Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator needs to centralize logs from multiple AWS accounts into a single S3 bucket for analysis. Which solution is the MOST operationally efficient?

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by choosing Kinesis or replication, missing that CloudTrail natively supports cross-account S3 delivery, which is the simplest and most cost-effective method for centralizing logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure CloudTrail in each account to deliver logs to the same S3 bucket in the central account.

AWS CloudTrail can be configured in each account to deliver logs directly to the same S3 bucket in a central account by specifying the central bucket's ARN and setting appropriate bucket policies. This approach is operationally efficient as it eliminates the need for intermediate services or replication, reducing complexity and cost while ensuring logs are centralized without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use S3 replication to copy logs from each account's bucket to a central bucket.

    Why it's wrong here

    S3 replication is unnecessary for this scenario because CloudTrail natively supports direct cross-account delivery to a central S3 bucket. Adding replication requires enabling versioning on source buckets, configuring replication rules, and paying for inter-region data transfer, while also suffering from event-driven replication latency. This indirect approach creates duplicate storage and operational overhead without providing any benefit over the native CloudTrail delivery mechanism.

  • ✗

    Use CloudWatch Logs subscription filter to stream logs to a central account.

    Why it's wrong here

    A CloudWatch Logs subscription filter is the wrong tool because it would force you to first configure CloudTrail to deliver events to CloudWatch Logs, then build a cross-account subscription that forwards those log streams to a central account using Kinesis Data Streams or Lambda. This adds significant moving parts, per-log-ingestion costs, and latency compared to having CloudTrail write directly to a shared S3 bucket. Additionally, CloudTrail log files are delimited JSON or compressed gzip objects designed for S3, not for stream processing.

  • ✗

    Use Amazon Kinesis Data Firehose to deliver logs from each account to a central S3 bucket.

    Why it's wrong here

    Amazon Kinesis Data Firehose is an unnecessarily complex intermediate step; CloudTrail cannot natively deliver to Firehose, so you would need to chain CloudTrail to CloudWatch Logs and then subscription-filter into Firehose to reach S3. This pipeline introduces per-GB ingest and delivery costs, adds processing latency, and complicates data integrity checks because Firehose may buffer and transform records. Direct S3 delivery from CloudTrail is the simplest supported integration and meets the requirement without requiring Firehose.

  • ✓

    Configure CloudTrail in each account to deliver logs to the same S3 bucket in the central account.

    Why this is correct

    Configure each account's CloudTrail trail to deliver logs to the same central S3 bucket by creating a shared destination bucket with a bucket policy that trusts the CloudTrail service principal (cloudtrail.amazonaws.com) and grants write permissions to each source account. Set a distinct log-file prefix per account or enable partition-based prefixes to keep logs organized, and ensure the bucket versioning is enabled for log integrity. This is the standard, AWS-supported method for centralizing CloudTrail logs across multiple accounts, requiring no replication, streaming, or additional services.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.