SCS-C02 · Question #14
A company manages multiple AWS accounts using AWS Organizations. The company's security team notices that some member accounts are not sending AWS CloudTrail logs to a centralized Amazon S3 logging bu
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #14. The question stem and answer options stay visible for context.
Question
A company manages multiple AWS accounts using AWS Organizations. The company's security team notices that some member accounts are not sending AWS CloudTrail logs to a centralized Amazon S3 logging bucket. The security team wants to ensure there is at least one trail configured for all existing accounts and for any account that is created in the future. Which set of actions should the security team implement to accomplish this?
Options
- ACreate a new trail and configure it to send CloudTrail logs to Amazon S3. Use Amazon
- BDeploy an AWS Lambda function in every account to check if there is an existing trail and create
- CEdit the existing trail in the Organizations management account and apply it to the organization.
- DCreate an SCP to deny the cloudtrail:Delete* and cloudtrail:Stop* actions. Apply the SCP to all
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.