Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has an AWS Organizations structure with a management account and 200 member accounts. The security team wants to prevent any member account from disabling AWS CloudTrail or deleting the organization trail. They also want to ensure that only the management account can create new trails. Which solution meets these requirements with the least operational overhead?

⚠ Common exam trap

The trap here is relying on detective controls such as AWS Config or per-account IAM policies, which do not prevent the action before it occurs and do not cover the account root user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Organizations service control policies (SCPs) to deny cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:CreateTrail in all member accounts, while allowing these actions in the management account.

Service control policies in AWS Organizations provide centralized, preventive control over member accounts, including the root user, and automatically apply to new accounts. Denying StopLogging and DeleteTrail protects the organization trail, while denying CreateTrail ensures trail creation is limited to the management account, meeting the requirements with minimal operational effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS Organizations service control policies (SCPs) to deny cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:CreateTrail in all member accounts, while allowing these actions in the management account.

    Why this is correct

    SCPs applied at the organization or OU level centrally restrict actions in all member accounts, including the root user, and automatically apply to new accounts. Denying StopLogging and DeleteTrail protects the trail, and denying CreateTrail ensures only the management account can create trails, with minimal ongoing effort.

  • ✗

    Use AWS CloudFormation StackSets to deploy a trail in each member account and set the trail to use an S3 bucket in the management account.

    Why it's wrong here

    Deploying a trail per account does not prevent member accounts from stopping or deleting their local trail, and a member account could still create additional trails. StackSets adds deployment overhead and does not enforce the restriction centrally.

  • ✗

    Create an IAM policy in each member account that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail, and attach it to all IAM roles.

    Why it's wrong here

    Manually creating and attaching IAM policies in 200 accounts is high operational overhead and can be bypassed by users with permission to modify IAM policies. It also does not prevent the root user of a member account from making changes, and it does not scale with new accounts.

  • ✗

    Enable AWS Config in all member accounts with a managed rule that checks for CloudTrail logging and automatically remediates with a Lambda function.

    Why it's wrong here

    AWS Config rules detect noncompliance but do not prevent the action in real time; remediation occurs after the fact. A malicious actor could disable logging and delete the trail before remediation runs, and the solution requires deploying and maintaining Config and Lambda in every account, adding overhead.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.