SAP-C02 Practice Question: Design Solutions for Organizational Complexity
Which TWO AWS services can be used to automate the enforcement of compliance policies across multiple AWS accounts? (Choose TWO.)
⚠ Common exam trap
Watch out — candidates often confuse monitoring services (CloudTrail, VPC Flow Logs) with enforcement services, or assume that infrastructure deployment tools (CloudFormation StackSets) inherently enforce compliance, when in fact they only provision resources without policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations SCPs
AWS Organizations Service Control Policies (SCPs) are correct because they attach at the OU or account level and set the maximum available permissions for member accounts, thereby automatically enforcing compliance guardrails (e.g., denying use of unapproved regions or services) across many accounts at once. AWS Config rules are correct because they continuously evaluate resource configurations against desired compliance policies and can trigger automatic remediation (via SSM Automation documents) across accounts when aggregated with a Config aggregator, enabling automated enforcement. AWS CloudTrail only records API activity for auditing and does not enforce policy, so it is not correct. AWS CloudFormation StackSets deploys resources across accounts but does not itself enforce compliance policies, so it is not correct. Amazon VPC Flow Logs capture IP traffic metadata for monitoring and troubleshooting, not policy enforcement, so it is not correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity for auditing and forensic review; it does not evaluate or enforce policy state across accounts. It is the right choice when the requirement is capturing who did what, rather than preventing non-compliant resource configurations.
- ✓
AWS Organizations SCPs
Why this is correct
AWS Organizations service control policies centrally restrict the maximum available permissions across every member account, satisfying the multi-account enforcement constraint. Attaching an SCP to an organisational unit or the root immediately denies non-compliant actions organisation-wide, regardless of each account's own IAM policies, giving automated, preventive governance rather than detective-only monitoring.
- ✗
AWS CloudFormation StackSets
Why it's wrong here
StackSets deploys CloudFormation templates across accounts and Regions, but it provisions resources rather than continuously evaluating and remediating drift against compliance rules. It fits standardised infrastructure rollout, whereas ongoing policy enforcement requires a dedicated governance service.
- ✗
Amazon VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture network traffic metadata for diagnostics and security analysis; they neither define nor remediate compliance rules across accounts. They are correct when investigating connectivity or anomalous traffic patterns, not enforcing configuration standards.
- ✓
AWS Config rules
Why this is correct
AWS Config rules continuously evaluate resource configurations against desired settings and can be deployed across accounts via AWS Organizations conformance packs, satisfying the requirement to automate compliance enforcement at scale. They detect non-compliant resources and can trigger remediation through SSM Automation, providing the multi-account policy enforcement the stem demands.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.