Courseiva
Design Solutions for Organizational ComplexitymediumMultiple SelectObjective-mapped

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that all accounts use AWS CloudTrail with logs delivered to a central S3 bucket. Which TWO actions should be taken to enforce this?

⚠ Common exam trap

It's easy for candidates to confuse initial deployment (CloudFormation StackSets) with ongoing enforcement, or they mistakenly believe that a reactive Lambda function is sufficient for compliance, failing to recognize that SCPs and Config rules provide the necessary preventive and detective controls required by the security team's goal of ensuring all accounts use CloudTrail with logs delivered to a central S3 bucket.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use AWS Config rules to detect when CloudTrail is not configured correctly and trigger remediation

AWS Config rules can be used to continuously monitor CloudTrail configuration across accounts and automatically trigger remediation actions (e.g., via AWS Systems Manager Automation or Lambda) when non-compliance is detected. This ensures that any drift from the required CloudTrail setup is corrected without manual intervention, providing a detective and corrective control. Option E is correct because a service control policy (SCP) can deny the cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail actions at the organizational level, preventing any account from disabling or modifying the central CloudTrail trail, thus enforcing the required configuration proactively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an IAM role in each account that requires CloudTrail to be enabled

    Why it's wrong here

    IAM roles cannot require services to be enabled.

  • Use CloudFormation StackSets to deploy a CloudTrail trail in each account

    Why it's wrong here

    This does not prevent users from disabling the trail.

  • Use AWS Config rules to detect when CloudTrail is not configured correctly and trigger remediation

    Why this is correct

    Config rules can monitor and auto-remediate to ensure compliance.

  • Use AWS Lambda to automatically re-enable CloudTrail if it is disabled

    Why it's wrong here

    This is reactive and not enforcement.

  • Use a service control policy (SCP) to deny actions that disable CloudTrail or modify the trail configuration

    Why this is correct

    SCPs can prevent disabling or altering the central trail.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 1,660 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.