CCSP Cloud Platform and Infrastructure Security Practice Question
A startup is designing its first cloud landing zone and wants a guardrail that prevents any principal in the organization from disabling AWS CloudTrail logging in any account, including the management account, while still allowing normal administrative work. Which control achieves this with the LEAST operational overhead?
⚠ Common exam trap
The trap here is reaching for a detective control such as AWS Config or a CloudWatch alarm when the requirement is to prevent the action from succeeding at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An organization-level service control policy attached to the root that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail.
An organization root service control policy denies the trail-modification API calls for all principals in every account, making the guardrail preventive rather than detective and requiring no per-account upkeep. Detection rules, permissions boundaries, and remediation automation either act after the fact or leave uncovered principals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A CloudWatch Logs metric filter on the CloudTrail log group that triggers an AWS Lambda function to restart the trail.
Why it's wrong here
This is a reactive remediation loop that depends on logs still being delivered, which is not guaranteed once a trail is deleted or its destination changed. It adds moving parts, latency, and a window of lost audit data. It also cannot prevent an authorized administrator from acting again, so it is neither preventive nor low overhead.
- ✗
An IAM permissions boundary on every administrator role that denies the CloudTrail modification actions.
Why it's wrong here
Permissions boundaries must be attached to each role and are evaluated per principal, so new roles and accounts are not covered until someone updates them. They also do not constrain the management account's root user or roles that lack the boundary. This creates ongoing operational overhead and coverage gaps compared with a single organization-wide policy.
- ✓
An organization-level service control policy attached to the root that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail.
Why this is correct
A service control policy attached at the organization root sets the maximum available permissions for every account in the organization, including the management account when applied at the root. Denying the trail-modification actions blocks the operation regardless of identity-based policy, giving a single preventive guardrail with no per-account maintenance.
- ✗
An AWS Config rule that detects when a trail is stopped and sends an Amazon SNS notification to the security team.
Why it's wrong here
An AWS Config rule is detective, not preventive; by the time the notification fires, logging has already been disabled and the gap may never be recoverable. It also requires building and maintaining the remediation path. The scenario asks for a guardrail that stops the action itself, which a detection rule cannot do.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.