nerdexam
Amazon

SAP-C02 · Question #872

A company is migrating its entire IT portfolio to AWS. The company requires a centralized payment management solution for several business units. The solution must provide visibility into each…

The correct answer is B. Use AWS Organizations to create a new organization from a payer account. Define an OU E. Enable all features of AWS Organizations. Establish appropriate SCPs that filter IAM permissions. You can meet the requirements by setting up a central AWS Organizations structure with a payer account that manages all other accounts. Each business unit keeps its own account, which gives visibility into individual spending while consolidating billing at the organizational…

Submitted by haruto_sh· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company is migrating its entire IT portfolio to AWS. The company requires a centralized payment management solution for several business units. The solution must provide visibility into each business unit's spending. A security team requires a centralized solution to control IAM usage in all the company's AWS accounts. The security team requires that production workloads run in separate accounts. Each business unit in the company has a separate AWS account. Which combination of actions will meet these requirements with the LEAST effort? (Choose two.)

Options

  • AUse a collection of parameterized AWS CloudFormation templates to define common IAM
  • BUse AWS Organizations to create a new organization from a payer account. Define an OU
  • CConsolidate all of the company's business units into a single AWS account. Use tags to track
  • DEnsure that each business unit continues to use its own AWS account. Tag each AWS account
  • EEnable all features of AWS Organizations. Establish appropriate SCPs that filter IAM permissions

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    72% (23)
  • C
    19% (6)
  • D
    3% (1)

Explanation

You can meet the requirements by setting up a central AWS Organizations structure with a payer account that manages all other accounts. Each business unit keeps its own account, which gives visibility into individual spending while consolidating billing at the organizational level. Then, by enabling all features in AWS Organizations, you can create and attach Service Control Policies (SCPs) that centrally enforce IAM restrictions across the organization. This provides the security team with a single point of governance for IAM usage, while still allowing workloads such as production systems to run in dedicated, isolated accounts.

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice