SAP-C02 exam dumps

SAP-C02 practice question 1 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 1

Single answer

Your organization has a multi-account AWS environment with accounts for different business units and environments (e.g., production, staging, development). The organization wants to enforce consistent security policies across all accounts, such as requiring encryption for all S3 buckets and restricting the creation of publicly accessible RDS instances. Additionally, each business unit needs the flexibility to manage their own resources within their accounts. Which solution would best address these requirements?

  1. A

    Use AWS Organizations with Service Control Policies (SCPs) to enforce security policies across all accounts, while allowing each account to manage its own resources.

  2. B

    Use AWS Config rules in each account to enforce security policies, and centralize compliance reporting using AWS Config Aggregators.

  3. C

    Set up AWS IAM roles in each account with strict policies, and manually ensure that all accounts comply with the security requirements.

  4. D

    Create a single AWS account for the entire organization and use tags to segregate resources by business unit, applying security policies at the account level.

Show answer and explanation

Correct answer: A

Explanation

AWS Organizations with Service Control Policies (SCPs) is the most effective solution for enforcing consistent security policies across a multi-account AWS environment. SCPs provide centralized control over permissions, ensuring that accounts adhere to organizational security requirements while allowing them to manage their own resources within those boundaries. This approach is scalable, reduces management overhead, and aligns with AWS best practices for multi-account setups.

  • A. Correct.

    This is the correct solution. AWS Organizations with SCPs enable you to enforce security policies across all accounts by applying restrictions at the organization level. SCPs ensure compliance while still allowing individual accounts the flexibility to manage their own resources within the defined boundaries.

  • B. Incorrect.

    While AWS Config can be used to enforce and monitor compliance, managing rules independently across multiple accounts can be operationally complex. AWS Config Aggregators help centralize reporting, but they do not enforce policies as effectively as SCPs at the organizational level.

  • C. Incorrect.

    This approach requires significant manual effort and lacks the centralized governance provided by AWS Organizations and SCPs. It is prone to human error and does not scale well for large organizations.

  • D. Incorrect.

    Using a single AWS account for the entire organization and relying on tags to segregate resources is not a recommended practice for multi-account environments. It sacrifices security isolation and governance, and it doesn't effectively enforce organizational-level policies.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam