Solutions Architect Professional · 26% of the exam

Design Solutions for Organizational Complexity: free practice questions

5 sample questions from our 15-question bank for this domain — answers and explanations included. These are the same scenario-based style as the real AWS exam.

1. An enterprise wants centralized, federated workforce access to all its AWS accounts using existing corporate identities (via SAML), with permission sets mapped to roles. Which service should the architect recommend?

  • A. AWS IAM Identity Center (successor to AWS SSO)✓ Correct
  • B. Creating IAM users in every account
  • C. Sharing root credentials
  • D. Amazon Cognito user pools for employees
Explanation

IAM Identity Center provides centralized, federated single sign-on to multiple accounts with permission sets, integrating corporate identity providers via SAML. Per-account IAM users (B) don't scale and fragment identity, sharing root (C) is a severe risk, and Cognito (D) targets application end users, not workforce SSO to accounts.

2. A multinational company must keep certain workloads' data within specific countries for sovereignty, while still governing all accounts centrally. Which combination BEST enforces the data-residency guardrail?

  • A. Region-restricting SCPs on the relevant OUs, combined with central governance via Control Tower/Organizations✓ Correct
  • B. Trusting each team to only deploy in-country
  • C. A single global VPC
  • D. Disabling CloudTrail to avoid cross-Region logs
Explanation

Region-restricting SCPs on the OUs enforce that workloads can only deploy in approved (in-country) Regions, while Control Tower/Organizations provide central governance — a preventive, enforceable residency guardrail. Trust (B) isn't enforcement, a global VPC (C) doesn't constrain Regions, and disabling CloudTrail (D) harms auditability.

3. A large enterprise must prevent any account in its 'Sandbox' organizational unit from using AWS Regions other than us-east-1 and eu-west-1, regardless of the account's own IAM policies. What should the solutions architect implement?

  • A. A Service Control Policy (SCP) attached to the Sandbox OU that denies actions outside the allowed Regions✓ Correct
  • B. An IAM policy in each account allowing only those Regions
  • C. A resource-based policy on each S3 bucket
  • D. A permissions boundary on every user
Explanation

SCPs set the maximum permissions for accounts in an OU and cannot be overridden by account-level IAM — a Region-restricting SCP on the OU enforces the guardrail organization-wide. Per-account IAM (B) can be changed by account admins, a bucket policy (C) only affects S3, and permissions boundaries (D) apply per principal and are easy to miss across accounts.

4. An architect must ensure that even if a developer creates an overly permissive IAM policy in a member account, that user still cannot delete CloudTrail logging or disable security services. What is the BEST control?

  • A. A Service Control Policy denying the specific security-critical actions across the organization✓ Correct
  • B. Trusting developers to follow guidelines
  • C. A CloudWatch alarm after the fact
  • D. An IAM permissions boundary applied to some users
Explanation

An SCP that explicitly denies actions like disabling CloudTrail or GuardDuty sets an organization-wide guardrail that no account-level policy can override — a preventive control. Guidelines (B) aren't enforced, an alarm (C) is detective (after the fact), and permissions boundaries (D) must be applied per principal and can be missed.

5. A hybrid architecture needs many on-premises sites and AWS VPCs interconnected, with the ability to add new VPCs and sites easily and route between them centrally. Which pairing BEST supports this at scale?

  • A. AWS Transit Gateway with Direct Connect (and/or Site-to-Site VPN) attachments✓ Correct
  • B. One VPN tunnel per VPC pair, fully meshed
  • C. A NAT gateway shared across all sites
  • D. Public IP addresses on all resources
Explanation

Transit Gateway centralizes routing among many VPCs and on-premises connections (via Direct Connect gateway and/or VPN attachments), scaling cleanly as sites/VPCs are added. Full-mesh VPNs (B) don't scale, a NAT gateway (C) provides outbound internet not inter-network routing, and public IPs (D) are insecure and unmanaged.

10 more questions in this domain

Practice the full bank with instant grading, flashcards, and a timed mock exam.

Start practicing free
Design Solutions for Organizational Complexity — Free Solutions Architect Professional Practice Questions | DataCertPrep — Certification Prep