For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 1Question 52
    Hard1 markMultiple Choice
    Domain 1.4: Multi-Account EnvironmentSecurityLoggingMulti-AccountKMS

    AWS SAP-C02 · Question 52 · Domain 1.4: Multi-Account Environment

    An enterprise is setting up a centralized logging architecture using AWS Organizations. They want all VPC Flow Logs, AWS CloudTrail logs, and Amazon Route 53 DNS logs from all member accounts to be sent to a central Amazon S3 bucket in a dedicated 'Log Archive' account. Which TWO configurations are required to achieve this securely? (Select TWO)

    Answer options:

    A.

    Create IAM cross-account roles in the Log Archive account for each member account to assume.

    B.

    Configure an S3 bucket policy on the central bucket that grants write access to the specific AWS services (CloudTrail, VPC Flow Logs, Route 53) from the organization's accounts.

    C.

    Encrypt the central S3 bucket using an AWS KMS Customer Managed Key (CMK) and share the key policy with the organization.

    D.

    Use AWS Resource Access Manager (RAM) to share the S3 bucket with the organization.

    E.

    Configure VPC Peering between all member accounts and the Log Archive account.

    F.

    Enable S3 Block Public Access only on the member accounts.

    How to approach this question

    Understand cross-account S3 permissions (Bucket Policy) and cross-account KMS encryption (CMK).

    Full Answer

    Configure an S3 bucket policy on the central bucket that grants write access to the specific AWS services (CloudTrail, VPC Flow Logs, Route 53) from the organization's accounts. Encrypt the central S3 bucket using an AWS KMS Customer Managed Key (CMK) and share the key policy with the organization.
    To centralize logs, the destination S3 bucket must have a bucket policy allowing the respective AWS services to write to it. Furthermore, if the bucket is encrypted (which it should be), you MUST use a Customer Managed Key (CMK) because AWS managed keys (aws/s3) cannot be used across accounts.

    Common mistakes

    Thinking AWS RAM is used to share S3 buckets.
    Question 51All questionsQuestion 53

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01An enterprise has 50 VPCs across two AWS Regions. They need to establish transitive routing betwe...HardQ02A company uses AWS Organizations. The security team wants to ensure that no IAM user or role can ...MediumQ03An application requires a relational database with an RPO of 1 second and an RTO of less than 1 m...HardQ04A company is setting up a new multi-account environment. They want to automate the provisioning o...MediumQ05An organization wants to allocate AWS costs to specific business units. They use AWS Organization...Hard
    View all 75 questions →