Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 76 pages
Exam (elaborations)

AWS Certified Solutions Architect – Professional (SAP-C02) Practice Exam 150 Advanced Multiple Choice Questions with Answers and Rationales a well detailed one 2025 / 2026 written and graded A+ upgraded

Document preview thumbnail
Preview 4 out of 76 pages

AWS Certified Solutions Architect – Professional (SAP-C02) Practice Exam 150 Advanced Multiple Choice Questions with Answers and Rationales a well detailed one 2025 / 2026 written and graded A+ upgraded

Content preview

1




AWS Certified Solutions Architect
– Professional (SAP-C02) Practice
Exam 150 Advanced Multiple-
Choice Questions with Answers
and Rationales a well detailed
one written and
graded A+ upgraded




Exam Title: AWS Certified Solutions Architect – Professional (SAP-C02) Practice Exam: 150
Advanced Scenario-Based Questions Covering Organizational Complexity, New Solution Design,
Continuous Improvement, and Workload Migration & Modernization



Domain 1: Design Solutions for Organizational Complexity (26%)

Questions 1–39

, 2




Question 1

A multinational enterprise operates 200+ AWS accounts across multiple business units. The
security team requires that no IAM user in any member account can create an S3 bucket with
public read access. The organization uses AWS Organizations with all accounts under a single
management account. Which solution provides centralized enforcement with the LEAST
operational overhead?

A. Create an IAM policy in each member account denying s3:PutBucketPublicAccess and attach
it to all IAM users.

B. Deploy AWS Config rules in each account to detect publicly accessible S3 buckets and trigger
automated remediation via Systems Manager.

C. Create a Service Control Policy (SCP) at the root OU that
denies s3:PutBucketPublicAccess and s3:PutBucketAcl actions when the request would make
the bucket publicly accessible.

D. Enable S3 Block Public Access at the AWS Organizations level using the S3 Block Public Access
account settings for all member accounts.

- detailed answer 100% correct :- D

Rationale: S3 Block Public Access settings can be applied at the AWS Organizations level to all
member accounts, providing centralized, account-level enforcement without requiring per-
account policy management. SCPs (Option C) cannot evaluate the effect of a request (whether it
makes a bucket public) — they can only deny specific API actions unconditionally. Option A
requires per-account management and is not centrally enforced. Option B is reactive (detect
and remediate) rather than preventive.



Question 2

A company uses AWS Organizations with consolidated billing across 50 accounts. The finance
team needs to allocate costs to individual project teams accurately. Each team has multiple
accounts tagged with Project: <name>. However, the finance team reports that Cost Explorer
shows significant untagged costs. What is the MOST effective approach to enforce tagging
compliance?

A. Create an IAM policy requiring the Project tag on all resources and attach it to all IAM roles.

, 3



B. Enable tag policies in AWS Organizations, define a tag policy requiring the Project tag on all
resources, and attach it to all OUs.

C. Use AWS Budgets to alert when untagged resources exceed 5% of monthly spend.

D. Create a Lambda function that runs hourly, identifies untagged resources, and applies a
default Project: Unknown tag.

- detailed answer 100% correct :- B

Rationale: AWS Organizations Tag Policies allow centralized enforcement of tag compliance
across all member accounts. Tag policies can specify required tags and prevent non-compliant
resource creation. Option A is insufficient as IAM policies cannot enforce tagging on all resource
types globally. Option C only provides alerts, not enforcement. Option D is reactive and adds
operational overhead.



Question 3

A solutions architect is designing a multi-account strategy for a financial services firm. The firm
requires:

• Complete isolation between production and non-production environments

• Centralized logging and security monitoring

• Delegated administration for networking and security teams

• Ability to share a common network across all accounts

Which combination of AWS services and configurations should the architect recommend?

A. Create separate OUs for Production and Non-Production. Use AWS Control Tower to set up a
landing zone. Use AWS Resource Access Manager (RAM) to share subnets from a central
networking account. Delegate administration to OU-specific administrators.

B. Create all accounts directly under the root. Use VPC peering between all production accounts
and all non-production accounts. Enable CloudTrail in each account with a central S3 bucket.

C. Use a single VPC with multiple subnets and network ACLs to isolate environments. Create
IAM roles for each team.

D. Create separate AWS accounts for each environment. Use Transit Gateway with route tables
to isolate production from non-production. Use AWS Organizations SCPs for delegation.

- detailed answer 100% correct :- A

, 4



Rationale: AWS Control Tower provides a prescriptive landing zone with OUs, guardrails, and
centralized governance. RAM enables VPC subnet sharing from a central networking account.
OU-based delegation provides appropriate administrative boundaries. Option B lacks
organizational structure and isolation. Option C violates the isolation requirement. Option D
does not address landing zone or subnet sharing.



Question 4

A company has deployed AWS Control Tower to manage its multi-account environment. The
security team has enabled mandatory guardrails, including SCPs that restrict regions to us-east-
1 and us-west-2. A development team needs to deploy a solution in eu-west-1 for a temporary
proof of concept. What is the MOST efficient way to allow this while maintaining security
posture?

A. Create a new OU with a SCP that allows all regions. Move the development account to this
OU temporarily.

B. Disable the region restriction guardrail for all accounts, then re-enable after the POC.

C. Create a service control policy that explicitly allows eu-west-1 and attach it directly to the
development account, overriding the OU-level SCP.

D. Request AWS Support to exempt the development account from the Control Tower guardrail.

- detailed answer 100% correct :- A

Rationale: OUs in AWS Organizations provide logical grouping for policy application. Creating a
dedicated OU with relaxed SCPs allows temporary exceptions without compromising the overall
governance structure. SCPs are evaluated hierarchically — the most restrictive policy takes
precedence, so attaching a permissive policy to an account that inherits a restrictive OU policy
would not override it (Option C is incorrect). Option B impacts all accounts. Option D is not a
standard practice.



Question 5

A global enterprise with 500+ AWS accounts needs to implement centralized logging. The
requirements are:

• All CloudTrail logs, VPC Flow Logs, and application logs must be aggregated

• Logs must be retained for 7 years for compliance

Document information

Uploaded on
July 25, 2026
Number of pages
76
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$28.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions