Question 370 of 1,570
Centralize CloudTrail Logs Across Multiple AWS Accounts Using AWS Organizations
A company uses AWS Organizations to manage multiple accounts. The security team wants to enable CloudTrail for all accounts and centrally store logs. What is the most efficient way to achieve this?
Quick Answer
The answer is to create a single CloudTrail trail in the management account and apply it to all accounts in the AWS Organization. This is the most efficient method because AWS Organizations allows you to enable CloudTrail organization-wide from the management account, automatically logging API activity for every member account without requiring manual setup or individual trails. On the AWS Certified Security Specialty SCS-C02 exam, this tests your understanding of centralized governance versus decentralized logging—a common trap is assuming each account needs its own trail or that an S3 bucket policy alone suffices. Remember, the management account acts as the single source of truth for audit logs, and deleting existing trails is unnecessary. Memory tip: think of the management account as the "master key" that unlocks logging for the entire organization with one turn.
⚠ Common exam trap
Watch out — candidates often assume cross-account S3 bucket policies (Option A) are sufficient, overlooking the native organization-wide trail capability that automates trail creation and management across all accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudTrail trail in the management account and apply it to all accounts in the organization
AWS Organizations allows you to create a single CloudTrail trail in the management account that automatically applies to all member accounts within the organization. This is the most efficient method as it eliminates the need for manual per-account configuration or custom automation, and it ensures consistent logging across the entire organization with centralized log delivery to a single S3 bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an S3 bucket policy to allow cross-account log delivery
Why it's wrong here
Bucket policy alone does not create trails.
- ✓
Create a CloudTrail trail in the management account and apply it to all accounts in the organization
Why this is correct
Organization trails log all accounts centrally.
- ✗
Use AWS Lambda to create trails in each account
Why it's wrong here
Complex and not as efficient as organization trail.
- ✗
Ask each account admin to create their own CloudTrail trail and deliver to a central S3 bucket
Why it's wrong here
Inefficient and may miss some accounts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS Organizations with multiple accounts. The security team needs to centrally monitor all API calls made in the member accounts. The team wants to ensure that all CloudTrail logs are delivered to a centralized S3 bucket in the management account. Which configuration should the security team implement?
medium- A.Configure CloudWatch cross-account subscription to send logs from member accounts to the management account.
- B.Enable CloudTrail in each member account and configure each trail to deliver logs to the same S3 bucket.
- ✓ C.Create an organization trail in the management account with the S3 bucket in the management account.
- D.Use Amazon S3 replication to copy logs from member account buckets to the management account bucket.
Why C: AWS Organizations supports creating an organization trail in the management account that automatically applies to all member accounts. This ensures that all API calls from every account in the organization are logged and delivered to a centralized S3 bucket in the management account without needing to configure individual trails or manage cross-account permissions manually.
Variation 2. A company uses AWS Organizations with multiple accounts. The security team needs to ensure that all accounts have CloudTrail enabled and that logs are delivered to a centralized S3 bucket in the management account. Which solution meets these requirements?
hard- A.Write a script that runs in each account using AWS Lambda to enable CloudTrail and point to the central bucket.
- B.Use AWS Config rules in each account to check CloudTrail status and remediate via Lambda.
- ✓ C.Use AWS CloudTrail with Organizations to create an organization trail that logs all accounts to the central bucket.
- D.Create an IAM role that each account assumes to enable CloudTrail and log to the central bucket.
Why C: AWS CloudTrail supports integration with AWS Organizations, allowing you to create an organization trail that automatically logs events for all accounts in the organization. This trail delivers log files to a single centralized S3 bucket in the management account without requiring per-account configuration, ensuring compliance with the security team's requirement.
Last reviewed: Jul 4, 2026
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.