Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is using AWS Organizations to manage multiple accounts. The security team wants to ensure that all accounts have AWS CloudTrail enabled in all regions. Which approach should be used?

⚠ Common exam trap

The SCS-C02 exam often tests the misconception that SCPs can enforce positive actions (like enabling a service), when in reality SCPs only provide preventive controls (denying actions) and cannot proactively configure resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail from the master account as an organization trail.

AWS Organizations allows you to create an organization trail from the management account that automatically applies to all member accounts and all regions. This ensures CloudTrail is enabled across the entire organization without requiring per-account configuration, and it centralizes log delivery to a single Amazon S3 bucket for auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an SCP that requires CloudTrail to be enabled.

    Why it's wrong here

    SCPs are IAM-based policy boundaries that only restrict the maximum allowed permissions for principals in an account; they cannot force a service like CloudTrail to be active because they do not perform configuration actions or evaluate resource state. An SCP could deny specific API calls, but it has no condition key that reports whether a trail exists, so it cannot enforce the actual enabled state of CloudTrail. Thus an SCP cannot 'require' CloudTrail in any meaningful, automated way.

  • ✗

    Enable CloudTrail in each account using a cross-account IAM role.

    Why it's wrong here

    Deploying CloudTrail manually in each account through a cross-account IAM role would require a separate role, permission, and enablement step for every member account, with no centralized control over the trails or their configuration. Even if automated via scripts, this does not leverage AWS Organizations' native capability to manage all logs from a single management account. Each account would have its own isolated trail, requiring manual aggregation of logs, which is error-prone and does not guarantee a uniform, continuously enforced trail across the entire organization.

  • ✗

    Use AWS Config rules to detect non-compliant accounts and automatically enable CloudTrail.

    Why it's wrong here

    AWS Config rules are reactive compliance checks that quantify whether resources — such as CloudTrail trails — match a desired configuration, but they cannot perform remediation on their own. Although you could pair a Config rule with an SSM Automation document to enable CloudTrail after a violation is detected, that is a separate, post-hoc remediation flow and not the direct, centralized enablement called for in the scenario. Config itself is not a provisioning service, so the rule alone cannot automatically create or start a trail for all accounts.

  • ✓

    Enable AWS CloudTrail from the master account as an organization trail.

    Why this is correct

    An organization trail, created from the management (master) account of AWS Organizations, automatically applies to every account within the organization and is centrally managed as a single trail. CloudTrail delivers log files for the management account and all member accounts to the same S3 bucket, and member accounts cannot stop or modify the trail, preserving a reliable audit baseline. This is the intended, native way to enable CloudTrail across an organization, and it fulfills the requirement with no per-account setup.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.