For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 5Question 07
    Medium1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityCloudTrailCompliance

    AWS SAP-C02 · Question 07 · Domain 1.2: Security Controls

    A healthcare company is migrating to AWS and must comply with HIPAA. They are setting up a multi-account structure. They need to ensure that AWS CloudTrail logs are immutable, encrypted, and centrally stored. Additionally, they must automatically detect if any CloudTrail logging is disabled across the organization. Which combination of steps should the Architect take? (Select THREE)

    Answer options:

    A.

    Create an organization trail in AWS Organizations that logs to a central S3 bucket.

    B.

    Enable S3 Object Lock in compliance mode on the central CloudTrail S3 bucket.

    C.

    Deploy an AWS Config rule (cloudtrail-enabled) across all accounts using AWS CloudFormation StackSets.

    D.

    Use Amazon Macie to continuously monitor the CloudTrail S3 bucket for unauthorized modifications.

    E.

    Create a Service Control Policy (SCP) that denies the s3:DeleteObject action on all S3 buckets in the organization.

    F.

    Enable AWS Shield Advanced on the central CloudTrail S3 bucket to protect against DDoS attacks.

    How to approach this question

    Select the native AWS features for centralized logging, immutability, and configuration compliance monitoring.

    Full Answer

    Create an organization trail in AWS Organizations that logs to a central S3 bucket., Enable S3 Object Lock in compliance mode on the central CloudTrail S3 bucket., Deploy an AWS Config rule (cloudtrail-enabled) across all accounts using AWS CloudFormation StackSets.
    For strict compliance, an Organization Trail ensures all accounts are logged centrally. S3 Object Lock (Compliance mode) provides WORM (Write Once Read Many) storage, ensuring immutability. AWS Config continuously monitors resource configurations, including CloudTrail status.

    Common mistakes

    Selecting Macie for log integrity, or applying overly broad SCPs.
    Question 06All questionsQuestion 08

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 5

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is redesigning its AWS network architecture across 50 AWS accounts and 3 AWS ...HardQ02A company uses AWS Organizations to manage multiple accounts. The security team mandates that no ...MediumQ03A financial institution requires a disaster recovery strategy for its critical trading applicatio...HardQ04An enterprise is setting up a new multi-account AWS environment using AWS Control Tower. They nee...MediumQ05A company has a complex AWS environment with hundreds of linked accounts under AWS Organizations....Hard
    View all 75 questions →