Centralize CloudTrail Logs from All AWS Organization Accounts
A company wants to centralize AWS CloudTrail logs from all accounts in AWS Organizations into a single S3 bucket. Which configuration is required?
Quick Answer
The answer is to create an organization trail in the management account that is enabled for all accounts. This configuration is correct because AWS Organizations allows you to define a single organization trail from the management account, which automatically applies to every member account, centralizing CloudTrail logs from all AWS Organization accounts into a designated S3 bucket without needing per-account setup. On the AWS Certified Solutions Architect Professional SAP-C02 exam, this tests your understanding of centralized governance versus manual aggregation—a common trap is thinking you must configure individual trails in each account or use a separate logging account. Instead, remember that the organization trail inherits the organization’s structure, ensuring consistent logging and simplifying compliance. Memory tip: think “one trail to rule them all”—the management account is the single source of truth for organization-wide CloudTrail configuration.
⚠ Common exam trap
A common mix-up: candidates think individual trails per account (Option B) are necessary or simpler, but AWS Organizations provides a native, centralized mechanism that automatically includes all accounts without per-account configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an organization trail in the management account that is enabled for all accounts
AWS Organizations supports creating an organization trail in the management account that automatically applies to all accounts in the organization. This centralizes CloudTrail logs from every account into a single S3 bucket without requiring per-account configuration, ensuring consistent logging and simplifying management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure each account's CloudTrail to send logs to a central CloudWatch Logs group
Why it's wrong here
CloudWatch Logs is not an S3 bucket.
- ✗
Create a CloudTrail trail in each account and deliver logs to the same S3 bucket
Why it's wrong here
Logs can be delivered to the same bucket but requires per-account trail creation.
- ✓
Create an organization trail in the management account that is enabled for all accounts
Why this is correct
Organization trails automatically apply to all accounts in the organization.
- ✗
Use S3 replication to copy logs from individual account buckets to a central bucket
Why it's wrong here
Adds complexity and potential for data loss.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,660 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
5 more ways this is tested on SAP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has multiple AWS accounts and wants to centralize CloudTrail logs from all accounts into a single S3 bucket in the audit account. Which configuration is required?
medium- A.Configure CloudWatch Events cross-account to forward logs to a central S3 bucket.
- ✓ B.Create an organization trail in the management account that delivers logs to the central S3 bucket in the audit account, and set the bucket policy to allow CloudTrail from the organization.
- C.Use AWS Organizations to automatically create a CloudTrail trail in the management account that logs all accounts.
- D.Create a CloudTrail trail in each account that delivers logs to the central S3 bucket, with a bucket policy that grants write access to each account's CloudTrail service.
Why B: AWS Organizations allows you to create an organization trail in the management account that automatically applies to all accounts in the organization. By configuring the trail to deliver logs to a central S3 bucket in the audit account, and setting the bucket policy to grant CloudTrail service access from the organization, you centralize logging without needing per-account trails. This approach ensures that new accounts added to the organization are automatically covered.
Variation 2. A company with multiple AWS accounts wants to centralize CloudTrail logging. They create a CloudTrail trail in the management account that logs all events across all accounts and regions. However, the security team notices that some management events from member accounts are not being logged. What is the most likely cause?
hard- A.The SCPs applied to member accounts are blocking CloudTrail from sending logs.
- B.CloudTrail is a regional service and the trail is only in one region.
- C.Member accounts have IAM policies that deny CloudTrail logging.
- ✓ D.The trail was not created as an organization trail.
Why D: When a CloudTrail trail is created in the management account without enabling the 'organization trail' option, it only logs events for the management account itself and not for member accounts. To centralize logging across all accounts in AWS Organizations, the trail must be explicitly created as an organization trail, which automatically applies to all current and future member accounts. Without this setting, member account events are not forwarded to the management account's trail.
Variation 3. A company has multiple AWS accounts and wants to centralize CloudTrail logs in a single S3 bucket in the security account. Which policy should be applied to the S3 bucket to allow cross-account delivery from all member accounts?
easy- A.Add an IAM role in the security account and allow the CloudTrail service in each member account to assume that role.
- B.Configure the bucket ACL to allow write access for all member account root users.
- C.Add a bucket policy that grants the service principal 'logs.amazonaws.com' s3:PutObject permissions.
- ✓ D.Add a bucket policy that grants the CloudTrail service principal s3:PutObject permissions for the bucket, with a condition that the source account is in the organization.
Why D: CloudTrail cross-account logging requires a bucket policy that grants the CloudTrail service principal (cloudtrail.amazonaws.com) s3:PutObject permission, with a condition (aws:SourceOrgID or aws:SourceAccount) to restrict access to only the member accounts within the AWS Organization. This ensures centralized delivery while preventing unauthorized accounts from writing to the bucket.
Variation 4. A company wants to centralize logging from multiple AWS accounts into a single Amazon S3 bucket. The logging accounts are part of an AWS Organization. Which approach should be used to allow CloudTrail to deliver logs from all accounts to the central bucket?
easy- ✓ A.Configure the central S3 bucket policy to allow CloudTrail from all accounts in the organization to write logs.
- B.Use a VPC endpoint and route logs through a central VPC.
- C.Attach an SCP to allow CloudTrail to write to the central bucket.
- D.Create an IAM role in each member account and allow the central account to assume it.
Why A: CloudTrail can deliver logs from all accounts in an AWS Organization to a single central S3 bucket by configuring the bucket policy to grant the CloudTrail service principal (cloudtrail.amazonaws.com) from each member account the s3:PutObject permission. This approach leverages the organization's trusted access, eliminating the need for individual IAM roles or cross-account assumptions, as CloudTrail automatically uses the organization's management account to validate member account identities.
Variation 5. A global company with 50 AWS accounts uses AWS Organizations and wants to centralize CloudTrail logs. The security team requires that all accounts send their CloudTrail logs to a central S3 bucket in the audit account. Which combination of steps will ensure this?
hard- A.Use AWS Config to forward logs to a central S3 bucket.
- B.Enable CloudTrail in each account and use AWS Organizations to aggregate logs.
- C.Create a CloudTrail trail in the audit account that logs all accounts via CloudWatch Logs.
- ✓ D.Create a CloudTrail trail in the audit account with an S3 bucket, and add a bucket policy that grants cross-account permissions for each member account to deliver logs. Then configure each member account to use the same trail.
Why D: It uses a single CloudTrail trail in the audit account with a central S3 bucket, and the bucket policy grants the necessary s3:PutObject permissions to each member account's CloudTrail service principal. Each member account then configures CloudTrail to use the same trail (the audit account's trail), which allows CloudTrail to deliver logs from all accounts to the central bucket without requiring separate trails or manual log forwarding.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.