DOP-C02 Monitoring and Logging Practice Question
A DevOps engineer is setting up centralized logging for a multi-account environment using AWS Organizations. The engineer needs to aggregate logs from all accounts into a single Amazon S3 bucket. Which TWO steps are necessary?
⚠ Common exam trap
Test-takers frequently confuse the need for IAM roles in each account (Option A) with the correct bucket policy approach, or they assume that enabling an organization trail (Option C) is mandatory when the question allows for individual account configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a bucket policy on the central S3 bucket that grants permissions to the source accounts.
A bucket policy on the central S3 bucket can grant cross-account permissions to source accounts to write logs. This allows services like CloudTrail and VPC Flow Logs from member accounts to deliver logs directly to the central bucket without requiring IAM roles in each account for reading logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create IAM roles in each account to allow the central bucket to read logs.
Why it's wrong here
Creating IAM roles in each account to allow the central bucket to read logs is unnecessary and misdirected. The central bucket does not read logs; it receives writes from services like CloudTrail and VPC Flow Logs. Instead, you must attach a bucket policy to the central bucket granting the source accounts (or their services) s3:PutObject and s3:GetBucketAcl permissions. IAM roles would be needed for cross-account read access, not for write, and they don't configure the services themselves.
- ✓
Create a bucket policy on the central S3 bucket that grants permissions to the source accounts.
Why this is correct
The central S3 bucket needs a resource-based policy that explicitly grants the source accounts' log-delivery services (e.g., CloudTrail, VPC Flow Logs) permission to write objects and read the bucket ACL. Without this bucket policy, cross-account writes from other accounts will be denied by default. The policy must reference the source account IDs or the organization ID and include conditions like aws:SourceAccount or aws:SourceArn to prevent confused deputy attacks. This is a mandatory step to enable centralized log collection.
- ✗
Enable CloudTrail organization trail in the management account to deliver logs to the central bucket.
Why it's wrong here
Enabling a CloudTrail organization trail in the management account is not sufficient for all centralized logging requirements. It automatically delivers CloudTrail events from all member accounts to a single bucket, but it does not configure VPC Flow Logs, ALB access logs, or other service logs. Those services must be separately configured in each account to deliver to the same bucket, and the bucket policy must still allow writes. Moreover, if you already want centralized logging beyond CloudTrail, this option only addresses one log source.
- ✗
Set up a cross-account subscription in CloudWatch Logs to forward logs to the central account.
Why it's wrong here
Setting up a cross-account subscription in CloudWatch Logs would require a Kinesis Data Stream or Lambda as the destination and is designed for streaming log data to a central account's CloudWatch Logs, not for delivering logs to S3. Since the goal is to have a central S3 bucket for long-term storage, this approach adds unnecessary complexity and does not directly enable S3 object delivery. It also does not replace the need for a bucket policy or per-service log delivery configuration.
- ✓
Configure each account’s services (e.g., CloudTrail, VPC Flow Logs) to deliver logs to the central S3 bucket.
Why this is correct
Each source account must explicitly configure its services (CloudTrail, VPC Flow Logs, etc.) to send logs to the central S3 bucket. This involves specifying the target S3 bucket, setting appropriate bucket names and key prefixes, and ensuring the IAM permissions or service-linked roles allow the cross-account delivery. Without this per-account configuration, the log data never leaves the source account, regardless of any bucket policy.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.