SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all CloudTrail trails are enabled and logging to a central S3 bucket. They need to detect any account that disables or modifies its CloudTrail trail. Which approach meets these requirements with the least operational overhead?
⚠ Common exam trap
It's easy for candidates to think a custom Lambda function (Option D) is necessary for cross-account monitoring, overlooking that AWS Config with an aggregator natively supports multi-account evaluation with far less operational overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config rules with an aggregator in the management account to evaluate CloudTrail configuration across all accounts.
AWS Config rules with an aggregator in the management account can evaluate CloudTrail configuration across all accounts in AWS Organizations without deploying per-account resources. The aggregator collects configuration snapshots and changes from member accounts, allowing a single managed rule (e.g., cloud-trail-enabled) to detect when a trail is disabled or modified. This approach minimizes operational overhead because it uses native AWS services with no custom code or cross-account IAM roles to manage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS Config rules with an aggregator in the management account to evaluate CloudTrail configuration across all accounts.
Why this is correct
AWS Config rules can run managed or custom rules against the configuration of CloudTrail trails, and an aggregator in the management account lets you view compliance results from all member accounts in a single dashboard. When a trail is misconfigured or deleted, the rule evaluates the change and can trigger an Amazon EventBridge event to notify administrators. This is the only option that provides continuous, native, multi-account governance without writing custom monitoring code or relying on external scheduling.
- ✗
Enable CloudTrail Insights in all accounts to detect unusual activity.
Why it's wrong here
CloudTrail Insights analyzes the event history of the trail to identify unusual API activity, such as IAM role chaining, unusually high error rates, or resource limit exceedances. It does not evaluate the configuration of the trail itself, so it cannot detect whether the trail is disabled, has an insecure log file validation setting, or is missing from a required Region. Enabling Insights adds detection capability for anomalous behavior but leaves configuration compliance gaps unresolved.
- ✗
Enable IAM Access Analyzer in each account to monitor CloudTrail changes.
Why it's wrong here
IAM Access Analyzer is designed to identify resources shared with external principals by analyzing resource-based policies (e.g., S3 bucket policies, KMS key policies, IAM roles). It has no logic to inspect the configuration of CloudTrail trails, such as whether the trail is logging to the correct S3 bucket, has log validation enabled, or is applying the correct management event selectors. Using it to monitor CloudTrail changes would be a fundamental mismatch of the service's intended purpose, providing no relevant compliance signal.
- ✗
Create a Lambda function that periodically checks CloudTrail status in each account via the API.
Why it's wrong here
A Lambda function that periodically calls the GetTrailStatus and GetTrail APIs can check trail existence and logging status, but this approach requires you to build custom code, manage IAM roles across accounts, and schedule invocations with CloudWatch Events; it also does not provide a persistent compliance record or automatic evaluation when configuration changes occur. AWS Config provides the same checks natively with built-in rules, centralized aggregation, and point-in-time compliance history, making the Lambda solution higher effort and less reliable for continuous monitoring.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.