For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 51
    Hard1 markMultiple Choice
    Domain 1.4: Multi-Account EnvironmentOrganizationsSecurityCloudTrail

    AWS SAP-C02 · Question 51 · Domain 1.4: Multi-Account Environment

    A company is designing a multi-account strategy using AWS Organizations. They want to isolate their production environment from their development environment. They also need a centralized logging account to store all AWS CloudTrail logs securely. Which combination of actions represents the BEST practice for this architecture? (Select THREE)

    Answer options:

    A.

    Create separate Organizational Units (OUs) for Production and Development.

    B.

    Create a dedicated Log Archive account and configure an Organization-level CloudTrail trail to deliver logs to an S3 bucket in this account.

    C.

    Apply an SCP to the Organization root to prevent any member account from modifying or deleting the CloudTrail trail.

    D.

    Use VPC peering to connect all Development VPCs to the Production VPCs.

    E.

    Store the CloudTrail logs in the Management account.

    F.

    Configure AWS IAM users in the Production account and share them with the Development account.

    How to approach this question

    Identify AWS Landing Zone best practices.

    Full Answer

    Create separate Organizational Units (OUs) for Production and Development., Create a dedicated Log Archive account and configure an Organization-level CloudTrail trail to deliver logs to an S3 bucket in this account., Apply an SCP to the Organization root to prevent any member account from modifying or deleting the CloudTrail trail.
    Best practices for multi-account environments include separating environments into OUs, using a dedicated Log Archive account for centralized CloudTrail logs, and using SCPs to protect those logs from tampering.

    Common mistakes

    Storing logs in the Management account, which violates the principle of least privilege.
    Question 50All questionsQuestion 52

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →