SCS-C02 Management and Security Governance Practice Question
A company wants to use AWS CloudTrail to log all API activity across multiple accounts in AWS Organizations. Which configuration meets the requirement of centralized logging with minimal operational overhead?
⚠ Common exam trap
Many candidates think they need to manually configure trails per account or use cross-account roles, missing the fact that AWS Organizations provides a native, low-overhead solution through organization trails that automatically centralize logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an organization trail in the management account that applies to all accounts
Creating an organization trail in the management account automatically applies to all accounts in AWS Organizations, centralizing CloudTrail logs into a single S3 bucket without requiring per-account configuration. This approach minimizes operational overhead by leveraging the Organizations integration, which handles log delivery from member accounts transparently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a CloudTrail trail in each account and aggregate logs to a common S3 bucket
Why it's wrong here
Creating a trail in every account and pointing them to a common S3 bucket requires manually configuring each account's CloudTrail, IAM roles, and S3 bucket policies to permit cross-account log delivery. You also need to update the configuration whenever a new account is added, and you must manage multiple trails, which increases the risk of misconfiguration and missing API activity. This approach fails the requirement for minimal operational overhead because it does not leverage AWS Organizations' central management capabilities, unlike an organization trail which automatically provisions and manages trails across the entire organization.
- ✗
Enable CloudTrail in each account and use cross-account roles to centralize logs
Why it's wrong here
While cross-account roles enable a central account to assume IAM roles and retrieve logs from each member account, this approach requires manual setup and maintenance of roles and trust policies in every account, failing the requirement for minimal operational overhead. It is tempting because it is the standard method for aggregating logs when CloudTrail is not configured with an organisation trail, and would be correct if the organisation did not support centralised management via AWS Organizations.
- ✗
Use AWS Config to record API calls and send to CloudWatch Logs
Why it's wrong here
AWS Config is designed to record configuration changes to resources, such as when an EC2 instance is terminated or a security group rule is updated, and it does not capture the API calls that caused those changes. Even if you send Config events to CloudWatch Logs, you get configuration histories and compliance snapshots, not an audit trail of the API activities performed by IAM principals. CloudTrail is the service that logs AWS API calls, including the identity, time, source IP, and request parameters, so relying on Config fundamentally fails to meet the requirement to log all API activity.
- ✓
Create an organization trail in the management account that applies to all accounts
Why this is correct
When you create a CloudTrail trail in the management account with the 'Apply trail to my organization' option enabled, CloudTrail automatically creates and configures trails in every member account, delivering all management events to a single S3 bucket. The trail is managed centrally by the organization management account, and any new accounts that join the organization are automatically included without additional manual setup. This provides the lowest operational overhead and ensures comprehensive, centralized logging of API activity across the entire AWS organization, which is exactly what the requirement demands.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.