SCS-C02 Security Logging and Monitoring Practice Question
A company uses AWS Organizations with multiple accounts. The security team needs to ensure that all accounts have CloudTrail enabled and that logs are delivered to a central S3 bucket. A new member account is created and the security engineer wants to enforce this configuration automatically. Which approach meets these requirements with the least operational overhead?
⚠ Common exam trap
Many candidates confuse preventive controls (SCPs) with provisioning controls, mistakenly thinking that denying stop/delete actions is sufficient to enforce CloudTrail, when in fact it does not create or enable the trail in the first place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts in the organization.
AWS CloudFormation StackSets allows you to deploy a CloudTrail template across all accounts in an AWS Organization from a single administrative account. This approach ensures that every new member account automatically receives the CloudTrail configuration as part of the StackSet's automatic deployment to accounts added to the organization, providing a fully automated, infrastructure-as-code solution with minimal operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to detect accounts without CloudTrail and trigger a remediation via Systems Manager Automation.
Why it's wrong here
An AWS Config rule such as cloudtrail-enabled only evaluates the configuration state of resources after they exist. When a new account is added, the rule reports noncompliant, and the Systems Manager Automation document runs only after that detection, leaving an unlogged window. This strategy is reactive: it does not provision or enable CloudTrail before activity occurs, and it requires the automation document, IAM roles, and permissions to already be set up in every account. Config's periodic evaluations add further delay, so it cannot guarantee continuous coverage from the moment an account joins the organization.
- ✓
Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts in the organization.
Why this is correct
AWS CloudFormation StackSets with automatic deployment is the proactive, organization-native solution because it deploys a CloudTrail template to all current accounts and automatically to any new accounts that are added later. Using service-managed permissions, StackSets creates the trail, the logging S3 bucket, and the necessary IAM role in each account without custom code or manual steps. This ensures CloudTrail is enabled before any activity can occur in a new account, since the stack set rollout happens as part of account creation and organization integration. It is declarative, idempotent, and centrally managed from the management account.
- ✗
Use an SCP to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail actions.
Why it's wrong here
A service control policy (SCP) is a permission boundary that denies or restricts API actions across all principals in an account, but it cannot initiate any API call. Denying cloudtrail:StopLogging and cloudtrail:DeleteTrail would prevent an existing trail from being stopped or deleted, which is a protective guardrail rather than an enabling mechanism. Because SCPs never create or configure resources, they leave the original requirement unmet unless CloudTrail was already deployed by another mechanism. Also, an SCP alone cannot ensure that a trail is configured to log to a central bucket or track management events.
- ✗
Create an AWS Lambda function that runs periodically to check and enable CloudTrail in each account.
Why it's wrong here
A Lambda function that runs on a schedule is a custom, pull-based workaround that requires building cross-account IAM roles, writing code to iterate through accounts, and handling failures or throttling. If the function runs only periodically, there will be a gap between when an account is added and when the next invocation occurs, during which no CloudTrail logging is active. This also adds operational overhead for patching, managing permissions, and maintaining CloudWatch event rules, and it does not automatically deploy to new accounts unless you separately configure a trigger. It is inferior to CloudFormation StackSets, which natively handles deployment and drift without custom code.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.