Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A healthcare company has a multi-account AWS environment with a central audit account. Compliance requires that all access to Amazon S3 buckets containing protected health information be logged and that logs be immutable for seven years. The company wants to centralize log storage and prevent any account, including the management account, from deleting or modifying the logs. Which combination of steps should a solutions architect take?

⚠ Common exam trap

Watch out — candidates often confuse CloudTrail management events with data events, or assuming a bucket policy or governance mode provides the same immutability as compliance mode Object Lock.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail data events for S3 in all accounts, deliver logs to a central S3 bucket in the audit account, and enable S3 Object Lock in compliance mode on that bucket with a seven-year retention period.

CloudTrail data events capture object-level S3 operations, and delivering them to a central audit account bucket centralizes storage. S3 Object Lock in compliance mode enforces a write-once-read-many model that no principal, including the management account root user, can override during the retention period, which meets the seven-year immutability requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable AWS CloudTrail data events for S3 in all accounts, deliver logs to a central S3 bucket in the audit account, and enable S3 Object Lock in compliance mode on that bucket with a seven-year retention period.

    Why this is correct

    CloudTrail data events capture object-level S3 access, and delivering them to a central bucket in the audit account meets the centralized logging requirement. S3 Object Lock in compliance mode prevents any user, including the root user and the management account, from deleting or altering objects for the retention period, satisfying the seven-year immutability requirement.

  • ✗

    Use AWS Config to record S3 bucket changes, store the configuration history in the audit account, and enable S3 Object Lock in governance mode for seven years.

    Why it's wrong here

    AWS Config records configuration changes, not individual object access, so it does not log every read or write of protected health information. Governance mode allows users with sufficient permissions to bypass retention, which fails the requirement that no account, including the management account, can delete or modify the logs.

  • ✗

    Enable AWS CloudTrail management events only, deliver logs to a central S3 bucket, and configure a bucket policy that denies s3:DeleteObject for all principals.

    Why it's wrong here

    Management events do not capture object-level access to S3 buckets, so the compliance requirement for logging access to protected health information is not met. A bucket policy denying deletion can be modified by an administrator, so it does not provide the immutable retention that Object Lock in compliance mode enforces.

  • ✗

    Enable S3 server access logging on each bucket, deliver the logs to a central bucket, and use an S3 Lifecycle policy to transition logs to S3 Glacier Deep Archive after 90 days.

    Why it's wrong here

    S3 server access logging is best-effort and can be delayed or incomplete, so it is not reliable for compliance-grade auditing. A lifecycle policy moves objects but does not prevent deletion, and the logs can still be modified or removed, so the immutability requirement for seven years is not satisfied.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.