A DevOps engineer is setting up centralized logging for a multi-account environment using AWS Organizations. The engineer needs to aggregate logs from all accounts into a single Amazon S3 bucket. Which TWO steps are necessary?
The central S3 bucket needs a resource-based policy that explicitly grants the source accounts' log-delivery services (e.g., CloudTrail, VPC Flow Logs) permission to write objects and read the bucket ACL. Without this bucket policy, cross-account writes from other accounts will be denied by default. The policy must reference the source account IDs or the organization ID and include conditions like aws:SourceAccount or aws:SourceArn to prevent confused deputy attacks. This is a mandatory step to enable centralized log collection.
Why this answer
A bucket policy on the central S3 bucket can grant cross-account permissions to source accounts to write logs. This allows services like CloudTrail and VPC Flow Logs from member accounts to deliver logs directly to the central bucket without requiring IAM roles in each account for reading logs.
Exam trap
The trap here is that candidates often confuse the need for IAM roles in each account (Option A) with the correct bucket policy approach, or they assume that enabling an organization trail (Option C) is mandatory when the question allows for individual account configuration.