AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A global enterprise operates 300 production accounts in an AWS Organizations OU called Workloads. Four custom service control policies (SCPs) are attached directly to that OU. The cloud center of excellence has deployed an AWS Control Tower landing zone and wants to register the Workloads OU while immediately enabling two preventive guardrails: Disallow creation of access keys for the root user and Disallow public read access to Amazon S3 buckets.

During a dry-run in a test organization, the Register OU operation fails with the message "Exceeds maximum number of SCPs".

As the lead solutions architect, what is the MOST effective way to ensure that the Workloads OU can be successfully registered in AWS Control Tower without losing the intent of the existing custom policies?

  • Temporarily disable one custom SCP, register the OU, re-enable Control Tower guardrails, and then attach the disabled policy to every account in the OU instead of the OU itself.

  • Open a support ticket to raise the maximum number of SCPs that can be attached to an OU above five, then register the OU and enable the guardrails.

  • Consolidate the four custom SCPs into a single SCP, detach the original policies, attach the consolidated SCP to the Workloads OU, and then register the OU and enable the guardrails.

  • Create a new parent OU, move Workloads under the parent, register the parent OU with Control Tower, and rely on the child OU to inherit the existing SCPs.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot