SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A financial services company uses AWS Organizations with 60 accounts. The security team has enabled AWS CloudTrail organization trails in the management account and wants to prevent any member account administrator from disabling CloudTrail logging in their own account. Which solution will meet this requirement with the LEAST operational overhead?
⚠ Common exam trap
The trap here is assuming that deploying a trail in each account or using detective controls such as AWS Config is enough, when only an organization-level service control policy can prevent member administrators from stopping logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a service control policy in AWS Organizations that denies the cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail actions for all member accounts.
A service control policy in AWS Organizations denies the CloudTrail actions that stop, delete, or modify a trail, so member account administrators cannot disable logging even if their IAM policies allow those actions. Because SCPs apply at the organization level to all accounts, this is preventive and requires no per-account resources, satisfying both the security and least-overhead requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an AWS CloudFormation StackSet that deploys a CloudTrail trail in every account and configure drift detection to alert when the trail is modified.
Why it's wrong here
A StackSet can deploy trails, but drift detection only reports changes after they happen and does not block an account administrator from stopping logging. Because it is reactive rather than preventive, it fails the requirement to prevent disabling CloudTrail logging in member accounts.
- ✓
Create a service control policy in AWS Organizations that denies the cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail actions for all member accounts.
Why this is correct
SCPs set the maximum permissions for accounts in an organization. Denying the actions that stop or delete a trail prevents member account administrators from disabling CloudTrail logging, and because SCPs apply organization-wide, no per-account scripting is required, meeting the least operational overhead requirement.
- ✗
Configure an IAM permissions boundary on every IAM role in each member account that excludes the cloudtrail:StopLogging and cloudtrail:DeleteTrail actions.
Why it's wrong here
Permissions boundaries limit identity-based permissions for the entities they are attached to, but they must be attached to each user or role individually and do not affect future principals. Managing them across 60 accounts and all future roles is high overhead and leaves gaps, so it does not reliably prevent disabling logging.
- ✗
Use AWS Config with a managed rule that detects when a CloudTrail trail is not logging, and trigger an AWS Lambda function to restart logging when the rule is noncompliant.
Why it's wrong here
AWS Config detects noncompliance and can trigger remediation, but the trail is already stopped when the rule fires, so logging is interrupted. This is detective and corrective rather than preventive, and it adds Lambda and Config overhead that a service control policy avoids.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.