Courseiva
Management and Security GovernancemediumMultiple ChoiceObjective-mapped

SCS-C02 Management and Security Governance Practice Question

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that all accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket in the management account. What is the most efficient way to enforce this across all accounts?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a service control policy (SCP) that denies modifications to CloudTrail settings.

The most efficient way to enforce CloudTrail across all accounts in an AWS Organization is to use a Service Control Policy (SCP) that denies the ability to stop or modify CloudTrail settings. SCPs are applied at the organization level and affect all member accounts, preventing any user or role from disabling CloudTrail or changing trail configuration, regardless of their IAM permissions. This ensures compliance without needing per-account setup. Option B (Trusted Advisor) only provides alerts, not enforcement. Option C requires manual configuration per account, which is inefficient and error-prone. Option D (AWS Config rules) can detect non-compliance but cannot prevent changes from being made.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a service control policy (SCP) that denies modifications to CloudTrail settings.

    Why this is correct

    SCPs can prevent disabling CloudTrail or altering trail configurations across all accounts.

  • Use AWS Trusted Advisor to check CloudTrail status and send alerts.

    Why it's wrong here

    Trusted Advisor only checks and alerts, does not enforce.

  • Configure each account individually with a CloudTrail trail pointing to the central bucket.

    Why it's wrong here

    Manual per-account setup is not efficient and may be inconsistent.

  • Use AWS Config rules in each account to detect non-compliant trails.

    Why it's wrong here

    Config rules detect but do not prevent disabling; they only alert after the fact.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.