SCS-C02 Infrastructure Security Practice Question
A company is using AWS Organizations to manage multiple accounts. The security team wants to ensure that all accounts have AWS CloudTrail enabled in all regions. Which approach should be used?
⚠ Common exam trap
The SCS-C02 exam often tests the misconception that SCPs can enforce positive actions (like enabling a service), when in reality SCPs only provide preventive controls (denying actions) and cannot proactively configure resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail from the master account as an organization trail.
AWS Organizations allows you to create an organization trail from the management account that automatically applies to all member accounts and all regions. This ensures CloudTrail is enabled across the entire organization without requiring per-account configuration, and it centralizes log delivery to a single Amazon S3 bucket for auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an SCP that requires CloudTrail to be enabled.
Why it's wrong here
SCPs are IAM-based policy boundaries that only restrict the maximum allowed permissions for principals in an account; they cannot force a service like CloudTrail to be active because they do not perform configuration actions or evaluate resource state. An SCP could deny specific API calls, but it has no condition key that reports whether a trail exists, so it cannot enforce the actual enabled state of CloudTrail. Thus an SCP cannot 'require' CloudTrail in any meaningful, automated way.
- ✗
Enable CloudTrail in each account using a cross-account IAM role.
Why it's wrong here
Deploying CloudTrail manually in each account through a cross-account IAM role would require a separate role, permission, and enablement step for every member account, with no centralized control over the trails or their configuration. Even if automated via scripts, this does not leverage AWS Organizations' native capability to manage all logs from a single management account. Each account would have its own isolated trail, requiring manual aggregation of logs, which is error-prone and does not guarantee a uniform, continuously enforced trail across the entire organization.
- ✗
Use AWS Config rules to detect non-compliant accounts and automatically enable CloudTrail.
Why it's wrong here
AWS Config rules are reactive compliance checks that quantify whether resources — such as CloudTrail trails — match a desired configuration, but they cannot perform remediation on their own. Although you could pair a Config rule with an SSM Automation document to enable CloudTrail after a violation is detected, that is a separate, post-hoc remediation flow and not the direct, centralized enablement called for in the scenario. Config itself is not a provisioning service, so the rule alone cannot automatically create or start a trail for all accounts.
- ✓
Enable AWS CloudTrail from the master account as an organization trail.
Why this is correct
An organization trail, created from the management (master) account of AWS Organizations, automatically applies to every account within the organization and is centrally managed as a single trail. CloudTrail delivers log files for the management account and all member accounts to the same S3 bucket, and member accounts cannot stop or modify the trail, preserving a reliable audit baseline. This is the intended, native way to enable CloudTrail across an organization, and it fulfills the requirement with no per-account setup.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.