Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

Which TWO actions should a company take to implement a least-privilege access model across multiple AWS accounts? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often confuse SCPs with IAM permissions policies, thinking SCPs grant access rather than acting as a deny-only guardrail, or they mistakenly believe long-term access keys or shared root credentials are acceptable for cross-account access when they are explicitly anti-patterns for least-privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use IAM roles in each account with cross-account trust from a central identity provider, granting only required permissions.

Option A is correct because IAM roles with cross-account trust let users assume temporary credentials from a central identity provider (e.g., AWS IAM Identity Center or an external IdP via STS AssumeRole), so each account grants only the specific permissions the role needs, which is the essence of least privilege. Option B is correct because AWS Organizations service control policies (SCPs) set a permissions guardrail that denies high-risk actions (such as disabling CloudTrail or leaving the organization) across all member accounts, preventing privilege escalation even if an identity policy would otherwise allow it. Option C is wrong because generating long-term access keys for every user violates least privilege and key-rotation best practices; temporary credentials via roles are preferred. Option D is wrong because sharing root user credentials is a severe security anti-pattern—root has unrestricted access and should be protected with MFA and never shared. Option E is wrong because creating IAM users with full administrator access in every account grants excessive permissions and directly contradicts a least-privilege model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use IAM roles in each account with cross-account trust from a central identity provider, granting only required permissions.

    Why this is correct

    Cross-account IAM roles with trust policies let identities federate from a central provider and assume only scoped permissions in each account, eliminating long-lived credentials. This directly enforces least privilege across accounts by granting the minimum required permissions per role.

  • ✓

    Apply SCPs to deny high-risk actions across all accounts.

    Why this is correct

    SCPs define permission guardrails at the OU or account level, denying high-risk actions regardless of identity-based policies. Applying them across all accounts enforces least privilege by capping the maximum permissions any principal can exercise, satisfying the multi-account constraint.

  • ✗

    Generate long-term access keys for each user in the central account.

    Why it's wrong here

    Long-term access keys are static credentials that persist until manually rotated, so a leaked key grants indefinite access and cannot satisfy least privilege. Generating keys is tempting for programmatic access to the central account, where temporary credentials from IAM roles or AWS IAM Identity Center would be the correct mechanism.

  • ✗

    Share the root user credentials of each account with the central team.

    Why it's wrong here

    Root user credentials cannot be scoped by IAM policies, so sharing them grants unrestricted, unrevocable control and defeats least privilege. Sharing is tempting as a shortcut for central administration, but root access should be reserved for the few tasks that require it, with federated roles used instead.

  • ✗

    Create IAM users in each account with full administrator access for all users.

    Why it's wrong here

    Full administrator access directly contradicts least privilege, granting every user unrestricted permissions across the account. It is tempting because creating IAM users is a familiar way to give people access, and it would be correct only in a sandbox account where broad permissions are deliberately required for experimentation.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.