Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company is designing a multi-account strategy using AWS Organizations. They want to enforce that no one can disable AWS CloudTrail in any account. Which TWO methods can achieve this?

⚠ Common exam trap

Candidates often confuse IAM permissions boundaries or Trusted Advisor alerts as preventive controls, but only SCPs provide a true preventive guardrail that cannot be overridden by account administrators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a Service Control Policy (SCP) that denies disabling or deleting CloudTrail.

Option B is correct because an SCP attached at the organization, OU, or account level in AWS Organizations can explicitly deny the CloudTrail actions that stop or delete a trail (for example cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail), which centrally prevents any principal in member accounts from disabling CloudTrail. Option D is correct because AWS Config can evaluate CloudTrail configuration with a managed rule such as cloudtrail-enabled and trigger automatic remediation (for example via SSM Automation) to re-enable logging if a trail is stopped or deleted, restoring the desired state. Option A is not correct because Trusted Advisor only provides advisory checks and alerts; it cannot enforce or prevent the disabling of CloudTrail. Option C is not correct because AWS Shield Advanced is a DDoS protection service and has no role in controlling CloudTrail configuration. Option E is not correct because IAM permissions boundaries only limit the maximum permissions of an IAM entity and do not by themselves enforce organization-wide denial of CloudTrail changes across all accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Trusted Advisor to alert when CloudTrail is disabled.

    Why it's wrong here

    Alerts do not prevent disabling.

  • ✓

    Attach a Service Control Policy (SCP) that denies disabling or deleting CloudTrail.

    Why this is correct

    SCPs define the maximum permissions for principals in member accounts, so a deny statement for cloudtrail:StopLogging and DeleteTrail blocks the action at the Organizations level before IAM is evaluated, satisfying the requirement that no one in any account can disable CloudTrail.

  • ✗

    Use AWS Shield Advanced to protect CloudTrail.

    Why it's wrong here

    Shield is for DDoS protection.

  • ✓

    Use AWS Config rules with auto-remediation to re-enable CloudTrail if disabled.

    Why this is correct

    Config can detect and automatically re-enable.

  • ✗

    Use IAM permissions boundaries to restrict user permissions.

    Why it's wrong here

    Permissions boundaries do not apply to the root user.

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.