Courseiva

CV0-004 Cloud Architecture and Design Practice Question

A cloud architect is designing a landing zone in AWS Organizations. The security team mandates that all member accounts must centrally log API activity and that individual account administrators must not be able to disable or alter the log destination. The architect needs to enforce this across every current and future account with minimal operational overhead. Which combination of actions should the architect take?

⚠ Common exam trap

The trap here is assuming that a detective control such as AWS Config or Control Tower guardrails prevents an account administrator from stopping logging, when only a preventive control like an SCP actually blocks the action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an organization trail in CloudTrail from the management account with an S3 bucket in a dedicated log archive account, and attach a service control policy (SCP) denying cloudtrail:StopLogging and cloudtrail:DeleteTrail to all member accounts.

Centralized, tamper-resistant logging across an entire AWS Organization is achieved with an organization trail created from the management account that delivers to a log archive account, combined with an SCP that denies the trail-stopping and trail-deletion actions to member accounts. This design automatically covers future accounts and prevents local administrators from disabling logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable CloudTrail in each member account individually, and use AWS Config rules to detect when a trail is stopped so the security team can be notified.

    Why it's wrong here

    Per-account trails require manual enablement for every new account and leave a gap where logging is absent until someone configures it. AWS Config detection is reactive: it reports that a trail was stopped after the fact but does not prevent an account administrator from disabling logging in the first place.

  • ✗

    Enable AWS CloudTrail Lake in the management account and configure an event data store that ingests events from all member accounts through a resource-based policy.

    Why it's wrong here

    CloudTrail Lake is an analytics and query service for stored event data; it does not replace the requirement to enable event logging in each account. A CloudTrail Lake event data store does not automatically capture management events from member accounts unless trails or CloudTrail integration already deliver them.

  • ✓

    Create an organization trail in CloudTrail from the management account with an S3 bucket in a dedicated log archive account, and attach a service control policy (SCP) denying cloudtrail:StopLogging and cloudtrail:DeleteTrail to all member accounts.

    Why this is correct

    An organization trail automatically applies to all accounts in the organization, including accounts added later, and delivers events to a central S3 bucket. The SCP then removes the ability of member account principals to stop or delete the trail, satisfying the tamper-resistance requirement without per-account configuration.

  • ✗

    Configure AWS Control Tower with a detective guardrail that monitors CloudTrail configuration drift and sends findings to Security Hub for remediation.

    Why it's wrong here

    Detective guardrails in AWS Control Tower identify noncompliant resources but do not block the action that causes noncompliance. A member account administrator could still stop the trail, and remediation would occur only after the drift is detected, leaving a window in which API activity is unlogged.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.