SCS-C02 Management and Security Governance Practice Question
A security team needs to centralize audit logs from multiple AWS accounts into a single S3 bucket. The solution must be scalable and support future account additions. Which approach meets these requirements?
⚠ Common exam trap
The trap is choosing per-account CloudTrail configuration (Option C) because it seems straightforward, but the question emphasizes scalability and future account additions — only the organization trail automatically covers new accounts without manual intervention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Organizations to create a CloudTrail trail that applies to all accounts in the organization.
AWS Organizations allows you to create an organization-wide CloudTrail trail that automatically applies to all existing and future accounts in the organization. This is the most scalable approach because new accounts added to the organization are automatically covered without manual configuration per account. The trail delivers logs to a central S3 bucket, meeting the requirement to centralize audit logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon CloudWatch Logs to stream logs from each account to a central account.
Why it's wrong here
CloudWatch Logs is a log storage and monitoring service, not an aggregation transport. There is no native mechanism to stream CloudWatch Logs directly from one account to another; you would need to build a cross-account pipeline using Kinesis Data Firehose, a customer-controlled AWS Lambda function, and IAM roles. Such a bespoke setup adds complexity and still requires per-account configuration, making it a poor fit for centrally managing audit logs from multiple accounts.
- ✗
Use AWS Trusted Advisor to collect logs from all accounts.
Why it's wrong here
AWS Trusted Advisor is an advisory service that inspects an account against AWS best practices for cost optimization, performance, security, and service quotas. It does not ingest, store, or process log data, so it cannot collect CloudTrail audit events or act as a centralized log repository. Relying on Trusted Advisor would leave you with no audit log aggregation at all.
- ✗
Configure CloudTrail in each account to deliver logs to the same S3 bucket.
Why it's wrong here
While CloudTrail in each account can be configured to deliver logs to the same S3 bucket using a permissive bucket policy, this method mandates manually creating and maintaining a separate trail in every account. Each new member account requires additional configuration, and the independently managed trail configurations can drift over time. Unlike an organization trail, this approach does not automatically apply to new accounts and creates significant operational overhead for a security team.
- ✓
Use AWS Organizations to create a CloudTrail trail that applies to all accounts in the organization.
Why this is correct
An AWS Organizations trail is the native solution: CloudTrail is enabled in the management account and automatically applies to every member account, including accounts added later. The management account creates a service-linked role that allows CloudTrail to deliver log files from all member accounts to a designated S3 bucket in the management account. This centralizes all API activity across the organization into a single auditable store without per-account manual setup.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.