Query an Athena table over the organization CloudTrail trail with partition projection to find top users and roles

Answer Correct answer: C — query an Athena table with partition projection over the organization CloudTrail trail to rank users and roles.

A company has multiple AWS accounts in an organization in AWS Organizations that has all features enabled. The company’s DevOps administrator needs to improve security across all the company's AWS accounts. The administrator needs to identify the top users and roles in use across all accounts. Which solution will meet these requirements with the MOST operational efficiency?

  1. Create a new organization trail in AWS CloudTrail. Configure the trail to send log events to Amazon CloudWatch Logs. Create a CloudWatch Contributor Insights rule for the userIdentity.arn log field. View the results in CloudWatch Contributor Insights.
  2. Create an unused access analysis for the organization by using AWS Identity and Access Management Access Analyzer. Review the analyzer results and determine if each finding has the intended level of permissions required for the workload.
  3. Create a new organization trail in AWS CloudTrail. Create a table in Amazon Athena that uses partition projection. Load the Athena table with CloudTrail data. Query the Athena table to find the top users and roles. Correct Answer
  4. Generate a Service access report for each account by using Organizations. From the results, pull the last accessed date and last accessed by account fields to find the top users and roles.

Community Votes

C
69%
A
31%

69% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Athena with partition projection lets a table be queried directly over the CloudTrail S3 layout without ETL, partition management, or repeated full scans, which is what makes cross-account ranking operationally efficient at this data volume (C). Contributor Insights (A) is designed to surface the top contributors from a set of metrics, not to rank arbitrary log-field values across accounts, so it is the wrong tool for ranking userIdentity.arn occurrences. Access Analyzer's unused access analysis (B) finds unused and externally accessible permissions, not the most-used principals, and the Organizations service access report (D) reports service usage rather than user and role activity.

Finding the top users and roles across all accounts requires the CloudTrail data from every account in one place and a query engine efficient enough to rank principals at that scale. An organization trail aggregates CloudTrail logs from all member accounts into a single S3 location, an Athena table defined with partition projection avoids the slow, costly process of partitioning and loading the data, and a SQL query against that table ranks the userIdentity.arn values to produce the answer.

Using CloudWatch Contributor Insights on the userIdentity.arn log field (A) — Contributor Insights ranks top contributors among the metrics it observes in CloudWatch, and it is not a general-purpose log-field ranking tool for determining which principals are most active across accounts. Using IAM Access Analyzer unused access analysis (B) — that analysis reports unused IAM entities and external access findings, which is the opposite of ranking principals by usage. Using an Organizations service access report (D) — it reports which AWS services were accessed, not which users or roles performed the accesses.

Community Discussion (7 comments)

Srikantha 👍 1 Selected: C
This option provides the MOST operational efficiency because it: Aggregates CloudTrail logs from all AWS accounts using a single organization trail. Leverages Amazon Athena to analyze logs at scale with SQL-like queries. Allows for automated and repeatable querying to identify top users and roles across the entire organization. Partition projection reduces the need for manual partition management, improving performance and automation.
teo2157 👍 3 Selected: C
Voting for C, agree with Ky_24
Erso 👍 1 Selected: A
MOST operation efficency is the key point here
teo2157 👍 3 Selected: C
Athena is much more efficient that CloudWatch Contributor Insights in this case
Ky_24 👍 4 Selected: C
You can use partition projection in Athena to optimize your queries by specifying how the logs are structured in S3. This makes the process of querying CloudTrail logs across multiple AWS accounts much more efficient.
f4b18ba 👍 4 Selected: A
Option A provides a solution that is operationally efficient, scalable, and directly addresses the requirement to identify the top users and roles in use across all AWS accounts. By leveraging AWS services like CloudTrail and CloudWatch Contributor Insights, the DevOps administrator can gain real-time insights with minimal setup and maintenance effort.
phu0298 👍 4
C A: While Contributor Insights can identify the top contributors (e.g., users and roles), it is limited to specific log patterns and is more suited for real-time analysis. This option is not as operationally efficient for long-term, detailed analysis across all accounts.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To identify the top users and roles across all accounts, the CloudTrail data from every account must be brought together and then queried at scale. An organization trail delivers CloudTrail events from all member accounts into a single S3 location (C). Defining an Athena table with partition projection means queries run directly against that S3 layout without requiring partitions to be managed, data to be loaded, or full tables to be scanned on each run, which is precisely why this is the most operationally efficient option. A SQL query grouping on userIdentity.arn then ranks the principals and yields the top users and roles. C is correct.

Why the Other Options Are Wrong

A creates an organization trail delivered to CloudWatch Logs and a CloudWatch Contributor Insights rule for the userIdentity.arn field. Contributor Insights is designed to surface the top contributors from CloudWatch metrics, such as which dimension value contributes most to a sum or count of a metric; it is not a general mechanism for ranking arbitrary values of a log field across accounts, so it does not answer this question. Several commenters preferred A citing operational efficiency, but the analysis capability is the wrong one. B uses IAM Access Analyzer unused access analysis for the organization, which reports unused or externally accessible permissions and is the opposite of ranking principals by how much they are used. D generates an Organizations service access report per account and inspects the last-accessed-by fields, which reports service usage and account attribution rather than identifying the top individual users and roles. C is correct.

Community Comment Notes

Community voted C (69), with A a 31 percent minority. teo2157 and Ky_24 argued for C, noting that Athena with partition projection queries CloudTrail logs across all accounts much more efficiently than CloudWatch Contributor Insights, and Ky_24 explained that partition projection removes the need to define partitions manually. Erso preferred A on the basis that the question emphasizes operational efficiency, but the minority position does not address the capability mismatch in Contributor Insights.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide