Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a multi-account AWS environment with a central security account. The security team needs to audit all API activity across all accounts and retain the logs for 7 years in a tamper-evident manner. They also need to ensure that no account administrator can disable or modify the logging configuration. Which solution meets these requirements?

⚠ Common exam trap

The trap here is assuming that CloudTrail Lake or AWS Config can replace a properly configured organization trail with S3 Object Lock for tamper-evident auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an organization trail in AWS CloudTrail that applies to all accounts, deliver logs to a central S3 bucket in the security account, enable S3 Object Lock in compliance mode, and use SCPs to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail.

An organization trail in CloudTrail centralizes logging across all accounts, delivering to a central S3 bucket. S3 Object Lock in compliance mode ensures logs cannot be deleted or altered for the retention period, meeting tamper-evident requirements. SCPs prevent member accounts from stopping or deleting the trail. This solution provides the necessary audit coverage, retention, and protection against administrative tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail Lake to aggregate all events, set a retention period of 7 years, and use AWS KMS to encrypt the event data store.

    Why it's wrong here

    AWS CloudTrail Lake is a managed data lake for CloudTrail events, but it does not provide tamper-evident storage with object lock. While it supports long retention, it does not prevent administrators from modifying or deleting the event data store if they have permissions. It also does not automatically apply to all accounts without an organization trail.

  • ✗

    Enable AWS Config in all accounts to record API activity, deliver snapshots to a central S3 bucket, and use AWS Config rules to monitor changes.

    Why it's wrong here

    AWS Config records resource configurations and changes, not API activity. It is not a replacement for CloudTrail for auditing API calls. While it can deliver snapshots to S3, it does not provide the comprehensive API activity logging required. It also does not prevent administrators from disabling logging.

  • ✗

    Create individual trails in each account, deliver logs to a central S3 bucket, enable versioning and MFA delete on the bucket, and use IAM policies to restrict access to the bucket.

    Why it's wrong here

    Individual trails require manual setup and maintenance per account, increasing operational overhead and risk of misconfiguration. Versioning and MFA delete provide some protection but do not prevent an account administrator from stopping logging or deleting the trail itself. IAM policies alone cannot prevent a determined administrator with sufficient permissions from disabling logging.

  • ✓

    Create an organization trail in AWS CloudTrail that applies to all accounts, deliver logs to a central S3 bucket in the security account, enable S3 Object Lock in compliance mode, and use SCPs to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail.

    Why this is correct

    An organization trail automatically applies to all accounts in the organization and delivers logs to a central S3 bucket. S3 Object Lock in compliance mode prevents deletion or modification of log objects for the retention period. SCPs deny actions that could disable logging. This combination provides centralized, tamper-evident logging with long-term retention and protection against administrative interference.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.