nerdexam
Amazon

SAP-C02 · Question #599

A company is migrating its infrastructure to the AWS Cloud. The company must comply with a variety of regulatory standards for different projects. The company needs a multi-account environment. A…

The correct answer is B. Create an organization in AWS Organizations. Enable AWS Control Tower on the organization. The company needs a multi-account AWS environment with a consistent security baseline, flexibility for varying compliance, and on-premises AD FS integration, all with minimal operational overhead.

Submitted by joshua94· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company is migrating its infrastructure to the AWS Cloud. The company must comply with a variety of regulatory standards for different projects. The company needs a multi-account environment. A solutions architect needs to prepare the baseline infrastructure. The solution must provide a consistent baseline of management and security, but it must allow flexibility for different compliance requirements within various AWS accounts. The solution also needs to integrate with the existing on-premises Active Directory Federation Services (AD FS) server. Which solution meets these requirements with the LEAST amount of operational overhead?

Options

  • ACreate an organization in AWS Organizations. Create a single SCP for least privilege access
  • BCreate an organization in AWS Organizations. Enable AWS Control Tower on the organization.
  • CCreate an organization in AWS Organizations. Create SCPs for least privilege access. Create an
  • DCreate an organization in AWS Organizations. Enable AWS Control Tower on the organization.

How the community answered

(56 responses)
  • A
    16% (9)
  • B
    46% (26)
  • C
    32% (18)
  • D
    5% (3)

Why each option

The company needs a multi-account AWS environment with a consistent security baseline, flexibility for varying compliance, and on-premises AD FS integration, all with minimal operational overhead.

ACreate an organization in AWS Organizations. Create a single SCP for least privilege access

A "single SCP for least privilege access across all accounts" does not offer the necessary flexibility for varying compliance requirements between different projects within the organization.

BCreate an organization in AWS Organizations. Enable AWS Control Tower on the organization.Correct

Enabling AWS Control Tower provides a managed multi-account baseline with security guardrails and allows for custom preventive and detective guardrails to accommodate flexible compliance requirements across accounts. AWS IAM Identity Center (SSO) directly integrating with existing AD FS as an identity source provides seamless identity management with the least operational overhead.

CCreate an organization in AWS Organizations. Create SCPs for least privilege access. Create an

Setting up AWS Directory Service for Microsoft Active Directory and establishing a trust relationship adds significant operational overhead compared to directly integrating AD FS with AWS IAM Identity Center (SSO) as an external identity provider.

DCreate an organization in AWS Organizations. Enable AWS Control Tower on the organization.

Manually configuring individual AWS accounts and cross-account roles for AD FS integration increases operational overhead significantly compared to leveraging AWS Control Tower and AWS IAM Identity Center (SSO) for a managed baseline and identity federation.

Concept tested: AWS Control Tower, IAM Identity Center (SSO), AD FS integration, multi-account strategy

Source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice