nerdexam
Amazon

SCS-C03 · Question #150

A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account. All AWS account activity across all member accounts must be logged and repor

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #150. The question stem and answer options stay visible for context.

Submitted by jakub_pl· Mar 6, 2026Logging and Monitoring

Question

A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account. All AWS account activity across all member accounts must be logged and reported to the dedicated security account. The company must retain all the activity logs in a secure storage location within the dedicated security account for 2 years. No changes or deletions of the logs are allowed. Which combination of steps will meet these requirements with the LEAST operational overhead? (Select TWO.)

Options

  • AIn the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in
  • BIn the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in
  • CIn the dedicated security account, create an Amazon S3 bucket with an S3 Lifecycle configuration
  • DCreate an AWS CloudTrail organization trail. Configure logs to be delivered to the Amazon S3
  • ETurn on AWS CloudTrail in each account and forward logs to the dedicated security account by

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CloudTrail#S3 Object Lock#Organizations#log retention
Full SCS-C03 Practice