Home › Certifications › AWS Certified Solutions Architect SAP-C02 › Design Solutions for Organizational Complexity
40 multiple-choice questions and 27 flashcards on Design Solutions for Organizational Complexity, about 27% of the AWS Certified Solutions Architect SAP-C02 bank. Every one carries a written rationale.
Design Solutions for Organizational Complexity is one of 4 chapters in CoStudy's AWS Certified Solutions Architect — Professional (SAP-C02) bank, and it holds 40 of the bank's 150 multiple-choice questions — roughly 27% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
6 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
AWS Transit Gateway is BEST used for:
Answer: C — Central hub-and-spoke connectivity for many VPCs and on-premises networks at scale
C) TGW is a hub-and-spoke network transit service. A) That is CloudFront. B) That is Storage Gateway. D) TGW does not replace IAM.
An enterprise runs on-prem AD and is acquiring a company on Okta; both must federate to AWS via a single Identity Center instance. Which approach is BEST?
Answer: D — Pick one external identity source per Identity Center instance and federate the second organization into it via SAML during integration
D) Identity Center allows only one external identity source per instance; pick one and federate the other. A) Two external sources are not supported simultaneously. B) Bypassing Identity Center for Okta forfeits central federation. C) Manual IAM users defeat federation.
A firm managing 100+ AWS accounts needs uniform guardrails, centralized logging, and enterprise SSO. Which combination BEST meets all three?
Answer: A — AWS Organizations with Control Tower guardrails, IAM Identity Center, and a dedicated Log Archive account
A) Control Tower provisions Landing Zone guardrails, Identity Center centralizes SSO, and a Log Archive account aggregates CloudTrail. B) Per-account IAM users scale poorly and duplicate logs. C) A single account fails isolation and blast-radius requirements. D) Multiple Organizations fragment billing and governance.
Sandbox accounts must allow arbitrary EC2 launches but stop all provisioning once a $500 monthly spend is breached, automatically. Which is BEST?
Answer: D — AWS Budgets with Budget Action attaching a deny IAM policy to all roles on threshold breach plus Cost Anomaly Detection
D) Budget Actions are purpose-built to attach a deny policy on breach. A) Time-based deny does not reflect spend. B) Custom and slow. C) Email alerts are detective-only.
A security team wants ML-based threat detection aggregated across every account in the Organization. Which is BEST?
Answer: C — Amazon GuardDuty enabled Organization-wide with a delegated administrator account
C) GuardDuty with a delegated admin is the Organization-wide threat detection service. A) WAF only inspects web traffic. B) Config detects configuration state, not threats. D) Inspector scans vulnerabilities, not runtime threats.
Cross-account access in AWS is BEST implemented via:
Answer: A — IAM roles with trust policies allowing principals in another account to assume via STS
A) IAM cross-account roles + STS assume-role is the canonical pattern. B) Hardcoded keys are the anti-pattern. C) Shared root is the anti-pattern. D) Email is not an AWS auth mechanism.
4 cards from the 27 in this chapter.
Organizational Units (OUs) purpose?
Logical groupings of accounts. Apply policies hierarchically.
AWS Config conformance packs?
Bundle of rules for compliance frameworks (HIPAA, PCI, etc.). Deploy across org.
VPC Endpoints types?
Gateway (S3, DynamoDB) and Interface (most other AWS services, uses ENI).
Tag policies in Organizations?
Standardize tagging across accounts. Enforce required tags.
These are a sample. The full Design Solutions for Organizational Complexity chapter runs 67 items with per-chapter progress tracking, on the web and in the iOS app.
Open AWS Certified Solutions Architect SAP-C02 in CoStudy →
All AWS Certified Solutions Architect SAP-C02 practice questions →