorrect because converting logs to Parquet adds overhead and does not solve the need for automatic partition discovery across accounts.

174
MCQeasy

A company wants to automate the creation of new AWS accounts and apply baseline security configurations. Which combination of services should be used to achieve this?

A.AWS Service Catalog and AWS Config.
B.AWS Organizations API and CloudTrail.
C.AWS Control Tower and Service Control Policies (SCPs).
D.AWS CloudFormation StackSets and IAM.
AnswerC

AWS Control Tower automates account provisioning through its Account Factory, applying baseline guardrails via mandatory and strongly recommended controls. SCPs, attached through AWS Organizations, enforce permission boundaries across those accounts, satisfying the requirement to apply baseline security configurations consistently at scale without manual setup.

Why this answer

AWS Control Tower provides a managed service to automate the creation of new AWS accounts through Account Factory, while Service Control Policies (SCPs) enforce baseline security guardrails across all accounts in the organization. This combination ensures that every new account is provisioned with consistent security policies without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Control Tower with AWS Organizations alone, forgetting that Control Tower adds automated account provisioning and pre-built security guardrails (SCPs) that Organizations alone does not provide.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog is used for creating and managing approved IT service catalogs, not for automating account creation, and AWS Config is a configuration auditing service, not a provisioning tool. Option B is wrong because the AWS Organizations API can create accounts programmatically but lacks built-in baseline security configuration enforcement; CloudTrail only logs API activity and does not apply security policies. Option D is wrong because AWS CloudFormation StackSets deploy infrastructure templates across accounts but do not automate account creation itself, and IAM manages user permissions but not account provisioning or baseline security guardrails.

175
MCQhard

A company with multiple AWS accounts wants to centralize CloudTrail logging. They create a CloudTrail trail in the management account that logs all events across all accounts and regions. However, the security team notices that some management events from member accounts are not being logged. What is the most likely cause?

A.The SCPs applied to member accounts are blocking CloudTrail from sending logs.
B.CloudTrail is a regional service and the trail is only in one region.
C.Member accounts have IAM policies that deny CloudTrail logging.
D.The trail was not created as an organization trail.
AnswerD

An organization trail is required for CloudTrail to log events from every member account into the management account's centralized S3 bucket. A standard trail only captures events within its own account, so member-account management events are silently omitted — exactly the gap described in the stem.

Why this answer

When a CloudTrail trail is created in the management account without enabling the 'organization trail' option, it only logs events for the management account itself and not for member accounts. To centralize logging across all accounts in AWS Organizations, the trail must be explicitly created as an organization trail, which automatically applies to all current and future member accounts. Without this setting, member account events are not forwarded to the management account's trail.

Exam trap

The trap here is that candidates often assume that creating a trail in the management account automatically covers all member accounts, but they overlook the explicit requirement to designate the trail as an organization trail during creation.

How to eliminate wrong answers

Option A is wrong because SCPs (Service Control Policies) can only deny or allow actions at the AWS Organizations level, but they do not block CloudTrail from sending logs; CloudTrail delivers logs to an S3 bucket, and SCPs cannot prevent that delivery unless they explicitly deny the `cloudtrail:PutEventSelectors` or similar actions, which is not the described issue. Option B is wrong because the question states the trail logs events across all regions, and CloudTrail trails can be configured as multi-region trails, so a single trail can capture events from all regions. Option C is wrong because IAM policies in member accounts do not affect CloudTrail logging; CloudTrail operates at the AWS service level and does not require IAM permissions in member accounts to log management events, as the trail is managed from the management account.

176
MCQeasy

A startup is using a single AWS account for development, testing, and production. They want to isolate environments and improve security. What is the most aligned AWS best practice?

A.Use separate VPCs within the same account.
B.Use IAM policies to restrict access per environment.
C.Create separate AWS accounts for each environment using AWS Organizations.
D.Use resource tagging to separate environments.
AnswerC

Separate accounts give each environment its own blast radius, IAM boundaries and service quotas, satisfying the isolation and security requirement. AWS Organizations centrally manages billing and governance through service control policies, while consolidated billing retains volume discounts. A single account cannot enforce hard environment boundaries, since IAM policies alone permit cross-environment access.

Why this answer

AWS best practice for isolating environments is to use separate AWS accounts for each environment (development, testing, production) managed under AWS Organizations. This provides strong security boundaries, simplifies billing, and allows for centralized governance and service control policies (SCPs).

Exam trap

SAP-C02 often tests the misconception that VPCs or IAM policies provide sufficient isolation; the best practice is to use separate AWS accounts for strong security boundaries.

How to eliminate wrong answers

Option A is wrong because separate VPCs within the same account do not provide strong isolation; IAM policies and resource sharing can still cross VPC boundaries, and a compromised account affects all environments. Option B is wrong because IAM policies alone are not sufficient for isolation; they are complex to manage and do not provide the same level of separation as separate accounts. Option D is wrong because resource tagging is for organization and cost allocation, not security isolation; tags can be easily changed and do not enforce boundaries.

177
Multi-Selecthard

Which THREE design patterns are recommended for decoupling components in a microservices architecture on AWS?

Select 3 answers
A.Use Amazon EventBridge for event-driven integration.
B.Use AWS Direct Connect for private connectivity.
C.Use Amazon SNS topics for pub/sub messaging.
D.Use Amazon SQS queues between services.
E.Use Elastic Load Balancing to distribute traffic.
AnswersA, C, D

Amazon EventBridge provides asynchronous, event-driven integration so producers publish events without knowing consumers, satisfying the decoupling requirement. Its routing rules and schema registry let services evolve independently, and native AWS service targets remove direct point-to-point calls. This contrasts with synchronous request-response patterns, which tightly couple availability and latency between microservices.

Why this answer

Amazon EventBridge (A) is correct because it provides an event bus that routes events between producers and consumers based on rules, so services publish events without knowing subscribers, achieving asynchronous decoupling. Amazon SNS topics (C) are correct because the publish/subscribe model lets a publisher fan out messages to multiple subscribing endpoints (SQS, Lambda, HTTP/S, email) without direct coupling to consumers. Amazon SQS queues (D) are correct because point-to-point queues buffer messages between services, letting producers and consumers operate independently and absorb traffic spikes or consumer downtime.

AWS Direct Connect (B) is not a decoupling pattern but a dedicated private network connection for hybrid connectivity, and Elastic Load Balancing (E) distributes synchronous traffic across targets but still requires the caller to know and directly invoke the load balancer endpoint, so neither decouples components in the event-driven sense.

Exam trap

The trap here is that candidates may confuse network connectivity solutions (Direct Connect) or load balancing (ELB) with true decoupling patterns, but decoupling in microservices requires asynchronous, event-driven or message-based integration, not synchronous request/response or network links.

178
MCQmedium

A company has a multi-account AWS environment managed by AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central security account. The roles must be automatically created in all existing and future accounts, and any changes to the roles must be applied consistently. Which solution meets these requirements with the LEAST administrative effort?

A.Use AWS Organizations service control policies (SCPs) to enforce the creation of IAM roles with specific permissions in all accounts.
B.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share the role with all member accounts.
C.Develop a script using the AWS CLI that iterates over all accounts and creates the IAM roles, and schedule it to run regularly to catch new accounts.
D.Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack that creates the IAM roles to all accounts in the organization.
AnswerD

AWS CloudFormation StackSets with service-managed permissions can deploy stacks to all accounts in an organization, including automatically to new accounts as they are added. This allows centralized management of IAM roles, and any updates to the stack set are rolled out to all accounts, ensuring consistency with minimal effort.

Why this answer

AWS CloudFormation StackSets with service-managed permissions integrates with AWS Organizations to automatically deploy stacks to all accounts, including new ones. This enables centralized creation and updates of IAM roles across the organization without manual intervention. It provides consistency and reduces administrative effort, making it the ideal solution for this scenario.

Exam trap

The trap here is thinking that SCPs can create resources, but they only define permissions boundaries and cannot provision IAM roles.

179
Multi-Selectmedium

A large enterprise is consolidating 300 AWS accounts under AWS Organizations. The security team needs a way to centrally define and deploy IAM roles that grant break-glass access, must ensure the roles can be assumed only by members of a specific federated group, and must be able to update the roles across all accounts without logging into each account. (Choose two.)

Select 2 answers
A.Create the break-glass role in the management account and grant cross-account access to every workload account using an IAM group with an inline policy that lists each account ID.
B.Attach an SCP at the root that allows iam:CreateRole only from the management account and rely on that as the deployment mechanism for the break-glass role.
C.Define the role trust policy to require the SAML provider and a condition on the group attribute from the identity provider, so only the specified federated group can assume the role.
D.Use IAM Identity Center permission sets with a custom inline policy that embeds the break-glass trust policy, and assign the permission set to the federated group.
E.Use AWS CloudFormation StackSets with service-managed permissions and automatic deployment enabled to deploy the break-glass role to every account in the target OUs.
AnswersC, E

An IAM role trust policy can require sts:AssumeRoleWithSAML and include a condition key such as SAML:aud or a custom attribute mapped from the IdP, which restricts assumption to members of the named group. This is the standard way to scope federated access to a specific group rather than the whole directory.

Why this answer

StackSets with service-managed permissions is the supported way to deploy and update IAM roles across many organization accounts, and a trust policy conditioned on the federated group attribute is what limits assumption to the intended users. Together they satisfy both the centralized deployment and the scoped-access requirements.

Exam trap

The trap here is confusing IAM Identity Center permission sets with a mechanism for distributing an arbitrary custom role, when permission sets only generate their own auto-created roles.

180
MCQeasy

A company uses AWS Organizations and wants to ensure that all member accounts have AWS CloudTrail enabled and logs are delivered to a central S3 bucket in the management account. Which approach is MOST efficient?

A.Use AWS Config rules to detect accounts without CloudTrail and auto-remediate.
B.Manually enable CloudTrail in each account by logging into every account.
C.Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts.
D.Create an SCP that requires CloudTrail to be enabled in each account.
AnswerC

CloudFormation StackSets deploy the same CloudTrail template across every account in AWS Organizations, including new accounts, with a central S3 bucket in the management account. This automates consistent, scalable enablement rather than manual per-account configuration.

Why this answer

AWS CloudFormation StackSets allow you to deploy a single CloudTrail template across all member accounts in an AWS Organization from a central management account. This approach is the most efficient as it automates the deployment, ensures consistent configuration, and delivers logs to the specified central S3 bucket without requiring manual intervention or per-account scripting.

Exam trap

The trap here is that candidates often confuse the capabilities of SCPs (which only control permissions) with resource enforcement, leading them to incorrectly select Option D, not realizing that SCPs cannot create or enable resources like CloudTrail.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect non-compliance and trigger auto-remediation via Systems Manager Automation or Lambda, but they do not natively deploy CloudTrail across all accounts; they react to existing resources rather than proactively provisioning them, making them less efficient for initial deployment. Option B is wrong because manually enabling CloudTrail in each account by logging into every account is not scalable, error-prone, and violates the principle of least effort for a multi-account environment. Option D is wrong because Service Control Policies (SCPs) can only deny or allow API actions, not enforce the presence of a resource like CloudTrail; an SCP cannot require CloudTrail to be enabled—it can only block actions that disable it, which is insufficient to ensure initial enablement.

181
MCQmedium

A global company is using a multi-account AWS Organizations setup with a centralized logging account. They want to aggregate CloudTrail logs from all accounts into a single S3 bucket in the logging account. Which combination of steps will meet this requirement?

A.Create an IAM role in each account that allows the logging account to assume and copy logs. Schedule a Lambda function to copy logs hourly.
B.Create an S3 bucket in the logging account with a bucket policy that grants read/write access to all accounts. Configure each account's CloudTrail to deliver to that bucket.
C.Create a CloudTrail trail in the management account that applies to all accounts in the organization, and specify the S3 bucket in the logging account as the destination.
D.Enable AWS Config in each account and stream configuration history to a centralized S3 bucket.
AnswerC

An organisation trail created in the management account automatically applies to every account in the organisation, delivering events to the specified S3 bucket in the logging account. This satisfies aggregation without configuring trails per member account.

Why this answer

AWS Organizations allows you to create a single CloudTrail trail in the management account that automatically applies to all member accounts. By specifying the S3 bucket in the centralized logging account as the destination, CloudTrail delivers logs from every account directly to that bucket without needing cross-account IAM roles or manual copying. This leverages the organization trail feature, which simplifies log aggregation and ensures consistent logging across the entire organization.

Exam trap

The trap here is that candidates often assume they need to configure CloudTrail in each account individually or use cross-account IAM roles to copy logs, but AWS Organizations provides a native organization trail feature that automatically aggregates logs from all accounts into a single S3 bucket in a centralized logging account.

How to eliminate wrong answers

Option A is wrong because it introduces unnecessary complexity and latency by requiring an IAM role in each account and a scheduled Lambda function to copy logs hourly, which is not real-time and violates the principle of least privilege by granting cross-account copy permissions. Option B is wrong because CloudTrail does not support delivering logs to an S3 bucket in a different account using a bucket policy that grants read/write access to all accounts; CloudTrail requires the destination bucket to be in the same account as the trail or uses an organization trail with a bucket policy that grants CloudTrail service principal write access, not all accounts. Option D is wrong because AWS Config streams configuration history and changes, not CloudTrail logs, and it does not aggregate CloudTrail API activity logs; it serves a different purpose for compliance and resource tracking.

182
MCQmedium

A company has a multi-account environment with a central security account. They want to use AWS Security Hub to aggregate findings from all accounts. What is the correct setup?

A.Set up Amazon EventBridge to forward findings from each account to the central account.
B.Use Amazon CloudWatch cross-account dashboards to view findings.
C.Enable AWS Config aggregator in the central account.
D.Enable Security Hub in the central account and invite member accounts to enable Security Hub.
AnswerD

Security Hub aggregation requires enabling it in the central account as the administrator, then inviting member accounts to enable Security Hub and accept the invitation. Findings from all accounts then flow into the central account, satisfying the multi-account aggregation requirement.

Why this answer

AWS Security Hub uses a multi-account architecture where a central administrator account invites member accounts to enable Security Hub. This allows the administrator account to aggregate findings, insights, and compliance scores from all member accounts into a single view, enabling centralized security monitoring without additional forwarding infrastructure.

Exam trap

The trap here is that candidates confuse Security Hub's multi-account model with other aggregation services like AWS Config aggregator or CloudWatch cross-account dashboards, assuming any cross-account aggregation tool can consolidate Security Hub findings, when in fact Security Hub requires its own dedicated multi-account feature.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge can forward events but is not the native mechanism for Security Hub multi-account aggregation; Security Hub uses its own invitation-based model, and EventBridge would require custom event buses and rules, adding unnecessary complexity and missing native cross-account finding consolidation. Option B is wrong because Amazon CloudWatch cross-account dashboards aggregate metrics and logs, not Security Hub findings; Security Hub findings are not stored in CloudWatch Logs or Metrics by default, so dashboards cannot display them. Option C is wrong because AWS Config aggregator aggregates AWS Config rules and compliance data across accounts, not Security Hub findings; Security Hub findings are separate from AWS Config and require Security Hub's own multi-account enablement.

183
MCQhard

A company uses AWS Organizations with hundreds of accounts. The security team needs to ensure that no IAM user in any account can create a new IAM user or access key. What is the most scalable way to enforce this?

A.Use AWS Config rules to detect and automatically delete any new users or keys.
B.Enable AWS CloudTrail and create a metric filter to alert on these actions.
C.Attach an IAM policy to the Administrator role in each account that denies these actions.
D.Apply a service control policy (SCP) that denies the iam:CreateUser and iam:CreateAccessKey actions.
AnswerD

SCPs apply to all principals in the account.

Why this answer

Service control policies (SCPs) are the most scalable way to enforce restrictions across all accounts in an AWS Organization because they apply to all IAM users and roles in every member account, including the root user. By denying the iam:CreateUser and iam:CreateAccessKey actions at the organization root or OU level, the security team can prevent any IAM user from creating new users or access keys without needing to manage individual account policies or rely on reactive measures.

Exam trap

The trap here is that candidates often choose Option C because they think attaching a deny policy to the Administrator role is sufficient, but they overlook that SCPs are the only mechanism that can restrict the root user and scale across hundreds of accounts without per-account management.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are reactive—they detect non-compliant resources after creation and can trigger auto-remediation, but they do not prevent the action from occurring, leaving a window where the user or key exists and could be used. Option B is wrong because CloudTrail with metric filters and alerts only provides notification after the fact; it does not block the action, so the security violation still occurs. Option C is wrong because attaching an IAM policy to the Administrator role in each account is not scalable for hundreds of accounts—it requires manual per-account configuration and does not prevent actions by the root user or other roles that might bypass the policy.

184
Multi-Selecthard

A company is migrating to a multi-account AWS environment. They want to centralize DNS management using Amazon Route 53 private hosted zones. The private zones must be accessible from all VPCs in the organization. Which THREE steps are required to achieve this?

Select 3 answers
A.Create a private hosted zone in the central networking account.
B.Share the private hosted zone with other accounts using AWS Resource Access Manager.
C.Create a public hosted zone with the same name and configure DNSSEC.
D.Associate the private hosted zone with the VPCs in the member accounts.
E.Create a Route 53 Resolver outbound endpoint in each account.
AnswersA, B, D

A Route 53 private hosted zone must exist before any cross-account association can occur, so creating it in the central networking account establishes the single authoritative record container that member VPCs will later resolve against.

Why this answer

Option A is correct because a Route 53 private hosted zone must first be created in the central networking (owner) account, which becomes the zone owner and controls its records and associations. Option B is correct because AWS Resource Access Manager (RAM) is the mechanism used to share the private hosted zone with other AWS accounts in the organization so their VPCs can be associated with it. Option D is correct because after sharing, the private hosted zone must be explicitly associated with each VPC in the member accounts (via AssociateVPCWithHostedZone or the console) for DNS resolution to work in those VPCs.

Option C is wrong because a public hosted zone with DNSSEC does not provide private, internal resolution across VPCs and is unrelated to this requirement. Option E is wrong because a Route 53 Resolver outbound endpoint is used to forward DNS queries from a VPC to on-premises or external resolvers, not to share private hosted zones across accounts.

Exam trap

The trap here is that candidates often confuse the need for a public hosted zone or outbound endpoints with the simpler mechanism of sharing a private hosted zone via AWS RAM and associating it with VPCs, leading them to select unnecessary or incorrect options.

185
MCQhard

A multinational corporation uses AWS Organizations with hundreds of accounts. The security team requires that all Amazon S3 buckets across the organization be encrypted with a specific AWS KMS key from the security account. Which combination of controls should be implemented to enforce this requirement?

A.Create an AWS Service Catalog portfolio that restricts bucket creation to encrypted buckets only.
B.Use IAM policies in each account to deny PutBucketEncryption actions that do not specify the required KMS key.
C.Enable AWS CloudTrail and create a CloudWatch Events rule to automatically remediate non-compliant buckets.
D.Apply an SCP to deny s3:PutBucketEncryption with any key other than the required KMS key, and use AWS Config rules to detect and remediate existing non-compliant buckets.
AnswerD

SCPs can deny actions organization-wide, and AWS Config rules can detect and remediate non-compliant buckets.

Why this answer

Applying an SCP to deny s3:PutBucketEncryption with any key other than the required KMS key enforces the encryption requirement across all accounts in the organization. Additionally, using AWS Config rules detects and remediates existing non-compliant buckets, ensuring ongoing compliance. This combination provides preventive and detective controls.

Exam trap

SAP-C02 often tests the difference between preventive controls (SCPs) and detective controls (Config), causing candidates to choose reactive options like CloudTrail remediation instead of a combination of both.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog portfolios restrict resource creation to approved products but do not enforce encryption settings on S3 buckets created outside the portfolio. Option B is wrong because IAM policies in each account are not centrally managed and can be modified, lacking the organization-wide enforcement of SCPs. Option C is wrong because CloudTrail and CloudWatch Events provide reactive remediation but do not prevent non-compliant bucket creation in the first place.

186
MCQmedium

A company has multiple AWS accounts managed using AWS Organizations. The security team wants to enforce that all new accounts automatically have a specific AWS Config rule enabled to prohibit public S3 bucket access. Which solution requires the least operational overhead?

A.Use AWS CloudFormation StackSets to deploy the AWS Config rule to all accounts.
B.Enable AWS Config in the management account and use an aggregator for all accounts.
C.Use an SCP to automatically enable the AWS Config rule in all accounts.
D.Use an SCP to deny the s3:PutBucketPublicAccessBlock action if a specific tag is not present.
AnswerA

CloudFormation StackSets deploys the Config rule across all accounts in AWS Organizations from one template, automatically applying it to new accounts. This centralised, automated rollout requires the least ongoing operational overhead compared with manual per-account configuration.

Why this answer

AWS CloudFormation StackSets can deploy the AWS Config rule to all accounts in the organization. With automatic deployment enabled, new accounts will automatically receive the rule, requiring minimal operational overhead after initial setup. Option B is incorrect because it only sets up an aggregator and does not enable any rule.

Option C is incorrect because SCPs cannot automatically enable Config rules; they only control API actions. Option D is incorrect because it denies the s3:PutBucketPublicAccessBlock action but does not enable the required Config rule, failing to meet the explicit requirement.

Exam trap

The trap here is that candidates may think SCPs can enforce configuration standards, but SCPs only control API actions and cannot create or enable resources like Config rules. The correct approach is to use a deployment mechanism such as CloudFormation StackSets to automatically deploy the rule across accounts.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation StackSets require manual setup and ongoing maintenance to deploy to new accounts as they are added, which adds operational overhead compared to a policy-based approach. Option B is wrong because enabling AWS Config in the management account and using an aggregator only centralizes compliance data; it does not enforce the Config rule in new accounts automatically. Option C is wrong because SCPs cannot directly enable AWS Config rules; they can only deny or allow API actions, not create or configure AWS resources.

187
MCQeasy

A company needs to share a VPC subnet with multiple accounts in the same AWS Organization. What is the MOST secure way to achieve this?

A.Create a Transit Gateway and attach all accounts.
B.Set up a VPN connection between accounts.
C.Use AWS RAM to share the subnet with the organization.
D.Create a VPC peering connection between each account and the VPC owner.
AnswerC

AWS RAM shares the subnet in place, so participant accounts launch resources directly into it without duplicating networking or peering. Sharing within the organisation enables automatic acceptance and centralised governance, satisfying the secure multi-account requirement more tightly than VPC peering or duplicated subnets.

Why this answer

AWS Resource Access Manager (RAM) allows you to share a subnet with other accounts within the same AWS Organization without requiring any intermediate networking appliances or complex routing. This is the most secure approach because the shared subnet remains under the VPC owner's administrative control, and participating accounts can launch resources directly into the subnet while inheriting the VPC's security policies. No traffic traverses external connections or third-party devices, reducing the attack surface.

Exam trap

The trap here is that candidates often confuse network connectivity solutions (Transit Gateway, VPC peering, VPN) with resource sharing, assuming that to 'share' a subnet you must connect the VPCs, when in fact AWS RAM provides a direct, secure, and managed way to share subnets without any network-level interconnection.

How to eliminate wrong answers

Option A is wrong because a Transit Gateway is a network transit hub used to interconnect VPCs and on-premises networks, not a mechanism to share a subnet; attaching accounts via Transit Gateway would require separate VPCs and routing, not direct subnet sharing. Option B is wrong because a VPN connection between accounts would create an encrypted tunnel over the internet, which is unnecessary overhead and introduces latency and complexity for sharing a subnet that should be accessed natively within the same AWS backbone. Option D is wrong because VPC peering connects entire VPCs, not individual subnets, and requires managing multiple peering connections and route tables; it also does not allow the peered accounts to launch resources directly into the owner's subnet.

188
MCQeasy

A company has a decentralized IT structure where each business unit manages its own AWS accounts. The central IT team wants to enforce security policies across all accounts but allow business units to retain administrative control. Which solution should the central IT team implement?

A.Deploy AWS CloudFormation StackSets to each account with security templates.
B.Create a shared services account and use IAM cross-account roles for each business unit.
C.Use AWS Organizations with service control policies (SCPs) to enforce baseline permissions, and delegate administration to organizational units (OUs) for each business unit.
D.Migrate all workloads to a single AWS account and use IAM roles for each business unit.
AnswerC

AWS Organizations SCPs set permission guardrails at the organisation root or OU level, capping the maximum permissions available to every principal in member accounts. Delegating each business unit to its own OU preserves their administrative autonomy within those guardrails, satisfying central enforcement without removing local control.

Why this answer

AWS Organizations with SCPs allows the central IT team to enforce baseline security policies across all accounts without removing administrative control from business units. By delegating administration to OUs for each business unit, the central team sets guardrails while business units retain full IAM management within their accounts, satisfying the decentralized structure requirement.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking SCPs remove all administrative control, when in fact SCPs only set upper permission boundaries and allow business units to retain full administrative autonomy within those limits.

How to eliminate wrong answers

Option A is wrong because CloudFormation StackSets deploy resources and templates but do not enforce ongoing security policies; business units could modify or delete the deployed resources, and StackSets lack the ability to set permission guardrails. Option B is wrong because a shared services account with cross-account roles centralizes access control, which contradicts the requirement for business units to retain administrative control over their own accounts. Option D is wrong because migrating all workloads to a single account violates the decentralized IT structure and removes business unit autonomy, while IAM roles alone cannot enforce baseline security policies across separate accounts.

189
MCQmedium

A company has a multi-account AWS environment with AWS Organizations. The security team wants to centrally manage IAM roles that grant cross-account access to a central audit account. They need to ensure that only the audit account can assume these roles and that the roles are automatically created in all existing and future accounts. What should they do?

A.Use AWS Organizations to create a service control policy (SCP) that allows sts:AssumeRole only from the audit account, and manually create the roles in each account.
B.Use AWS Identity and Access Management (IAM) to create a role in each account with a trust policy that allows the audit account, and use AWS Lambda to create the roles in new accounts as they are added.
C.Use AWS CloudFormation StackSets with service-managed permissions to deploy a stack set that creates the IAM roles in all accounts in the organization.
D.Create an IAM role in the management account and use AWS Resource Access Manager (RAM) to share it with all member accounts.
AnswerC

CloudFormation StackSets with service-managed permissions can automatically deploy stack instances to all accounts in an organization, including future accounts when auto-deployment is enabled. The stack set can create IAM roles with trust policies that allow only the audit account to assume them. This meets the requirements for central management and automatic provisioning.

Why this answer

CloudFormation StackSets with service-managed permissions is designed to deploy resources across all accounts in an AWS Organization, including automatically to new accounts when auto-deployment is enabled. By defining a stack set that creates IAM roles with trust policies restricted to the audit account, the security team can centrally manage and automatically provision these roles. This is the most efficient and native solution.

Exam trap

The trap here is assuming that AWS Resource Access Manager can share IAM roles, but RAM does not support IAM roles as shareable resources.

190
MCQeasy

A company is using AWS Organizations with all features enabled. They want to apply a service control policy (SCP) that denies the ability to delete AWS KMS keys across all member accounts, but they need to allow a specific break-glass role in the management account to delete keys in case of emergency. Which statement is true regarding SCP enforcement in this scenario?

A.SCPs apply to all principals in member accounts, including the root user, but do not apply to the management account, so the break-glass role in the management account is unaffected.
B.SCPs apply to all accounts in the organization, including the management account, so the break-glass role must be explicitly exempted in the SCP.
C.SCPs apply only to IAM users, not to IAM roles, so the break-glass role is unaffected regardless of which account it is in.
D.SCPs apply to member accounts but can be overridden by an IAM policy in the member account that allows kms:ScheduleKeyDeletion.
AnswerA

SCPs are applied to member accounts and affect all principals, including the root user, but they do not apply to the management account. Therefore, a break-glass role in the management account is not restricted by the SCP, allowing key deletion as intended. This matches the requirement.

Why this answer

SCPs are guardrails that apply to all principals in member accounts, including the root user, but they are not evaluated for the management account. Therefore, a role in the management account can perform actions denied by an SCP attached to member accounts. This allows the break-glass role to delete KMS keys without needing an exemption in the SCP.

Exam trap

The trap here is thinking that SCPs apply to the management account or that they can be overridden by IAM policies, when in fact SCPs do not affect the management account and always take precedence over IAM policies in member accounts.

191
MCQeasy

A company wants to ensure that no IAM user in any account can create access keys. The company uses AWS Organizations. Which approach should be used?

A.Enable AWS CloudTrail and set up a metric filter for CreateAccessKey
B.Apply an IAM policy to all users in each account that denies iam:CreateAccessKey
C.Attach an SCP to the root OU that denies iam:CreateAccessKey
D.Use AWS Config to detect access key creation and trigger a Lambda to delete the key
AnswerC

An SCP attached to the root OU applies to every member account in the organisation, denying `iam:CreateAccessKey` regardless of identity-based policies. This satisfies the requirement that no IAM user in any account can create access keys, since SCPs set the maximum permissions boundary across all accounts beneath the root.

Why this answer

A Service Control Policy (SCP) attached to the root organizational unit denies the iam:CreateAccessKey action across all accounts in the organization, providing centralized enforcement. Option A is wrong because CloudTrail logs events but does not prevent them. Option B is wrong because applying an IAM policy in each account is not centrally managed and may be overridden by administrator permissions.

Option D is wrong because AWS Config detects but cannot prevent the action, and the remediation Lambda may have a delay.

192
MCQeasy

A company has a single AWS account and wants to implement a multi-account strategy for better isolation. Which AWS service is designed to help centrally manage multiple accounts?

A.AWS IAM
B.AWS Organizations
C.AWS Control Tower
D.AWS Service Catalog
AnswerB

AWS Organizations provides central governance over multiple accounts through organisational units and service control policies, enabling consolidated billing and policy-based guardrails. It directly satisfies the stem's requirement for centrally managing multiple accounts, whereas IAM and Microsoft Entra ID govern identities within or across separate directories rather than provisioning AWS account structure itself.

Why this answer

AWS Organizations is the native AWS service designed to centrally manage multiple AWS accounts. It allows you to create a hierarchy of accounts with organizational units (OUs), apply service control policies (SCPs) for governance, and consolidate billing. This directly addresses the need for a multi-account strategy with centralized management.

Exam trap

The trap here is that candidates often confuse AWS Control Tower (a managed landing zone service) with AWS Organizations (the underlying account management service), but Control Tower relies on Organizations and is not the service designed for direct central management of multiple accounts.

How to eliminate wrong answers

Option A is wrong because AWS IAM is an identity and access management service for a single account; it cannot create or manage multiple accounts. Option C is wrong because AWS Control Tower is a higher-level service that uses AWS Organizations under the hood to set up a multi-account landing zone, but it is not the core service designed for central management—it is an orchestration layer. Option D is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., EC2, RDS) for end users; it does not manage multiple accounts or their structure.

193
MCQeasy

A company uses AWS Organizations with several OUs for different environments (dev, test, prod). They want to restrict the use of specific EC2 instance types in the prod OU only. Which approach should they use?

A.Create a separate AWS account for prod and use an IAM policy on the account.
B.Attach a service control policy (SCP) to the prod OU that denies ec2:RunInstances for non-approved instance types.
C.Attach an IAM policy to all users in the prod accounts that denies non-approved instance types.
D.Use AWS Config to detect non-approved instance types and terminate them.
AnswerB

An SCP attached to the prod OU sets the maximum permissions for every account beneath it, denying ec2:RunInstances unless the instance type is approved. This satisfies the OU-scoped constraint, restricting instance types in production only while leaving dev and test unaffected.

Why this answer

Service control policies (SCPs) are the correct mechanism to centrally restrict permissions across all accounts within an AWS Organizations organizational unit (OU). By attaching an SCP to the prod OU that denies ec2:RunInstances for non-approved instance types, you enforce a guardrail that applies to every principal (including root users) in all accounts under that OU, regardless of IAM policies. This ensures that even if a user or role has an IAM policy allowing all EC2 instances, the SCP will block the non-approved types.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking IAM policies can centrally restrict all accounts in an OU, when in fact SCPs are the only AWS Organizations feature that applies a guardrail across all accounts without requiring per-account configuration.

How to eliminate wrong answers

Option A is wrong because creating a separate account for prod does not by itself restrict instance types; you would still need an SCP or IAM policy to enforce the restriction, and IAM policies on a single account cannot centrally manage multiple accounts. Option C is wrong because IAM policies attached to users in prod accounts can be overridden by other IAM policies or bypassed by users with administrative privileges, and they do not apply to the root user or services running without an explicit IAM role. Option D is wrong because AWS Config is a detective control that can detect non-approved instance types after they are launched, but it cannot prevent the launch; it would require a separate remediation action (e.g., Lambda) to terminate instances, which is reactive and not a preventive restriction.

194
MCQeasy

A company uses AWS Organizations and has a requirement that all root user activities in member accounts must be immediately reported to the security team. Which combination of actions should be taken to meet this requirement? (Choose the best answer.)

A.Enable AWS CloudTrail and use Amazon Athena to query logs periodically and send a report.
B.Enable AWS CloudTrail in all accounts with a trail that logs management events and delivers to a centralized S3 bucket. Use Amazon CloudWatch Events to create a rule that matches root user API calls and sends notifications via Amazon SNS.
C.Use AWS Config rules to detect root user activities and trigger an AWS Lambda function to send an email.
D.Use AWS Trusted Advisor to check for root user usage and generate a weekly report.
AnswerB

CloudTrail with management events captures root user API activity across all member accounts, satisfying the immediate reporting requirement. A CloudWatch Events rule matching those root calls then triggers Amazon SNS notifications, delivering real-time alerts to the security team without polling or delay.

