SAP-C02 Organization Trail Practice Question
A company uses AWS Organizations and wants to establish a central logging solution. They need to collect CloudTrail logs from all accounts and store them in a central S3 bucket in the management account. Which TWO steps are required to achieve this?
⚠ Common exam trap
The trap is thinking that individual CloudTrail enablement in each member account is necessary. In reality, creating an organization trail in the management account automatically enables CloudTrail in all accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new CloudTrail trail in the management account with organization trail enabled.
To centrally collect CloudTrail logs from all accounts in an AWS Organization, create an organization trail in the management account (C) which automatically enables CloudTrail in all member accounts and logs management events. Then configure that trail to deliver logs to a central S3 bucket in the management account (D). No individual account CloudTrail enablement is required because the organization trail handles it automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an AWS Config rule to monitor CloudTrail configuration.
Why it's wrong here
Config rule is optional and not a required step.
- ✗
Apply a service control policy (SCP) to enforce CloudTrail logging.
Why it's wrong here
SCPs are not required; the organization trail covers all accounts.
- ✓
Create a new CloudTrail trail in the management account with organization trail enabled.
Why this is correct
Correct. Creating an organization trail in the management account automatically enables CloudTrail across all member accounts.
- ✓
Configure the trail to deliver logs to a central S3 bucket in the management account.
Why this is correct
Correct. Configuring the trail to deliver logs to a central S3 bucket in the management account ensures centralized storage.
- ✗
Enable CloudTrail in each member account individually.
Why it's wrong here
Incorrect. Individual CloudTrail enablement is not required because the organization trail automatically enables CloudTrail in all member accounts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 1,660 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.