SCS-C02 Management and Security Governance Practice Question
A company's Security team is using AWS Organizations with a consolidated billing account. The security team wants to ensure that all member accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket in the management account. Which combination of actions should the security team take? (Choose the best answer.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an SCP to deny disabling CloudTrail and use CloudFormation StackSets to deploy CloudTrail in all accounts.
Using an SCP to deny disabling CloudTrail and a CloudFormation StackSet to deploy CloudTrail in each account ensures enforcement and deployment across all member accounts. Option A is wrong because AWS Config rules can detect but not prevent disabling of CloudTrail. Option B is wrong because an IAM policy requiring account owners to enable CloudTrail is not enforceable and relies on individual action. Option C is wrong because enabling CloudTrail only in the management account does not enable it in member accounts; cross-account logging requires member accounts to have CloudTrail configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to detect when CloudTrail is disabled.
Why it's wrong here
An AWS Config managed rule such as cloudtrail-enabled is purely detective: it evaluates configuration snapshots and can flag an account where CloudTrail has been stopped, but it cannot stop the underlying StopLogging or DeleteTrail API call from succeeding. Remediation actions invoked by Config (e.g., AWS Systems Manager automation) are asynchronous and may run after the trail is already off, meaning events generated in the interval are never captured. This option fails to meet the requirement to prevent the cloud team from disabling CloudTrail in member accounts.
- ✗
Create a new IAM policy that requires each account owner to enable CloudTrail.
Why it's wrong here
An IAM policy defines allowed or denied API actions; it cannot impose an obligation on an account owner to perform an action, and it certainly does not block an already-authorized user from calling cloudtrail:StopLogging or cloudtrail:DeleteTrail. Even if you tried to craft a policy that explicitly allowed only enable actions and denied stop/delete, a member account administrator with full permissions can simply change their own IAM policy or assume a role that bypasses those restrictions. Only an SCP at the organization root or OU level can create an unremovable preventive control across all accounts.
- ✗
Enable CloudTrail in the management account only and use cross-account logging.
Why it's wrong here
Enabling CloudTrail in the management account and using cross-account logging centralizes the management account's trail data into an S3 bucket, but it does not create trails for member accounts. Each member account must independently have a trail configured to capture its own management events; cross-account logging only means the destination bucket resides in another account, not that the source account has a trail. Without an automated deployment like StackSets or CloudFormation, this leaves member accounts without CloudTrail coverage, so it fails the security team's goal.
- ✓
Use an SCP to deny disabling CloudTrail and use CloudFormation StackSets to deploy CloudTrail in all accounts.
Why this is correct
An SCP such as 'DenyCloudTrailDisable' can be attached to the root or OU to explicitly deny cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail (along with PutEventSelectors actions that could stop recording), preventing any principal—including the root user—from disabling the trail. CloudFormation StackSets then deploys a consistent multi-region trail template to every account in the organization, automatically creating the required trail, S3 bucket, and bucket policy. Because SCPs are evaluated in addition to IAM policies and cannot be overridden by account admins, this combination provides both automated enablement and a hard preventive boundary.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.