Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to use AWS CloudTrail to log all API activity across multiple accounts in AWS Organizations. Which configuration meets the requirement of centralized logging with minimal operational overhead?

⚠ Common exam trap

Many candidates think they need to manually configure trails per account or use cross-account roles, missing the fact that AWS Organizations provides a native, low-overhead solution through organization trails that automatically centralize logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an organization trail in the management account that applies to all accounts

Creating an organization trail in the management account automatically applies to all accounts in AWS Organizations, centralizing CloudTrail logs into a single S3 bucket without requiring per-account configuration. This approach minimizes operational overhead by leveraging the Organizations integration, which handles log delivery from member accounts transparently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a CloudTrail trail in each account and aggregate logs to a common S3 bucket

    Why it's wrong here

    Creating a trail in every account and pointing them to a common S3 bucket requires manually configuring each account's CloudTrail, IAM roles, and S3 bucket policies to permit cross-account log delivery. You also need to update the configuration whenever a new account is added, and you must manage multiple trails, which increases the risk of misconfiguration and missing API activity. This approach fails the requirement for minimal operational overhead because it does not leverage AWS Organizations' central management capabilities, unlike an organization trail which automatically provisions and manages trails across the entire organization.

  • ✗

    Enable CloudTrail in each account and use cross-account roles to centralize logs

    Why it's wrong here

    While cross-account roles enable a central account to assume IAM roles and retrieve logs from each member account, this approach requires manual setup and maintenance of roles and trust policies in every account, failing the requirement for minimal operational overhead. It is tempting because it is the standard method for aggregating logs when CloudTrail is not configured with an organisation trail, and would be correct if the organisation did not support centralised management via AWS Organizations.

  • ✗

    Use AWS Config to record API calls and send to CloudWatch Logs

    Why it's wrong here

    AWS Config is designed to record configuration changes to resources, such as when an EC2 instance is terminated or a security group rule is updated, and it does not capture the API calls that caused those changes. Even if you send Config events to CloudWatch Logs, you get configuration histories and compliance snapshots, not an audit trail of the API activities performed by IAM principals. CloudTrail is the service that logs AWS API calls, including the identity, time, source IP, and request parameters, so relying on Config fundamentally fails to meet the requirement to log all API activity.

  • ✓

    Create an organization trail in the management account that applies to all accounts

    Why this is correct

    When you create a CloudTrail trail in the management account with the 'Apply trail to my organization' option enabled, CloudTrail automatically creates and configures trails in every member account, delivering all management events to a single S3 bucket. The trail is managed centrally by the organization management account, and any new accounts that join the organization are automatically included without additional manual setup. This provides the lowest operational overhead and ensures comprehensive, centralized logging of API activity across the entire AWS organization, which is exactly what the requirement demands.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.