SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company with multiple AWS accounts wants to centralize CloudTrail logging. They create a CloudTrail trail in the management account that logs all events across all accounts and regions. However, the security team notices that some management events from member accounts are not being logged. What is the most likely cause?
⚠ Common exam trap
Many exam-takers assume that creating a trail in the management account automatically covers all member accounts, but they overlook the explicit requirement to designate the trail as an organization trail during creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The trail was not created as an organization trail.
When a CloudTrail trail is created in the management account without enabling the 'organization trail' option, it only logs events for the management account itself and not for member accounts. To centralize logging across all accounts in AWS Organizations, the trail must be explicitly created as an organization trail, which automatically applies to all current and future member accounts. Without this setting, member account events are not forwarded to the management account's trail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SCPs applied to member accounts are blocking CloudTrail from sending logs.
Why it's wrong here
Service control policies restrict which API actions principals in member accounts can perform; they do not block CloudTrail from recording or delivering those actions to the central bucket. It is tempting because SCPs are the standard guardrail across an AWS Organization, and an SCP denying cloudtrail:StartLogging would be the cause if logging could not be enabled.
- ✗
CloudTrail is a regional service and the trail is only in one region.
Why it's wrong here
A multi-region trail created in the management account captures events from all regions; the organisation trail setting, not regional scope, governs whether member accounts are included. It is tempting because CloudTrail is indeed regional by default, and a single-region trail would be the cause if events from other regions were missing.
- ✗
Member accounts have IAM policies that deny CloudTrail logging.
Why it's wrong here
CloudTrail delivers events to the trail's S3 bucket and CloudWatch Logs using service-linked roles and bucket policies, not member-account IAM policies; an IAM deny cannot suppress CloudTrail's own event delivery. It is tempting because IAM policies govern most AWS API access, and denying CloudTrail actions would be the cause if users were prevented from creating or managing trails.
- ✓
The trail was not created as an organization trail.
Why this is correct
An organization trail is required for CloudTrail to log events from every member account into the management account's centralized S3 bucket. A standard trail only captures events within its own account, so member-account management events are silently omitted — exactly the gap described in the stem.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.