Use an organization CloudTrail trail in the management account instead of per-account trails

Answer Correct answer: B — Create one CloudTrail trail in the management account configured to log events for all accounts in the organization.

A company is planning a migration from an on-premises data center to the AWS Cloud. The company plans to use multiple AWS accounts that are managed in an organization in AWS Organizations. The company will create a small number of accounts initially and will add accounts as needed. A solutions architect must design a solution that turns on AWS CloudTrail in all AWS accounts. What is the MOST operationally efficient solution that meets these requirements?

  1. Create an AWS Lambda function that creates a new CloudTrail trail in all AWS accounts in the organization. Invoke the Lambda function daily by using a scheduled action in Amazon EventBridge.
  2. Create a new CloudTrail trail in the organization's management account. Configure the trail to log all events for all AWS accounts in the organization. Correct Answer
  3. Create a new CloudTrail trail in all AWS accounts in the organization. Create new trails whenever a new account is created. Define an SCP that prevents deletion or modification of trails. Apply the SCP to the root OU.
  4. Create an AWS Systems Manager Automation runbook that creates a CloudTrail trail in all AWS accounts in the organization. Invoke the automation by using Systems Manager State Manager.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An organization trail in the management account logs events for every account in the organization automatically, including accounts created later, so one trail covers the current and future accounts with no per-account automation.

A company is planning a migration to AWS Cloud and will use multiple accounts managed in an AWS Organization, creating a few accounts at first and adding more over time. CloudTrail must be turned on in all of the organization's accounts, and the solution must be the most operationally efficient.

Automating per-account trail creation with Lambda on a schedule or with a Systems Manager runbook. Both require a mechanism that runs repeatedly or is triggered per new account, and any gap in that mechanism means an account is unlogged, which is exactly the monitoring gap the requirement exists to prevent.

Community Discussion (5 comments)

juanife 👍 1 Selected: B
I agree with option B, since the other ones are not operationally efficient. About letter C, I undoubtedly think that it is not needed for you to create avery single aws cloudtrail trail on each account to apply it
Santoshhhhh 👍 1
B is correct
pangchn 👍 3 Selected: B
B https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html
Dgix 👍 1 Selected: B
B is correct.
CMMC 👍 4 Selected: B
#B is the most operational efficient

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS CloudTrail supports an organization trail, which is created in the management account and records events for all accounts in the organization, including accounts added later, without any further configuration. Because the organization will grow as accounts are created, this is the only option that is automatically correct for both the current accounts and every future one, and it is a single trail to manage rather than one per account. That makes it the most operationally efficient choice by a wide margin, and it also gives the security team one consolidated set of logs for the whole organization.

Why the Other Options Are Wrong

A: A Lambda function invoked on a daily schedule would have to enumerate the accounts and create a trail in each one, and any account created after that day's run would be unlogged until the next run, which leaves a monitoring gap and requires maintaining the function. D: A Systems Manager Automation runbook invoked through State Manager has the same per-account scaling problem and additionally requires managing runbook executions and state, which is more operational work than a single organization trail. C: Creating a trail in every account plus creating new trails whenever an account is created depends on an account-creation notification mechanism that is not described, needs one trail per account to maintain, and the SCP only prevents deletion or modification of the trails rather than creating them in the first place, so new accounts would be unlogged until the separate creation step runs.

Community Comment Notes

The community voted 100 to 0 for B, with a commenter linking the AWS documentation page for creating a CloudTrail trail for an organization and noting that the per-account options are not operationally efficient, particularly option C since it requires managing a separate trail per account rather than relying on the organization trail.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide