For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 2Question 10
    Medium1 markMultiple Choice
    Domain 1.4: Multi-Account EnvironmentCloudTrailSecurityMulti-Account

    AWS SAP-C02 · Question 10 · Domain 1.4: Multi-Account Environment

    An architect is designing a multi-account structure. The security team requires that all AWS CloudTrail logs from all accounts be stored in a centralized, immutable S3 bucket in a dedicated 'Log Archive' account. What is the MOST secure and scalable way to implement this?

    Answer options:

    A.

    Create an Organization Trail in the management account. Configure it to log to the S3 bucket in the Log Archive account with S3 Object Lock enabled.

    B.

    Create a CloudTrail trail in each account manually and point them to the centralized S3 bucket.

    C.

    Use AWS Config to aggregate logs into the Log Archive account.

    D.

    Stream CloudTrail logs to CloudWatch Logs in each account, then use a Lambda function to forward them to the central S3 bucket.

    How to approach this question

    Combine Organization-level features with S3 immutability features.

    Full Answer

    A.Create an Organization Trail in the management account. Configure it to log to the S3 bucket in the Log Archive account with S3 Object Lock enabled.✓ Correct
    Create an Organization Trail in the management account. Configure it to log to the S3 bucket in the Log Archive account with S3 Object Lock enabled.
    AWS Organizations integration with CloudTrail allows creating an Organization Trail that logs all accounts automatically. S3 Object Lock (WORM model) ensures the logs cannot be deleted or modified.

    Common mistakes

    Choosing manual trail creation which fails to scale.
    Question 09All questionsQuestion 11

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A company is setting up a multi-account AWS environment using AWS Organizations. They need to ens...EasyQ02An enterprise needs to connect its on-premises data center to AWS. They require a dedicated, priv...EasyQ03A company wants to share a single AWS Transit Gateway across multiple AWS accounts within their A...EasyQ04An architect needs to design a highly available database architecture that spans multiple AWS Reg...EasyQ05A global financial institution is migrating its core banking application to AWS. The application ...Medium
    View all 75 questions →