1
AWS Certified Solutions
Architect – Professional
(SAP-C02) Practice Exam
v2.0 150 Advanced
Multiple-Choice Questions
with Answers and
Rationales a well
detailed one 2025 /
, 2
2026 written and graded
A+ upgraded
Exam Title: AWS Certified Solutions Architect – Professional (SAP-C02) Practice Exam v2.0: 150
Advanced Scenario-Based Questions Covering Organizational Complexity, New Solution Design,
Continuous Improvement, and Workload Migration & Modernization
Domain 1: Design Solutions for Organizational Complexity (26%)
Questions 1–39
Question 1
A global financial institution operates 300+ AWS accounts across 12 business units. The
compliance team requires that all IAM roles in production accounts must have a session
duration of no more than 1 hour. The company uses AWS Organizations with SCPs. Which
solution provides centralized enforcement?
A. Create an IAM policy in each production account that restricts sts:AssumeRole session
duration to 1 hour.
B. Create an SCP that denies sts:AssumeRole when the sts:RoleSessionDuration condition key
exceeds 3600 seconds.
C. Use AWS Config rules to detect roles with session duration > 1 hour and trigger remediation.
D. Configure AWS IAM Identity Center with a permission set that limits session duration to 1
hour for all roles.
, 3
- detailed answer 100% correct :- B
Rationale: SCPs can enforce session duration limits using the sts:RoleSessionDuration condition
key. This provides organization-wide enforcement. Option A requires per-account management.
Option C is reactive. Option D only applies to Identity Center users, not all IAM roles.
Question 2
A company has implemented AWS Control Tower with a landing zone. The security team wants
to add a custom preventive guardrail that prevents the creation of S3 buckets with public read
access across all accounts. Which approach should be used?
A. Create an SCP and attach it to the root OU.
B. Use AWS Control Tower's built-in S3 public access guardrail.
C. Create a CloudFormation StackSet that deploys bucket policies to all accounts.
D. Use AWS Config with automatic remediation.
- detailed answer 100% correct :- A
Rationale: AWS Control Tower allows custom SCPs to be created and attached to OUs. SCPs
provide preventive controls at the organization level. Option B may not cover all scenarios.
Option C is reactive. Option D is detective, not preventive.
Question 3
A multinational enterprise uses AWS Organizations with consolidated billing. The finance team
needs to allocate costs to individual projects. Each project spans multiple accounts and uses
resources across multiple regions. Which AWS service should be used for cost allocation?
A. AWS Cost Explorer with tag-based filtering
B. AWS Cost Categories
C. AWS Budgets with tag-based alerts
D. AWS Pricing Calculator
- detailed answer 100% correct :- B
Rationale: AWS Cost Categories allow grouping of costs across accounts, regions, and tags into
custom categories like projects. This provides flexibility when projects span multiple accounts.
, 4
Cost Explorer (A) can filter but not create custom categories. Budgets (C) are for alerts. Pricing
Calculator (D) is for estimation.
Question 4
A company has 150 AWS accounts organized by environment (Dev, Test, Staging, Production)
and business unit. The security team requires that all resources in Production accounts must be
tagged with Environment: Production and DataClassification. Which AWS Organizations feature
should be used?
A. Service Control Policies (SCPs)
B. Tag Policies
C. AI services opt-out policies
D. Backup policies
- detailed answer 100% correct :- B
Rationale: AWS Organizations Tag Policies enforce tag compliance across accounts. They can
require specific tags and prevent creation of non-compliant resources. SCPs (A) are for
permission boundaries. AI services opt-out policies (C) are for AI services. Backup policies (D)
are for backup configuration.
Question 5
A company wants to implement a hub-and-spoke network architecture with a central Transit
Gateway in a networking account. The company has 50 VPCs across 30 accounts. Which service
enables VPC attachments from all accounts?
A. AWS Resource Access Manager (RAM)
B. VPC Peering
C. AWS PrivateLink
D. AWS Direct Connect Gateway
- detailed answer 100% correct :- A
Rationale: AWS RAM enables sharing of Transit Gateways across accounts within an AWS
Organization. This allows member accounts to attach their VPCs to the central Transit Gateway.
AWS Certified Solutions
Architect – Professional
(SAP-C02) Practice Exam
v2.0 150 Advanced
Multiple-Choice Questions
with Answers and
Rationales a well
detailed one 2025 /
, 2
2026 written and graded
A+ upgraded
Exam Title: AWS Certified Solutions Architect – Professional (SAP-C02) Practice Exam v2.0: 150
Advanced Scenario-Based Questions Covering Organizational Complexity, New Solution Design,
Continuous Improvement, and Workload Migration & Modernization
Domain 1: Design Solutions for Organizational Complexity (26%)
Questions 1–39
Question 1
A global financial institution operates 300+ AWS accounts across 12 business units. The
compliance team requires that all IAM roles in production accounts must have a session
duration of no more than 1 hour. The company uses AWS Organizations with SCPs. Which
solution provides centralized enforcement?
A. Create an IAM policy in each production account that restricts sts:AssumeRole session
duration to 1 hour.
B. Create an SCP that denies sts:AssumeRole when the sts:RoleSessionDuration condition key
exceeds 3600 seconds.
C. Use AWS Config rules to detect roles with session duration > 1 hour and trigger remediation.
D. Configure AWS IAM Identity Center with a permission set that limits session duration to 1
hour for all roles.
, 3
- detailed answer 100% correct :- B
Rationale: SCPs can enforce session duration limits using the sts:RoleSessionDuration condition
key. This provides organization-wide enforcement. Option A requires per-account management.
Option C is reactive. Option D only applies to Identity Center users, not all IAM roles.
Question 2
A company has implemented AWS Control Tower with a landing zone. The security team wants
to add a custom preventive guardrail that prevents the creation of S3 buckets with public read
access across all accounts. Which approach should be used?
A. Create an SCP and attach it to the root OU.
B. Use AWS Control Tower's built-in S3 public access guardrail.
C. Create a CloudFormation StackSet that deploys bucket policies to all accounts.
D. Use AWS Config with automatic remediation.
- detailed answer 100% correct :- A
Rationale: AWS Control Tower allows custom SCPs to be created and attached to OUs. SCPs
provide preventive controls at the organization level. Option B may not cover all scenarios.
Option C is reactive. Option D is detective, not preventive.
Question 3
A multinational enterprise uses AWS Organizations with consolidated billing. The finance team
needs to allocate costs to individual projects. Each project spans multiple accounts and uses
resources across multiple regions. Which AWS service should be used for cost allocation?
A. AWS Cost Explorer with tag-based filtering
B. AWS Cost Categories
C. AWS Budgets with tag-based alerts
D. AWS Pricing Calculator
- detailed answer 100% correct :- B
Rationale: AWS Cost Categories allow grouping of costs across accounts, regions, and tags into
custom categories like projects. This provides flexibility when projects span multiple accounts.
, 4
Cost Explorer (A) can filter but not create custom categories. Budgets (C) are for alerts. Pricing
Calculator (D) is for estimation.
Question 4
A company has 150 AWS accounts organized by environment (Dev, Test, Staging, Production)
and business unit. The security team requires that all resources in Production accounts must be
tagged with Environment: Production and DataClassification. Which AWS Organizations feature
should be used?
A. Service Control Policies (SCPs)
B. Tag Policies
C. AI services opt-out policies
D. Backup policies
- detailed answer 100% correct :- B
Rationale: AWS Organizations Tag Policies enforce tag compliance across accounts. They can
require specific tags and prevent creation of non-compliant resources. SCPs (A) are for
permission boundaries. AI services opt-out policies (C) are for AI services. Backup policies (D)
are for backup configuration.
Question 5
A company wants to implement a hub-and-spoke network architecture with a central Transit
Gateway in a networking account. The company has 50 VPCs across 30 accounts. Which service
enables VPC attachments from all accounts?
A. AWS Resource Access Manager (RAM)
B. VPC Peering
C. AWS PrivateLink
D. AWS Direct Connect Gateway
- detailed answer 100% correct :- A
Rationale: AWS RAM enables sharing of Transit Gateways across accounts within an AWS
Organization. This allows member accounts to attach their VPCs to the central Transit Gateway.