Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A healthcare company has 200 AWS accounts in AWS Organizations. The security team wants to prevent any principal in member accounts from disabling AWS CloudTrail or deleting the organization trail, even if they have administrator permissions in their own account. The solution must be centrally managed and apply to all existing and future accounts. Which approach should a solutions architect recommend?

⚠ Common exam trap

The trap here is choosing a detective control such as AWS Config remediation when the requirement explicitly asks to prevent administrators from disabling logging, which demands a preventive control like an SCP plus an organization trail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an organization trail in the management account and attach a service control policy that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail to all member accounts.

The most reliable way to prevent CloudTrail tampering across an organization is to use an organization trail, which member accounts cannot alter, combined with an SCP that denies the specific destructive CloudTrail API actions. This is preventive and applies uniformly to all accounts. Detective Config rules, CloudTrail Lake analytics, and per-account permission boundaries do not provide the same centralized prevention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM permission boundary in each member account that denies CloudTrail management actions for all IAM principals.

    Why it's wrong here

    Permission boundaries limit the maximum permissions of IAM entities but must be attached to each role or user and do not apply to the root user or to AWS service-linked roles. Managing boundaries across 200 accounts is error-prone and cannot reliably prevent all principals, including the account root user, from disabling CloudTrail.

  • ✗

    Use AWS CloudTrail Lake in the management account and grant member accounts read-only access to the event data store.

    Why it's wrong here

    CloudTrail Lake is an analytics engine for querying logged events; it does not prevent member accounts from modifying their own trails. Granting read-only access to a central event data store does not stop an account administrator from stopping or deleting a trail in their account, so the preventive requirement is not satisfied.

  • ✓

    Create an organization trail in the management account and attach a service control policy that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail to all member accounts.

    Why this is correct

    An organization trail applies to all accounts in the organization and cannot be modified by member accounts. Pairing it with an SCP that denies the destructive CloudTrail actions ensures that even account administrators cannot stop or delete logging. This combination provides centralized, tamper-resistant logging across current and future accounts.

  • ✗

    Enable CloudTrail in each member account and use AWS Config rules to detect and remediate trails that are stopped or deleted.

    Why it's wrong here

    Config rules detect noncompliance after the fact and can trigger remediation, but they do not prevent a determined administrator from stopping logging. There is also a window between the destructive action and remediation during which activity goes unlogged. This approach is detective rather than preventive and does not meet the requirement to prevent disabling CloudTrail.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.