Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

Which TWO AWS services can be used to automate the enforcement of compliance policies across multiple AWS accounts? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often confuse monitoring services (CloudTrail, VPC Flow Logs) with enforcement services, or assume that infrastructure deployment tools (CloudFormation StackSets) inherently enforce compliance, when in fact they only provision resources without policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations SCPs

AWS Organizations Service Control Policies (SCPs) are correct because they attach at the OU or account level and set the maximum available permissions for member accounts, thereby automatically enforcing compliance guardrails (e.g., denying use of unapproved regions or services) across many accounts at once. AWS Config rules are correct because they continuously evaluate resource configurations against desired compliance policies and can trigger automatic remediation (via SSM Automation documents) across accounts when aggregated with a Config aggregator, enabling automated enforcement. AWS CloudTrail only records API activity for auditing and does not enforce policy, so it is not correct. AWS CloudFormation StackSets deploys resources across accounts but does not itself enforce compliance policies, so it is not correct. Amazon VPC Flow Logs capture IP traffic metadata for monitoring and troubleshooting, not policy enforcement, so it is not correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records API activity for auditing and forensic review; it does not evaluate or enforce policy state across accounts. It is the right choice when the requirement is capturing who did what, rather than preventing non-compliant resource configurations.

  • ✓

    AWS Organizations SCPs

    Why this is correct

    AWS Organizations service control policies centrally restrict the maximum available permissions across every member account, satisfying the multi-account enforcement constraint. Attaching an SCP to an organisational unit or the root immediately denies non-compliant actions organisation-wide, regardless of each account's own IAM policies, giving automated, preventive governance rather than detective-only monitoring.

  • ✗

    AWS CloudFormation StackSets

    Why it's wrong here

    StackSets deploys CloudFormation templates across accounts and Regions, but it provisions resources rather than continuously evaluating and remediating drift against compliance rules. It fits standardised infrastructure rollout, whereas ongoing policy enforcement requires a dedicated governance service.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture network traffic metadata for diagnostics and security analysis; they neither define nor remediate compliance rules across accounts. They are correct when investigating connectivity or anomalous traffic patterns, not enforcing configuration standards.

  • ✓

    AWS Config rules

    Why this is correct

    AWS Config rules continuously evaluate resource configurations against desired settings and can be deployed across accounts via AWS Organizations conformance packs, satisfying the requirement to automate compliance enforcement at scale. They detect non-compliant resources and can trigger remediation through SSM Automation, providing the multi-account policy enforcement the stem demands.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.