Hard1 markMultiple Choice
Domain 1.2: Security ControlsSecurityOrganizationsSCP

AWS SAP-C02 · Question 06 · Domain 1.2: Security Controls

An enterprise uses AWS Organizations with all features enabled. The CISO mandates that no AWS account can disable AWS CloudTrail, and this rule must apply to the root user of member accounts. What is the MOST secure way to enforce this?

Answer options:

A.

Create an IAM policy denying cloudtrail:StopLogging and attach it to all users in all accounts.

B.

Apply a Service Control Policy (SCP) to the Organization root that denies the cloudtrail:StopLogging action.

C.

Use AWS Config rules to automatically remediate if CloudTrail is disabled.

D.

Enable CloudTrail Organization trails from the management account.

How to approach this question

Identify the mechanism that can restrict the root user in member accounts.

Full Answer

B.Apply a Service Control Policy (SCP) to the Organization root that denies the cloudtrail:StopLogging action.✓ Correct
Apply a Service Control Policy (SCP) to the Organization root that denies the cloudtrail:StopLogging action.
Service Control Policies (SCPs) offer central control over the maximum available permissions for all accounts in your organization, including the root user.

Common mistakes

Relying on IAM policies, which local administrators can modify or bypass using the root user.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 6

75 questions · hints · full answers · grading

More questions from this exam