Courseiva
Design Solutions for Organizational ComplexityhardMultiple SelectObjective-mapped

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a multi-account environment and wants to centralize logging for all AWS API calls. Which TWO services should they use together to achieve this?

⚠ Common exam trap

It's easy for candidates to confuse Amazon S3 as a logging service rather than a storage destination, or they mistakenly think GuardDuty or AWS Config can replace CloudTrail for capturing API calls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS CloudTrail

AWS CloudTrail is the service that records all AWS API calls made in an account, capturing the who, what, when, and source IP for every action. To centralize these logs from multiple accounts into a single location, you can configure CloudTrail to deliver log files to a centralized Amazon S3 bucket, and then use Amazon CloudWatch Logs to monitor, search, and alert on those API events in real time. Together, they provide a complete, centralized logging and monitoring solution for API activity across a multi-account environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS CloudTrail

    Why this is correct

    Logs API calls.

  • Amazon CloudWatch Logs

    Why this is correct

    Can receive logs from multiple accounts via subscription.

  • Amazon GuardDuty

    Why it's wrong here

    Threat detection, not logging.

  • Amazon S3

    Why it's wrong here

    Storage only, does not aggregate.

  • AWS Config

    Why it's wrong here

    Logs resource changes, not API calls.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,660 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SAP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a multi-account AWS environment. They want to use AWS CloudTrail to log all API calls across all accounts and deliver the logs to a central S3 bucket in the logging account. They have configured a trail in the management account that logs management events for all accounts. However, they notice that the logs from member accounts are not being delivered to the central S3 bucket. What is the most likely cause?

easy
  • A.CloudTrail cannot log management events for member accounts from the management account.
  • B.The S3 bucket policy does not grant the CloudTrail service principal from member accounts write access.
  • C.The trail is configured to log only read events.
  • D.The member accounts have disabled CloudTrail.

Why B: A trail in the management account can log management events for all accounts, but it requires that the trail be created with the option 'Apply trail to all accounts in the organization' and the S3 bucket policy must allow CloudTrail to write from member accounts. Option A is wrong because there is no such limitation. Option C is wrong because CloudTrail supports cross-account delivery. Option D is wrong because the bucket policy is likely the issue.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.