SOA-C02 Deployment, Provisioning, and Automation Practice Question
A company has a multi-account AWS environment using AWS Organizations. The SysOps Administrator needs to deploy a standardized set of baseline resources (VPC, subnets, security groups, and an S3 bucket for logs) into each new member account as soon as the account is created. The administrator wants to automate this process using AWS CloudFormation and ensure that the baseline resources are deployed without manual intervention. The organization uses AWS CloudTrail and AWS Config for governance. What solution should the administrator implement?
⚠ Common exam trap
SOA-C02 often tests the difference between reactive compliance tools (AWS Config, Trusted Advisor) and proactive provisioning tools (StackSets, Service Catalog); candidates wrongly pick Config or Lambda-based automation when the question asks for automatic deployment to new accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation StackSets with automatic deployment to accounts in the organization.
AWS CloudFormation StackSets with automatic deployment is purpose-built for this scenario: it deploys a single template across multiple accounts in an AWS Organization and can automatically push the stack to new member accounts as they are added. The 'automatic deployment' setting enables StackSets to target the entire OU or organization, so new accounts inherit the baseline resources without manual intervention. This directly satisfies the requirement to deploy VPC, subnets, security groups, and an S3 log bucket into each new account automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS CloudFormation StackSets with automatic deployment to accounts in the organization.
Why this is correct
AWS CloudFormation StackSets with automatic deployment is the native, service-integrated method for account baselining. When a new account is added to an AWS Organization, StackSets with service-managed permissions automatically creates stack instances in that account, using the organization's trusted access to deploy the baseline template. This eliminates the need for custom event-driven orchestration and ensures consistent governance across the entire organization.
- ✗
Create an AWS Config rule that triggers an AWS Lambda function to deploy the baseline resources when a new account is created.
Why it's wrong here
AWS Config rules continuously evaluate resource configurations against desired policies, but they are not provisioning mechanisms. A Config rule invokes a Lambda function for compliance evaluation, not for creating or deploying resources, and account creation events do not trigger Config rule evaluations. Even if the Lambda attempted to deploy a stack, the rule's purpose and event source mismatch this use case entirely.
- ✗
Store the CloudFormation template in Amazon S3 and use S3 event notifications to trigger a Lambda function that deploys the stack into the new account.
Why it's wrong here
Amazon S3 event notifications respond to object lifecycle operations like a PUT or POST to a bucket, not to AWS Organization account creation events. To trigger deployment on a new account, the event must originate from the account creation process, which S3 is not involved in. Furthermore, using a Lambda function to deploy into the new account would require additional cross-account role assumptions, making this approach overly complex compared to StackSets.
- ✗
Use AWS Service Catalog to create a portfolio with the baseline products and grant access to the organization.
Why it's wrong here
AWS Service Catalog provides portfolios and products that enable users to provision resources on demand via a self-service catalog, but it has no mechanism to automatically deploy baseline resources when an account joins an organization. Each new account would still require a user to manually provision the product, which defeats the goal of automated account baseline creation. It is useful for governance and approved-products, not for automated account bootstrapping.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
6 more ways this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has multiple AWS accounts managed under AWS Organizations. The SysOps administrator needs to deploy a common AWS CloudFormation template to all accounts in a specific organizational unit (OU), ensuring consistent security group configurations across the organization. Which AWS service should the administrator use to perform this deployment?
medium- ✓ A.AWS CloudFormation StackSets
- B.AWS CodePipeline with cross-account actions
- C.AWS Service Catalog portfolio
- D.AWS Systems Manager Automation
Why A: AWS CloudFormation StackSets extends the functionality of CloudFormation by allowing you to deploy a common template across multiple accounts and regions from a single management account. In this scenario, the administrator can target the specific organizational unit (OU) within AWS Organizations, ensuring consistent security group configurations are applied to all member accounts without manual intervention.
Variation 2. A company manages multiple AWS accounts under AWS Organizations. The SysOps administrator needs to deploy a baseline set of AWS Config rules and an Amazon SNS topic to each account in the organization. The deployment must be centrally managed from the management account and automatically applied to any new member account added in the future. Which solution should the administrator use?
medium- ✓ A.Create an AWS CloudFormation StackSet with the template containing the AWS Config rules and SNS topic. Configure the StackSet to deploy to the organization and enable automatic deployment to new accounts.
- B.Use AWS Service Catalog to create a product that bundles the AWS Config rules and SNS topic. Grant each account access to launch the product.
- C.Configure AWS Config conformance packs in the management account and use AWS Resource Access Manager to share them with member accounts.
- D.Create an AWS Organizations Service Control Policy (SCP) that enforces the creation of AWS Config rules and SNS topics in every account.
Why A: AWS CloudFormation StackSets can be deployed to an entire AWS Organizations organization or organizational units (OUs), and they support automatic deployment to new accounts added to the organization. By creating a StackSet with a template that defines the AWS Config rules and SNS topic, and enabling automatic deployment, the administrator ensures that every current and future member account receives the baseline configuration without manual intervention.
Variation 3. A company uses AWS Organizations with multiple member accounts. The SysOps administrator needs to deploy a common AWS CloudFormation template that creates an IAM role across all member accounts in the organization. Which AWS service should be used to deploy this template across accounts?
medium- ✓ A.AWS CloudFormation StackSets
- B.AWS CodePipeline with cross-account deployment actions
- C.AWS CloudFormation cross-stack references
- D.AWS Service Catalog
Why A: AWS CloudFormation StackSets is the correct service because it extends CloudFormation functionality to deploy templates across multiple accounts and regions from a single management account. StackSets uses a self-managed or service-managed permission model, and with AWS Organizations, it can automatically deploy to all member accounts in the organization or specified organizational units (OUs), making it ideal for deploying a common IAM role across all accounts.
Variation 4. A SysOps administrator is tasked with automating the deployment of an application across multiple AWS accounts. Which AWS service should be used to orchestrate the deployment across accounts?
easy- A.AWS CodeDeploy
- ✓ B.AWS CloudFormation StackSets
- C.AWS Service Catalog
- D.AWS Systems Manager
Why B: AWS CloudFormation StackSets allows a single CloudFormation template to be deployed across multiple AWS accounts and regions from a central administrator account. It is purpose-built for cross-account orchestration, using a service-managed or self-managed permission model to push stacks to target OUs or accounts. This makes it the correct service for automating multi-account deployments.
Variation 5. A SysOps administrator needs to deploy a CloudFormation stack across multiple AWS accounts in an organization using AWS Organizations. The administrator wants to use a single template and a single deployment operation. Which AWS service should be used to centrally manage the deployment?
easy- A.AWS Systems Manager
- B.AWS OpsWorks Stacks
- C.AWS CodePipeline
- ✓ D.AWS CloudFormation StackSets
Why D: AWS CloudFormation StackSets allows you to deploy a single CloudFormation template across multiple AWS accounts and regions with a single operation. It is designed for centralized management of stacks in an organization, leveraging AWS Organizations for automatic deployment to member accounts. This meets the requirement of using one template and one deployment operation across multiple accounts.
Variation 6. A SysOps administrator needs to deploy the same AWS CloudFormation template across multiple AWS accounts and Regions in a single operation. The administrator wants to manage the deployment from a single management account. Which AWS service should the administrator use?
medium- A.AWS CodeDeploy
- B.AWS Elastic Beanstalk
- ✓ C.AWS CloudFormation StackSets
- D.AWS Service Catalog
Why C: AWS CloudFormation StackSets extends the functionality of CloudFormation by allowing you to deploy the same template across multiple accounts and Regions from a single management account. StackSets uses a self-managed or service-managed permission model to create, update, and delete stacks across target accounts in a single operation, making it the correct choice for this multi-account, multi-Region deployment requirement.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.