Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has an AWS Organizations environment with a management account, a central log archive account, and many workload accounts. The security team must prevent workload accounts from disabling AWS CloudTrail, deleting the central log bucket, or leaving the organization, while still allowing account administrators to manage their own resources. (Choose two.)

⚠ Common exam trap

The trap here is choosing detective controls such as AWS Config rules or GuardDuty findings when the requirement is to prevent the actions from succeeding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an S3 bucket policy on the central log bucket that denies s3:DeleteBucket and s3:DeleteObject to all principals except a tightly scoped log archive role.

Preventive guardrails require controls that block actions rather than merely detect them. Service control policies applied to the workload OUs deny trail modification and organization departure for all principals in those accounts, while an S3 bucket policy protects the central log bucket from deletion. Together they enforce the security team's requirements without removing account administrators' ability to manage other resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS Config in every workload account and create a managed rule that flags noncompliant trails.

    Why it's wrong here

    AWS Config rules detect and report noncompliance; they do not block the actions themselves. An administrator could still stop or delete a trail before a rule reports it, so Config alone does not prevent the prohibited operations the security team must stop.

  • ✗

    Enable Amazon GuardDuty in the management account to alert on attempts to disable logging.

    Why it's wrong here

    GuardDuty is a threat detection service that generates findings; it does not prevent configuration changes or enforce policy. It might surface suspicious activity after the fact, but it cannot stop a workload administrator from stopping a trail or leaving the organization.

  • ✗

    Use IAM permissions boundaries on all roles in workload accounts to remove the ability to modify CloudTrail.

    Why it's wrong here

    Permissions boundaries limit the maximum permissions of a specific identity but must be attached to each role and can be changed by anyone with IAM permissions in the account. They are not organization-wide guardrails and are easily bypassed by creating a new role without the boundary.

  • ✓

    Create an S3 bucket policy on the central log bucket that denies s3:DeleteBucket and s3:DeleteObject to all principals except a tightly scoped log archive role.

    Why this is correct

    A resource-based bucket policy on the central log bucket restricts destructive S3 actions to a specific role, so workload accounts cannot delete the bucket or its objects even if their identity policies allow S3 access. This complements the organization-level controls by protecting the log destination itself.

  • ✓

    Attach a service control policy to the workload OUs that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and organizations:LeaveOrganization.

    Why this is correct

    Service control policies set the maximum permissions for principals in member accounts and apply regardless of identity-based policies. Denying the specified actions at the OU level prevents even account administrators from stopping trails, deleting trails, or leaving the organization, which directly enforces the security team's guardrails.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.