Query an Athena table over the organization CloudTrail trail with partition projection to find top users and roles
A company has multiple AWS accounts in an organization in AWS Organizations that has all features enabled. The company’s DevOps administrator needs to improve security across all the company's AWS accounts. The administrator needs to identify the top users and roles in use across all accounts. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
69% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Athena with partition projection lets a table be queried directly over the CloudTrail S3 layout without ETL, partition management, or repeated full scans, which is what makes cross-account ranking operationally efficient at this data volume (C). Contributor Insights (A) is designed to surface the top contributors from a set of metrics, not to rank arbitrary log-field values across accounts, so it is the wrong tool for ranking userIdentity.arn occurrences. Access Analyzer's unused access analysis (B) finds unused and externally accessible permissions, not the most-used principals, and the Organizations service access report (D) reports service usage rather than user and role activity.
Finding the top users and roles across all accounts requires the CloudTrail data from every account in one place and a query engine efficient enough to rank principals at that scale. An organization trail aggregates CloudTrail logs from all member accounts into a single S3 location, an Athena table defined with partition projection avoids the slow, costly process of partitioning and loading the data, and a SQL query against that table ranks the userIdentity.arn values to produce the answer.
Using CloudWatch Contributor Insights on the userIdentity.arn log field (A) — Contributor Insights ranks top contributors among the metrics it observes in CloudWatch, and it is not a general-purpose log-field ranking tool for determining which principals are most active across accounts. Using IAM Access Analyzer unused access analysis (B) — that analysis reports unused IAM entities and external access findings, which is the opposite of ranking principals by usage. Using an Organizations service access report (D) — it reports which AWS services were accessed, not which users or roles performed the accesses.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To identify the top users and roles across all accounts, the CloudTrail data from every account must be brought together and then queried at scale. An organization trail delivers CloudTrail events from all member accounts into a single S3 location (C). Defining an Athena table with partition projection means queries run directly against that S3 layout without requiring partitions to be managed, data to be loaded, or full tables to be scanned on each run, which is precisely why this is the most operationally efficient option. A SQL query grouping on userIdentity.arn then ranks the principals and yields the top users and roles. C is correct.Why the Other Options Are Wrong
A creates an organization trail delivered to CloudWatch Logs and a CloudWatch Contributor Insights rule for the userIdentity.arn field. Contributor Insights is designed to surface the top contributors from CloudWatch metrics, such as which dimension value contributes most to a sum or count of a metric; it is not a general mechanism for ranking arbitrary values of a log field across accounts, so it does not answer this question. Several commenters preferred A citing operational efficiency, but the analysis capability is the wrong one. B uses IAM Access Analyzer unused access analysis for the organization, which reports unused or externally accessible permissions and is the opposite of ranking principals by how much they are used. D generates an Organizations service access report per account and inspects the last-accessed-by fields, which reports service usage and account attribution rather than identifying the top individual users and roles. C is correct.Community Comment Notes
Community voted C (69), with A a 31 percent minority. teo2157 and Ky_24 argued for C, noting that Athena with partition projection queries CloudTrail logs across all accounts much more efficiently than CloudWatch Contributor Insights, and Ky_24 explained that partition projection removes the need to define partitions manually. Erso preferred A on the basis that the question emphasizes operational efficiency, but the minority position does not address the capability mismatch in Contributor Insights.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →