SAP-C02 exam dumps

SAP-C02 practice question 4 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 4

Single answer

A multinational organization has multiple AWS accounts for its business units, each with its own application workloads. The organization wants to centralize governance, enforce compliance rules, and manage permissions across all accounts. Additionally, they need to ensure that each business unit retains some level of autonomy for managing their respective resources. Which AWS solution would best address these requirements?

  1. A

    Use AWS Control Tower to set up a multi-account environment with guardrails and delegate permissions to accounts via service control policies (SCPs).

  2. B

    Use AWS IAM Identity Center (formerly AWS SSO) to centrally manage user permissions and enable resource management across all accounts.

  3. C

    Use AWS Organizations to create a multi-account structure, apply service control policies (SCPs), and link accounts for centralized billing.

  4. D

    Use AWS Config to monitor resource compliance and enforce rules across all accounts while allowing individual accounts to self-manage their resources.

Show answer and explanation

Correct answer: A

Explanation

AWS Control Tower is the best solution for this scenario as it is specifically designed to set up and manage a secure, multi-account AWS environment. It provides features like guardrails (SCPs and Config rules) for governance and compliance while allowing accounts to retain autonomy for resource management. While other options provide partial functionality, they do not offer the complete centralized governance and compliance framework required.

  • A. Correct.

    Correct: AWS Control Tower provides a comprehensive solution for setting up and governing a multi-account environment. It enables centralized governance using guardrails (SCPs and Config rules) while allowing individual accounts to manage their own resources.

  • B. Incorrect.

    Incorrect: While AWS IAM Identity Center can centrally manage user permissions across accounts, it does not provide the governance or compliance enforcement features required for this scenario.

  • C. Incorrect.

    Incorrect: AWS Organizations helps in creating a multi-account structure and implementing SCPs, but it does not provide a full governance and compliance framework like AWS Control Tower does.

  • D. Incorrect.

    Incorrect: AWS Config is useful for monitoring compliance and enforcing rules, but it does not handle centralized governance, account setup, or permissions management as described in the scenario.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam