A global SaaS provider runs its platform across multiple AWS accounts managed by AWS Organizations. All API calls to AWS resources must be audited, tracked for changes, and stored durably and securely to satisfy regulatory compliance. The solution should minimize operational overhead. Which approach meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new AWS CloudTrail trail in the organization’s management account. Create a new Amazon S3 bucket with versioning enabled to store the logs. Configure the trail to apply to all accounts in the organization and enable MFA delete and encryption on the S3 bucket..
Why this is the answer
The correct answer centralizes CloudTrail management and storage, which is ideal for an AWS Organizations setup. Creating an organization trail in the management account automatically applies to all member accounts, minimizing operational overhead. Storing logs in a single S3 bucket with versioning enabled ensures durability and an audit trail of changes, crucial for compliance. MFA delete and encryption enhance security. Option 1 is incorrect because while it uses a central S3 bucket, it doesn't specify an organization trail, meaning you'd have to configure trails in each account. Option 2 is incorrect because creating separate trails and S3 buckets in each member account drastically increases operational overhead and management complexity, making auditing across the organization difficult. Option 4 is incorrect because while it centralizes the trail and storage, it doesn't explicitly state the trail applies to all accounts in the organization, and SNS notifications are an additional feature, not the core solution for the primary requirements.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed