Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

A company uses AWS Organizations with multiple member accounts. The SysOps administrator needs to deploy a common AWS CloudFormation template that creates an IAM role across all member accounts in the organization. Which AWS service should be used to deploy this template across accounts?

⚠ Common exam trap

Many candidates confuse AWS Service Catalog's ability to launch templates in individual accounts with automatic multi-account deployment, overlooking that StackSets is the only service designed for bulk, automated deployment across all organization accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudFormation StackSets

AWS CloudFormation StackSets is the correct service because it extends CloudFormation functionality to deploy templates across multiple accounts and regions from a single management account. StackSets uses a self-managed or service-managed permission model, and with AWS Organizations, it can automatically deploy to all member accounts in the organization or specified organizational units (OUs), making it ideal for deploying a common IAM role across all accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudFormation StackSets

    Why this is correct

    AWS CloudFormation StackSets is the correct answer because it is the native, purpose-built service for deploying the same CloudFormation template across multiple AWS accounts and Regions from a single operation. StackSets uses a delegated administrator account to create stack instances in target accounts with optional automatic deployment and drift detection, and it supports organizational unit (OU) targeting directly through AWS Organizations. This makes it the most efficient and maintainable way to enforce consistent infrastructure, such as security baselines, across an entire organization.

  • ✗

    AWS CodePipeline with cross-account deployment actions

    Why it's wrong here

    AWS CodePipeline with cross-account deployment actions is incorrect because it is a CI/CD orchestration service, not a multi-account infrastructure provisioning tool. While CodePipeline can use cross-account actions (such as deploying to an S3 bucket or invoking an AWS Lambda in another account), each cross-account action requires IAM roles in both the pipeline account and the target account, and the pipeline must be explicitly configured with a role assumption per stage. It also lacks the ability to infer target accounts from AWS Organizations OUs like StackSets, so for deploying the exact same template to all member accounts, it requires significant per-account boilerplate and does not scale as cleanly.

  • ✗

    AWS CloudFormation cross-stack references

    Why it's wrong here

    AWS CloudFormation cross-stack references are incorrect because they only work within a single AWS account and a single Region. A cross-stack reference uses an Export from one stack and an Fn::ImportValue in another stack to share resource identifiers like an S3 bucket name or a VPC ID, but these exports cannot be resolved across different accounts or Regions. Therefore, this mechanism cannot deploy infrastructure to multiple member accounts in AWS Organizations.

  • ✗

    AWS Service Catalog

    Why it's wrong here

    AWS Service Catalog is incorrect because it is a governance and catalog service that lets administrators create, approve, and version products (CloudFormation templates), which end users can then provision in their own accounts. It does not automatically deploy or push portfolios and products across all member accounts; instead, it enables self-service provisioning by individual users or accounts that have been granted access. While it can enforce compliance and standardization, the deployment is user-initiated rather than an automatic organization-wide rollout, so it does not meet the requirement of ensuring a template is deployed to every member account.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.