AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Acme Group has merged its healthcare business (subject to HIPAA) and its payment-processing subsidiary (subject to PCI-DSS). The company already uses AWS Organizations with all features enabled and operates centralized log-archive and security-tooling accounts in a dedicated Security OU. Leadership wants to 1) apply and audit guardrails for HIPAA and PCI workloads independently, 2) continue sharing the existing security services, 3) receive a single consolidated bill for the entire conglomerate, and 4) avoid additional operational overhead. Which multi-account and OU strategy best satisfies these requirements?

  • Keep all workload accounts in the current Workloads OU, attach both HIPAA and PCI-DSS SCP sets to that OU, and rely on cost-allocation tags to distinguish the two subsidiaries.

  • Place all healthcare and payment workloads in separate VPCs inside a single shared AWS account, enable AWS Control Tower detective guardrails, and use an AWS Cost Category to allocate each subsidiary's spend.

  • Expand the current organization by creating two top-level workload OUs (Healthcare and Payments), move the respective workload accounts into each OU, retain the Security OU with the shared log-archive and security-tooling accounts, and attach HIPAA-specific SCPs to the Healthcare OU and PCI-DSS SCPs to the Payments OU while using the existing management account for consolidated billing.

  • Create a separate AWS Organization for the payment subsidiary, enable consolidated billing in each organization, and share the log-archive account between the two organizations by using AWS Resource Access Manager.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot