Use an organization CloudTrail trail in the management account instead of per-account trails
A company is planning a migration from an on-premises data center to the AWS Cloud. The company plans to use multiple AWS accounts that are managed in an organization in AWS Organizations. The company will create a small number of accounts initially and will add accounts as needed. A solutions architect must design a solution that turns on AWS CloudTrail in all AWS accounts. What is the MOST operationally efficient solution that meets these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
An organization trail in the management account logs events for every account in the organization automatically, including accounts created later, so one trail covers the current and future accounts with no per-account automation.
A company is planning a migration to AWS Cloud and will use multiple accounts managed in an AWS Organization, creating a few accounts at first and adding more over time. CloudTrail must be turned on in all of the organization's accounts, and the solution must be the most operationally efficient.
Automating per-account trail creation with Lambda on a schedule or with a Systems Manager runbook. Both require a mechanism that runs repeatedly or is triggered per new account, and any gap in that mechanism means an account is unlogged, which is exactly the monitoring gap the requirement exists to prevent.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS CloudTrail supports an organization trail, which is created in the management account and records events for all accounts in the organization, including accounts added later, without any further configuration. Because the organization will grow as accounts are created, this is the only option that is automatically correct for both the current accounts and every future one, and it is a single trail to manage rather than one per account. That makes it the most operationally efficient choice by a wide margin, and it also gives the security team one consolidated set of logs for the whole organization.Why the Other Options Are Wrong
A: A Lambda function invoked on a daily schedule would have to enumerate the accounts and create a trail in each one, and any account created after that day's run would be unlogged until the next run, which leaves a monitoring gap and requires maintaining the function. D: A Systems Manager Automation runbook invoked through State Manager has the same per-account scaling problem and additionally requires managing runbook executions and state, which is more operational work than a single organization trail. C: Creating a trail in every account plus creating new trails whenever an account is created depends on an account-creation notification mechanism that is not described, needs one trail per account to maintain, and the SCP only prevents deletion or modification of the trails rather than creating them in the first place, so new accounts would be unlogged until the separate creation step runs.Community Comment Notes
The community voted 100 to 0 for B, with a commenter linking the AWS documentation page for creating a CloudTrail trail for an organization and noting that the per-account options are not operationally efficient, particularly option C since it requires managing a separate trail per account rather than relying on the organization trail.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →