Aggregate organisation audit activity in CloudTrail Lake and query it with SQL
A company has multiple AWS accounts that are in an organization in AWS Organizations. The company needs to store AWS account activity and query the data from a central location by using SQL. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
CloudTrail Lake is a managed audit data store that accepts events from every account in the organization and is queried with SQL directly, so no export to S3, no Athena setup, and no per-account log pipeline is needed.
A company has multiple AWS accounts inside an AWS Organization and needs to store account activity in a central location and query that data using SQL. The audit data across the organization has to be brought together rather than queried account by account.
Querying the CloudTrail event history page. That page shows events for the current account over a limited period and is not a SQL-queryable store, so it cannot serve as the central queryable location the requirement describes.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement has two parts, centrally store the activity and query it with SQL, and CloudTrail Lake satisfies both in a single managed service. A delegated administrator creates the CloudTrail Lake data store, specifies CloudTrail management events as the event source, and enables the data store for all accounts in the organization, so activity from every member account flows into one central store automatically as accounts are created. Queries are then run in CloudTrail Lake using SQL, so the security team gets a central queryable location without building an export pipeline. The delegated administrator model is what allows organisation-wide configuration, since a member account cannot configure this for the whole organization.Why the Other Options Are Wrong
A: Creating a trail in every account and sending management events to CloudWatch Logs does centralise the logs through cross-account observability, but CloudWatch Logs Insights is a log query experience rather than SQL over a durable central audit store, so it does not meet the stated SQL requirement as directly. C: The event history page is a console view of recent events in a single account, it is not a central store and it does not support SQL, so it fails both parts of the requirement. D: Deploying a separate CloudTrail Lake data store in each account via CloudFormation StackSets creates many independent stores rather than one central location, and querying across them is not a single query, so the centralisation requirement is not met.Community Comment Notes
The community voted 100 to 0 for B, and the top-voted comment noted that CloudTrail Lake lets you run SQL-based queries on your events. Another linked the AWS announcement describing CloudTrail Lake as a managed audit and security lake and observed that a delegated administrator is required to enable it, and a further commenter explained that enabling it for all accounts in the organization is what aggregates the events centrally.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →