nerdexam
Amazon

SCS-C02 · Question #104

A company plans to create individual child accounts within an existing organization in AWS Organizations for each of its DevOps teams. AWS CloudTrail has been enabled and configured on all accounts to

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #104. The question stem and answer options stay visible for context.

Submitted by yuriko_h· Mar 6, 2026Security Logging and Monitoring

Question

A company plans to create individual child accounts within an existing organization in AWS Organizations for each of its DevOps teams. AWS CloudTrail has been enabled and configured on all accounts to write audit logs to an Amazon S3 bucket in a centralized AWS account. A security engineer needs to ensure that DevOps team members are unable to modify or disable this configuration. How can the security engineer meet these requirements?

Options

  • ACreate an IAM policy that prohibits changes to the specific CloudTrail trail and apply the policy to
  • BCreate an S3 bucket policy in the specified destination account for the CloudTrail trail that
  • CCreate an SCP that prohibits changes to the specific CloudTrail trail and apply the SCP to the
  • DCreate an IAM policy that prohibits changes to the specific CloudTrail trail and apply the policy to

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#SCP#CloudTrail protection#AWS Organizations#audit log integrity
Full SCS-C02 Practice