Why this answer

It combines AWS CloudTrail logging of management events across all accounts into a centralized S3 bucket with Amazon CloudWatch Events (now Amazon EventBridge) to detect root user API calls in real time. This setup ensures immediate notification via Amazon SNS, meeting the requirement for instant reporting without manual polling or batch processing.

Exam trap

The trap here is that candidates may confuse AWS Config rules (which monitor resource configurations) with CloudTrail event monitoring, or assume periodic tools like Athena or Trusted Advisor can satisfy an immediate reporting requirement.

How to eliminate wrong answers

Option A is wrong because using Amazon Athena to query logs periodically introduces a delay (not immediate reporting) and requires manual or scheduled queries, which does not meet the real-time requirement. Option C is wrong because AWS Config rules are designed for resource configuration compliance and change detection, not for monitoring API calls like root user activities; they cannot directly capture CloudTrail events or root user login actions. Option D is wrong because AWS Trusted Advisor provides a weekly report on root user usage, which is not immediate and fails the requirement for real-time notification.

195
MCQeasy

A company is migrating to AWS and plans to use a multi-account strategy. The management account will be used solely for administrative purposes. Which best practice should be followed when setting up AWS Organizations?

A.Enable all AWS services in the management account to centrally manage them.
B.Use the management account as the payer account and also host production workloads.
C.Restrict access to the management account and use it only for organization management tasks.
D.Use the management account for development environments to avoid creating additional accounts.
AnswerC

The management account holds root-level control over every member account, so credentials there grant sweeping privileges. Restricting access and limiting its use to organisation management tasks satisfies the stem's requirement that it serve solely administrative purposes, reducing blast radius if compromised.

Why this answer

The management account in AWS Organizations should be strictly restricted and used only for organization-wide administrative tasks, such as managing member accounts, applying service control policies (SCPs), and consolidating billing. This follows the AWS Well-Architected Framework's security pillar, which recommends isolating the management account from any workload or resource deployment to minimize the blast radius of a potential compromise. Using the management account for anything other than organization management violates the principle of least privilege and increases security risk.

Exam trap

The trap here is that candidates often confuse the management account's billing role with a permission to host workloads, or they assume that central management requires enabling all services in the management account, when in fact the management account should be kept as a lightweight, resource-free administrative container.

How to eliminate wrong answers

Option A is wrong because enabling all AWS services in the management account for central management is unnecessary and insecure; instead, services should be enabled only in the member accounts where they are needed, and the management account should not host resources. Option B is wrong because while the management account is the payer account, hosting production workloads in it violates the best practice of isolating the management account from workloads, increasing the attack surface and risk of privilege escalation. Option D is wrong because using the management account for development environments defeats the purpose of a multi-account strategy, which is to isolate environments for security and cost tracking; development workloads should be placed in dedicated member accounts.

196
MCQeasy

A company has a multi-account AWS environment with a centralized network account that hosts a transit gateway. The company wants to share the transit gateway with multiple member accounts. Which AWS service should be used to share the transit gateway?

A.AWS Resource Access Manager (RAM)
B.AWS PrivateLink
C.VPC peering connection
D.AWS Direct Connect
AnswerA

AWS Resource Access Manager is the only service that natively shares a transit gateway across accounts, satisfying the centralised network account requirement. It lets the owner account specify which member accounts may attach VPCs, avoiding duplicated TGWs or peering.

Why this answer

AWS Resource Access Manager (RAM) enables you to share a transit gateway owned by a central network account with other AWS accounts in your organization. This eliminates the need to create separate transit gateway attachments or VPC peering connections, simplifying network architecture and reducing operational overhead.

Exam trap

The trap here is that candidates often confuse VPC peering (which is point-to-point and non-transitive) with transit gateway sharing via RAM, which provides transitive routing and centralized management across multiple accounts.

How to eliminate wrong answers

Option B is wrong because AWS PrivateLink is used to expose services privately within a VPC via interface endpoints, not for sharing transit gateways across accounts. Option C is wrong because VPC peering connects individual VPCs directly but does not provide a centralized hub-and-spoke model or support transitive routing between multiple VPCs and accounts. Option D is wrong because AWS Direct Connect establishes dedicated network connections from on-premises to AWS, not for sharing transit gateways between accounts.

197
MCQeasy

A company wants to provide its developers with access to a shared development environment in AWS. The developers are in different AWS accounts, and they need to assume an IAM role in the development account. What is the secure way to allow cross-account access?

A.Use a service control policy to allow access from other accounts
B.Create IAM users in the development account for each developer
C.Share the access keys of an IAM user in the development account
D.Create an IAM role in the development account with a trust policy that allows the developers' accounts to assume it
AnswerD

A trust policy on the development account's role names each developer account as principal, so cross-account sts:AssumeRole succeeds without sharing long-term credentials. This satisfies the requirement that developers in separate AWS accounts assume a role in the development account, and it works alongside Microsoft Entra ID federation rather than replacing it.

Why this answer

It uses an IAM role with a trust policy that explicitly grants principals from other AWS accounts permission to assume the role. This is the standard secure method for cross-account access, as it avoids sharing long-term credentials and allows temporary, scoped access via AWS Security Token Service (STS) AssumeRole API.

Exam trap

The trap here is that candidates often confuse service control policies (SCPs) with IAM policies, thinking SCPs can grant cross-account access, but SCPs only act as a guardrail and cannot allow access that isn't already explicitly granted by IAM policies.

How to eliminate wrong answers

Option A is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an AWS Organizations hierarchy; they cannot grant access or allow cross-account access—they only deny or allow permissions within the organization. Option B is wrong because creating IAM users in the development account for each developer from other accounts violates the principle of least privilege and requires managing separate credentials, which is insecure and not scalable for cross-account access. Option C is wrong because sharing access keys of an IAM user exposes long-term credentials, which increases the risk of credential leakage and violates AWS security best practices for cross-account access.

198
MCQmedium

A company uses AWS Organizations with consolidated billing. The finance team needs to track costs by department, which are tagged with 'department' tags. However, some resources are not tagged. The team wants to ensure that all new resources are tagged, and existing untagged resources are identified. What should they do?

A.Use a service control policy (SCP) to deny resource creation without the 'department' tag, and use AWS Config rules to detect untagged resources.
B.Use AWS Config rules to enforce tagging on existing resources and automatically tag them.
C.Use AWS Cost Explorer to report on untagged resources.
D.Create an IAM policy that requires tagging for all actions and attach it to all users.
AnswerA

SCPs set the maximum available permissions for accounts in AWS Organizations, so denying resource creation without the 'department' tag enforces tagging on new resources. AWS Config rules continuously evaluate existing resources and flag untagged ones, satisfying both the prevention and detection requirements.

Why this answer

It combines two complementary AWS services to solve both requirements. A service control policy (SCP) can deny the creation of any resource that does not include the required 'department' tag, enforcing tagging at the organization level across all accounts. AWS Config rules can then be used to detect existing untagged resources by evaluating resources against a desired tagging configuration, providing visibility into non-compliant resources without automatically modifying them.

Exam trap

The trap here is that candidates may confuse AWS Config's ability to detect non-compliance with the ability to automatically remediate (e.g., apply tags), or assume that Cost Explorer can enforce tagging, when in fact it only reports on existing tags.

How to eliminate wrong answers

Option B is wrong because AWS Config rules can detect untagged resources but cannot automatically tag them; they only evaluate compliance and can trigger remediation actions (e.g., via Systems Manager Automation), but the statement 'automatically tag them' is misleading as Config itself does not apply tags. Option C is wrong because AWS Cost Explorer is a cost visualization and analysis tool that can filter by tags but cannot enforce tagging on new resources or identify untagged resources in a proactive manner; it only reports on costs associated with tagged resources. Option D is wrong because IAM policies that require tagging for all actions would apply to API calls made by users, but they cannot enforce tagging on resources created by services (e.g., Auto Scaling, CloudFormation) that may not pass the tag condition, and such a policy would be overly restrictive, potentially blocking legitimate operations that do not support tagging.

199
MCQeasy

A company is using AWS Organizations and wants to allow certain member accounts to create VPCs with specific CIDR ranges. Which mechanism should be used to enforce this restriction?

A.Use AWS Config rules to automatically delete non-compliant VPCs.
B.Use IAM policies with conditions on the ec2:CreateVpc action in each account.
C.Use AWS CloudTrail to monitor VPC creation and alert the security team.
D.Use SCPs with conditions on the ec2:CreateVpc action, specifying allowed CIDR ranges.
AnswerD

SCPs can deny VPC creation if the CIDR does not match allowed ranges.

Why this answer

SCPs (Service Control Policies) are the correct mechanism because they allow you to centrally control the maximum available permissions for all IAM users and roles in member accounts within an AWS Organization. By attaching an SCP with a condition key like `ec2:CreateVpc` and specifying allowed CIDR ranges (e.g., using `StringEquals` or `IpAddress` condition operators), you can enforce that only VPCs with permitted CIDR blocks can be created across all affected accounts, regardless of local IAM policies.

Exam trap

The trap here is that candidates often confuse IAM policies (which are account-specific and can be overridden by local admins) with SCPs (which are organization-wide guardrails that cannot be bypassed by member account administrators), leading them to choose Option B instead of the correct preventive control.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect non-compliant VPCs and trigger remediation (e.g., deletion), but they are reactive and cannot prevent the creation of a non-compliant VPC in the first place; the VPC would exist momentarily, potentially causing transient security or networking issues. Option B is wrong because IAM policies with conditions on `ec2:CreateVpc` would need to be applied individually to each member account's IAM roles/users, which is operationally complex and does not prevent a rogue admin with full IAM permissions in that account from bypassing the restriction. Option C is wrong because AWS CloudTrail only logs API calls after they occur; it cannot enforce or block the creation of a VPC, only alert after the fact, which is not a preventive control.

200
Multi-Selectmedium

A company wants to implement a least-privilege security model across multiple AWS accounts. Which TWO services can help enforce this?

Select 2 answers
A.AWS Key Management Service (KMS)
B.AWS Organizations Service Control Policies (SCPs)
C.AWS Config
D.AWS Identity and Access Management (IAM) Access Analyzer
E.AWS CloudTrail
AnswersB, D

SCPs set the permissions boundary for every IAM principal in member accounts, so they cap what identity policies can ever grant. This makes them the mechanism for enforcing least privilege centrally across accounts, rather than relying on per-account IAM review.

Why this answer

AWS Organizations Service Control Policies (SCPs) (B) are correct because they set permission guardrails at the organization, OU, or account level, defining the maximum permissions available to IAM principals in member accounts, which directly enforces least privilege across multiple accounts. IAM Access Analyzer (D) is correct because it analyzes resource-based policies and IAM policies to identify resources shared with external entities or unused permissions, generating findings that help teams tighten access to only what is needed. AWS KMS (A) is a key management and encryption service, not a mechanism for enforcing least-privilege access boundaries across accounts.

AWS Config (C) evaluates resource configuration compliance but does not itself restrict or grant permissions. AWS CloudTrail (E) provides API activity logging and auditing, which supports detection and investigation rather than enforcement of least privilege.

Exam trap

The trap here is that candidates often confuse AWS Config (which detects compliance) with a service that enforces policies, or they think KMS or CloudTrail can restrict permissions, when in fact only SCPs and IAM Access Analyzer (for validating policies against least-privilege) directly support enforcing or validating a least-privilege model across multiple accounts.

← PreviousPage 3 of 3 · 200 questions total

Ready to test yourself?

Try a timed practice session using only Design Solutions for Organizational Complexity questions.