Courseiva

SCS-C02 Management and Security Governance Practice Question

A company uses AWS Organizations and wants to centrally manage CloudTrail trails across all accounts. Which feature should be enabled?

⚠ Common exam trap

SCS-C02 often tests the misconception that SCPs can enforce CloudTrail logging or that AWS Config aggregator can centralize CloudTrail logs, when in fact only an organization trail provides automatic, multi-account CloudTrail management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail organization trail

A CloudTrail organization trail is a trail created in the management account of an AWS Organization that automatically applies to all member accounts. It logs events from every account in the organization to a single S3 bucket, enabling centralized management and compliance. This is the native feature designed for multi-account CloudTrail governance, requiring no per-account configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CloudTrail organization trail

    Why this is correct

    An organization trail is a dedicated CloudTrail feature created in the AWS Organizations management account that automatically logs API activity for every account in the organization and delivers those logs to a single S3 bucket. It is configured once and applies across all AWS Regions, providing a central, management-account-owned audit record that member accounts cannot modify or delete. This is the native, scalable mechanism for centrally managing CloudTrail logs across the entire organization.

  • ✗

    Cross-account CloudTrail

    Why it's wrong here

    CloudTrail does not have a native cross-account trail concept; every CloudTrail trail is scoped to the account in which it is created. Although you can manually configure multiple accounts to deliver their logs to a central S3 bucket via resource-based policies, that requires separate per-account trail creation and does not give you the automatic, organization-wide management that an organization trail provides. A cross-account delivery setup is a workaround, not a service feature, and therefore fails to centrally manage logging by itself.

  • ✗

    Service Control Policy for CloudTrail

    Why it's wrong here

    A service control policy (SCP) is a permission guardrail that restricts which AWS actions principals in member accounts can perform, such as blocking the deletion or modification of CloudTrail trails. However, an SCP does not create or configure a trail; it only acts as an authorization boundary and cannot enable log delivery or specify a destination bucket. While an SCP can complement central logging by protecting the trail from tampering, it is not a mechanism for centrally managing the logging configuration itself.

  • ✗

    AWS Config aggregator

    Why it's wrong here

    An AWS Config aggregator gathers configuration items and compliance snapshots from multiple accounts into a single delegated administrator account, but it does not collect or manage CloudTrail event logs. The aggregator is designed for visibility into resource configuration states and rule compliance, not for analyzing API call activity or user actions recorded by CloudTrail. Therefore, it serves a different audit purpose and cannot function as a central repository or manager for CloudTrail log data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.