Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A financial services company uses AWS Organizations with 300 member accounts. The security team wants to ensure that all AWS API activity in every account is logged to a central Amazon S3 bucket owned by the management account. The logs must be immutable for 7 years and protected from deletion by any member account administrator. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is assuming that a bucket policy denying delete operations provides the same immutability as S3 Object Lock, but bucket policies can be modified by administrators with sufficient permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an organization trail in the management account that applies to all accounts, configure the trail to deliver to a central S3 bucket, and enable S3 Object Lock in compliance mode with a 7-year retention period on the bucket.

An organization trail in the management account automatically applies to all current and future accounts, providing centralized logging with minimal effort. Delivering to a central S3 bucket with S3 Object Lock in compliance mode ensures that logs cannot be deleted or altered by any user, including the root user, for the specified retention period. This meets the immutability and centralization requirements with the least operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS Config in all accounts with a conformance pack that checks for CloudTrail logging, and configure an AWS Lambda function to copy trail logs to a central S3 bucket with a lifecycle policy.

    Why it's wrong here

    AWS Config conformance packs detect noncompliance but do not enable logging or enforce immutability. A Lambda function to copy logs adds complexity and latency, and lifecycle policies do not prevent deletion. This solution does not guarantee centralized immutable logging and introduces unnecessary operational overhead.

  • ✗

    Create an individual trail in each member account that delivers to a central S3 bucket, and use a bucket policy that denies s3:DeleteObject to all principals except the management account.

    Why it's wrong here

    Creating individual trails in 300 accounts requires significant operational overhead and does not automatically cover future accounts. A bucket policy denying delete operations can be modified by a member account administrator if they have permissions, and it does not provide the same immutability guarantee as S3 Object Lock. This approach fails the least-overhead and protection requirements.

  • ✓

    Create an organization trail in the management account that applies to all accounts, configure the trail to deliver to a central S3 bucket, and enable S3 Object Lock in compliance mode with a 7-year retention period on the bucket.

    Why this is correct

    An organization trail created in the management account automatically applies to all existing and future accounts in the organization, eliminating per-account configuration. Delivering to a central S3 bucket with S3 Object Lock in compliance mode enforces immutability for the retention period, and member account administrators cannot override or delete the objects, satisfying both centralization and protection requirements.

  • ✗

    Use AWS CloudTrail Lake in the management account to ingest events from all member accounts, and configure a 7-year retention period on the event data store.

    Why it's wrong here

    AWS CloudTrail Lake is a managed data lake for querying events, not a replacement for delivering immutable log files to a central S3 bucket. While it can aggregate events, it does not provide the same S3-based immutability with Object Lock, and it may not meet the requirement to store logs in a specific central bucket owned by the management account.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.