For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Associate (SAA-C03)AWS SAA-C03 Practice Exam 4Question 01
    Medium1 markMultiple Choice
    Domain 1.1: Secure AccessSecurityAWS OrganizationsIAMCloudTrail

    AWS SAA-C03 · Question 01 · Domain 1.1: Secure Access

    A company has multiple AWS accounts in an AWS Organizations organization. The security team wants to ensure that no user or role in any member account can disable AWS CloudTrail. <br/><br/>Which solution is the MOST secure and requires the LEAST operational overhead?

    Answer options:

    A.

    Create an IAM permissions boundary in each account that denies the cloudtrail:StopLogging action.

    B.

    Create a Service Control Policy (SCP) that denies the cloudtrail:StopLogging action and attach it to the organization root.

    C.

    Use AWS Config rules to automatically remediate and re-enable CloudTrail if it is disabled.

    D.

    Modify the resource-based policy of the CloudTrail S3 bucket to deny the StopLogging API call.

    How to approach this question

    Identify the requirement for cross-account preventative security controls. AWS Organizations SCPs are the best fit for this.

    Full Answer

    B.Create a Service Control Policy (SCP) that denies the cloudtrail:StopLogging action and attach it to the organization root.✓ Correct
    Create a Service Control Policy (SCP) that denies the cloudtrail:StopLogging action and attach it to the organization root.
    Service Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.

    Common mistakes

    Confusing SCPs (preventative) with AWS Config (detective/reactive).
    All questionsQuestion 02

    Practice the full AWS SAA-C03 Practice Exam 4

    65 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q02An application running on Amazon EC2 instances needs to access an Amazon DynamoDB table. Both res...EasyQ03A company is designing a web application that will be hosted on AWS. The application will use an ...MediumQ04A company is building a mobile app that requires users to authenticate using their social media a...HardQ05A solutions architect is designing a VPC for a three-tier web application. The database tier must...MediumQ06A company requires that all data stored in Amazon S3 must be encrypted at rest using keys managed...Easy
    View all 65 questions →