For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Associate (SAA-C03)AWS SAA-C03 Practice Exam 6Question 01
    Medium1 markMultiple Choice
    Domain 1.1: Secure AccessAWS OrganizationsSCPCloudTrailSecurity

    AWS SAA-C03 · Question 01 · Domain 1.1: Secure Access

    A company has multiple AWS accounts in an AWS Organizations organization. The security team wants to ensure that AWS CloudTrail is enabled across all accounts and cannot be disabled by any local account administrators.<br/><br/>What is the MOST secure way to achieve this?

    Answer options:

    A.

    Create an IAM policy in each account that denies the cloudtrail:StopLogging action.

    B.

    Use AWS Organizations Service Control Policies (SCPs) to deny the disabling of CloudTrail.

    C.

    Use AWS Config rules to automatically remediate if CloudTrail is disabled.

    D.

    Enable CloudTrail from the management account.

    How to approach this question

    Look for centralized, preventive controls when managing multiple accounts.

    Full Answer

    B.Use AWS Organizations Service Control Policies (SCPs) to deny the disabling of CloudTrail.✓ Correct
    Service Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts.

    Common mistakes

    Confusing reactive controls (AWS Config) with preventive controls (SCPs).
    All questionsQuestion 02

    Practice the full AWS SAA-C03 Practice Exam 6

    65 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q02A company has two AWS accounts: Account A for development and Account B for production. Developer...MediumQ03A mobile application needs to authenticate users using their social media accounts (Facebook, Goo...EasyQ04A company is running an application on Amazon EC2 instances. The application needs to connect to ...MediumQ05A company has 50 AWS accounts managed by AWS Organizations. The IT team wants to implement a cent...EasyQ06A company wants to restrict access to an Amazon S3 bucket so that only requests originating from ...Medium
    View all 65 questions →