SCS-C02 AWS Organizations Practice Question
A company is implementing a multi-account strategy using AWS Organizations. The security team wants to enforce that all newly created member accounts automatically have an IAM role that allows read-only access to the management account. Which configuration should be used?
⚠ Common exam trap
SCS-C02 often tests the misconception that SCPs can create or manage resources, when they are only permission boundaries; candidates may also overlook StackSets' automatic deployment feature for new accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation StackSets to deploy the role to all existing and future accounts.
AWS CloudFormation StackSets is the correct service for deploying a common IAM role across multiple accounts, including automatically to new accounts as they are added to the organization. When you create a StackSet with service-managed permissions, you can enable automatic deployments so that the stack instance is created in every new account that joins the target organizational unit (OU). This directly satisfies the requirement to enforce the role's presence in all newly created member accounts without custom automation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an AWS Lambda function that listens for AWS CloudTrail CreateAccount events and creates the role in the new account.
Why it's wrong here
This approach requires configuring a CloudTrail trail to deliver CreateAccount events to Amazon EventBridge or S3, then invoking a Lambda function that assumes a role in the new account to create the target role. Unlike a managed, declarative solution, this introduces non-trivial orchestration and a delay between the account creation and the Lambda invocation. Furthermore, if the CloudTrail trail fails to deliver the event or the Lambda function errors, the role may never be provisioned in the new account, leaving the account without the required baseline.
- ✓
Use AWS CloudFormation StackSets to deploy the role to all existing and future accounts.
Why this is correct
AWS CloudFormation StackSets with service-managed permissions allows you to deploy a stack template that defines the IAM role to every account in your AWS Organization. When you enable automatic deployment and specify the organization-wide or OU-wide target, StackSets automatically deploys the stack to new accounts as they are created. This ensures the role exists in all existing and future accounts without requiring custom orchestration or event-driven logic.
- ✗
Use an AWS Config managed rule to evaluate new accounts and trigger a remediation action to create the role.
Why it's wrong here
AWS Config managed rules are designed to continuously evaluate existing AWS resources for compliance, and they can trigger remediation actions when a resource is non-compliant. However, they do not provision roles proactively for newly created accounts—they would only detect after the fact that an account lacks the role and then invoke a remediation, typically via a custom Lambda function. This introduces a delay and relies on a remediation action being implemented, plus Config is regional so you would need to set up the rule in every region you care about.
- ✗
Configure an SCP with the 'iam_role' setting to specify a role name and path to be automatically created in new accounts.
Why it's wrong here
AWS Service Control Policies (SCPs) are used to restrict permissions by adding deny or allow actions for IAM principals—they do not contain settings to automatically create IAM roles. There is no 'iam_role' setting in SCP syntax; SCPs only manage what actions are allowed, and they cannot specify a role name and path to create a role. To provision a role automatically when an account is created, you would use a CloudFormation StackSet or the Organizations API, not an SCP.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.