SAA-C03 Design Secure Architectures Practice Question
A company uses AWS Organizations to manage multiple AWS accounts. A security engineer needs to prevent any IAM user in the organization from disabling AWS CloudTrail logging in any account. The solution must apply automatically to all existing and future accounts. What should the security engineer do?
⚠ Common exam trap
The trap here is thinking that IAM policies or permissions boundaries applied per-account can enforce organization-wide restrictions, when only SCPs can centrally deny actions across all accounts and principals, including root users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail organization trail and configure an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
Service control policies (SCPs) in AWS Organizations provide centralized control over the maximum available permissions for all accounts. By denying cloudtrail:StopLogging and cloudtrail:DeleteTrail, the SCP ensures that no principal, including root, can disable the organization trail. This solution automatically applies to all current and future accounts, satisfying the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable AWS CloudTrail organization trail and configure an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
Why this is correct
An organization trail applies to all accounts in the organization, and an SCP can deny the specific actions that would disable logging. SCPs are inherited by all accounts, including future ones, and affect all principals, including root users. This combination ensures CloudTrail cannot be disabled, meeting the requirement with minimal ongoing effort.
- ✗
Create an IAM policy that denies the cloudtrail:StopLogging action and attach it to all IAM users in each account.
Why it's wrong here
Attaching an IAM policy to every IAM user is not scalable and does not automatically cover future accounts or new users. It also does not prevent root user actions. A service control policy (SCP) in AWS Organizations is the correct mechanism to enforce restrictions across all accounts automatically, making this approach ineffective for the requirement.
- ✗
Use AWS Config to monitor CloudTrail configuration changes and trigger an AWS Lambda function to re-enable logging if it is stopped.
Why it's wrong here
AWS Config can detect changes, but the remediation is reactive and may allow a window where logging is disabled. It also requires custom Lambda code and does not prevent the action in the first place. The requirement is to prevent disabling, not to detect and revert, so this approach is insufficient and adds operational overhead.
- ✗
Create an IAM role in each account with a permissions boundary that denies cloudtrail:StopLogging and assign it to all users.
Why it's wrong here
Permissions boundaries limit the maximum permissions of an IAM entity but must be applied individually to each user or role, and they do not affect root users or automatically apply to new accounts. This manual approach does not scale and cannot guarantee organization-wide enforcement, making it unsuitable for the requirement.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.