AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your organization operates more than 200 AWS accounts under AWS Organizations. A dedicated log-archive account must store every account's CloudTrail management and data events in an encrypted S3 bucket. The security-ops account must receive near-real-time alerts whenever any account calls CreateNetworkInterface or DeleteTrail. The solution must automatically include future member accounts and require as little ongoing maintenance as possible.

Which architecture will satisfy these requirements?

  • Use CloudFormation StackSets to deploy an account-level CloudTrail trail, CloudWatch Logs group, metric filter, and alarm in every account. Configure each alarm to publish to an SNS topic in the security-ops account.

  • Enable AWS Config recorders in all accounts and aggregate the data with an organization AWS Config aggregator in the security-ops account. Deploy a managed Config rule that flags network interface creation and trail deletion and sends findings to SNS.

  • Create an organization CloudTrail trail that writes to an SSE-KMS-encrypted S3 bucket in the log-archive account. In the security-ops account, create a custom EventBridge event bus with an organization-wide resource policy and an EventBridge rule that matches CreateNetworkInterface and DeleteTrail and sends the events to an SNS topic.

  • Enable AWS Control Tower to create a central trail. Add an S3 ObjectCreated notification on the log-archive bucket that invokes a Lambda function in the security-ops account to scan new log files and publish SNS notifications when the two API calls are found.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot