Split a central Cost and Usage Report per account with an S3 event and Lambda

Answer Correct answer: B — Use an S3 event to run Lambda that writes each account's rows to its own S3 prefix, then grant each account access to that prefix.

A company that has multiple business units is using AWS Organizations with all features enabled. The company has implemented an account structure in which each business unit has its own AWS account. Administrators in each AWS account need to view detailed cost and utilization data for their account by using Amazon Athena. Each business unit can have access to only its own cost and utilization data. The IAM policies that govern the ability to set up AWS Cost and Usage Reports are in place. A central Cost and Usage Report that contains all data for the organization is already available in an Amazon S3 bucket. Which solution will meet these requirements with the LEAST operational complexity?

  1. In the organization's management account, use AWS Resource Access Manager (AWS RAM) to share the Cost and Usage Report data with each member account.
  2. In the organization's management account, configure an S3 event to invoke an AWS Lambda function each time a new file arrives in the S3 bucket that contains the central Cost and Usage Report. Configure the Lambda function to extract each member account’s data and to place the data in Amazon S3 under a separate prefix. Modify the S3 bucket policy to allow each member account to access its own prefix. Correct Answer
  3. In each member account, access AWS Cost Explorer. Create a new report that contains relevant cost information for the account. Save the report in Cost Explorer. Provide instructions that the account administrators can use to access the saved report.
  4. In each member account, create a new S3 bucket to store Cost and Usage Report data. Set up a Cost and Usage Report to deliver the data to the new S3 bucket.

Community Votes

B
66%
D
34%

66% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Because the consolidated report already exists, the cheapest path is to fan it out once with an S3 event and Lambda into per-account prefixes, rather than standing up a second Cost and Usage Report in every member account.

Each business unit account administrator must query only their own cost and utilization data through Athena. A consolidated organization-wide Cost and Usage Report already lands in one S3 bucket, and the goal is the least operational complexity.

Over-weighting the words least operational complexity and choosing per-account reports. Creating a new Cost and Usage Report in every member account duplicates billing pipelines that must each be monitored, whereas the S3 event plus Lambda path is fully automatic after one-time setup.

Community Discussion (18 comments)

trap 👍 9
Correct: D The option talks about LEAST operational complexity not LEAST operational overhead. Option B is quite complex
Dgix 👍 9 Selected: B
LEAST operational complexity, considering the report already is available in the bucket: B. After the initial setup, the process is fully automatic, which means the operational complexity involving separate actions by account managers isn't needed.
SIJUTHOMASP 👍 1 Selected: B
Multiple accounts since multiple business units has their own account. So, it is complex to do it in each member account rather than lambda solution in option B.
Spike2020 👍 1 Selected: D
It is easy to setup CUR. B works but unnecessarily complicated.
0b43291 👍 1 Selected: B
After the initial setup of the S3 event, Lambda function, and bucket policy modifications, the process becomes fully automatic, minimizing the ongoing operational complexity involving separate actions by account managers.
sashenka 👍 1 Selected: D
A Lambda-based solution for sharing Cost and Usage Reports, while powerful, introduces significant operational complexity due to the need to manage and maintain multiple AWS services and components. This includes Lambda functions, S3 events, S3 bucket policy, etc. The solution requires ongoing code maintenance, careful configuration management, and monitoring of multiple services, making it more complex than simpler alternatives like setting up individual CURs in member accounts. While it offers flexibility and automation capabilities, the added complexity might outweigh the benefits for basic cost-sharing requirements across AWS accounts.
AzureDP900 👍 1
Configures an S3 event that triggers a Lambda function every time a new file arrives in the central Cost and Usage Report bucket. The Lambda function extracts each member account's data from the central report. Stores the extracted data under separate prefixes for each member account in Amazon S3. Modifies the S3 bucket policy to grant access to each member account's prefix. By automating this process, Option B minimizes operational complexity while ensuring that each member account has access to its own cost and usage data without requiring manual setup or maintenance.
Danm86 👍 1
Already its mentioned the consolidated billing report is available in centralized bucket. Here if option D has to be chosen, then the Cost and Usage report have to be configured in individual accounts seperately again at individual accounts, which could add operational complexity, hence Option B seems to be right.
JoeTromundo 👍 2 Selected: B
In addition to what user Dgix commented, the fact that the S3 bucket must be in the account that creates the CUR does not make option B unfeasible. On the contrary, this option already assumes that the initial configuration of the bucket and the processing of the CUR report happen in the management account. Option B remains the recommended solution because it: Automates the data segmentation process. Ensures compliance with documentation by keeping the S3 bucket in the management account. Simplifies access control by using bucket policies to ensure that each account sees only its own data. Meets the requirement of lower operational complexity by centralizing the processing of the CUR. Therefore, even with the restriction that the S3 bucket must be in the management account, option B remains the best choice to meet the business requirements with the least operational effort.
asquared16 👍 2 Selected: D
B sounds like quite the adventure.
neta1o 👍 1 Selected: D
B would be very complex to parse the incoming files and separate by prefix. Then managing all the individual prefix shares. For that reason D seems like a better choice. Also the question mentions having the right permissions setup so they can configure their own CUR.
tqphuong 👍 2
Answer: Option D First Reason: The Cost and Usage Report (CUR) cannot be set up for cross-account delivery. According to the AWS documentation, “The account that creates the Cost and Usage Report must also own the Amazon S3 bucket that AWS sends the reports to.” This means each account must set up its own S3 bucket to receive its respective CUR. https://docs.aws.amazon.com/cur/latest/userguide/cur-consolidated-billing.html Second Reason: The question asks for the solution with the least operational complexity. Option D simplifies the process by allowing each account to independently manage its own CUR setup without requiring complex configurations or custom Lambda functions.
trungtd 👍 3 Selected: A
After some investigation, I found A could be a suitable choice, however it lacks a few details By using AWS RAM, you can share the S3 bucket (or specific prefixes within the bucket) containing the Cost and Usage Report with the member accounts. Each member account can set up Athena queries to access and analyze their own cost and utilization data from the shared S3 bucket. This approach ensures that each business unit can view its own data without accessing other units' data. B: too complicated C: Cost Explorer doesn't provide the raw cost and usage data that might be needed for detailed analysis with Athena. D: multiple Cost and Usage Reports, one for each account => out
trungtd 👍 2 Selected: B
The question asks for LEAST operational complexity But it seems that only the most complex option can solve the problem
red_panda 👍 4 Selected: D
Why B? The question talk about LEAST operations. D for me
VerRi 👍 1 Selected: B
The most straightforward option
pangchn 👍 2
B I don't like this type of question that shows the current AWS limit which need to use sneaky way, like lambda, to automate the process. This should be a potential new feature that AWS should improve in future since the billing and report is such a common scenrio as in the question.
CMMC 👍 1 Selected: B
With the Lambda to extract and separate each member account's cost and utilization data from the central Cost and Usage Report stored in the S3 bucket and S3 events to trigger the Lambda function, the process is automated and requires minimal ongoing management. Each member account can be given access only to its own prefix within the S3 bucket, ensuring that each business unit can only access its own cost data. Other options involve higher operational complexity and overhead.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An S3 event notification invokes Lambda on each new report delivery, the function extracts each member account's rows and writes them under a separate prefix, and a bucket policy grants each account read access to its own prefix. Athena queries those prefixes with the existing IAM cost-report permissions, and every future delivery is handled automatically with no per-account pipeline to maintain.

Why the Other Options Are Wrong

A: AWS RAM cannot share S3 objects, and there is no RAM resource-share type for Cost and Usage Report data. C: A saved Cost Explorer report is not queryable through Athena, so it does not satisfy the stated analytics requirement, and it also omits utilization data. D: Creating a separate Cost and Usage Report per member account multiplies billing pipelines, which is more operational work than a single automated fan-out.

Community Comment Notes

This was a close 59 to 31 community split between B and D. The top-voted comment for D argued the phrase is operational complexity rather than overhead, while the majority and the AWS exam answer favour B because the central report already exists and the fan-out runs itself after setup.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide