AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An organization's security team manages 50 AWS accounts with AWS Organizations. Compliance mandates that CloudTrail must remain enabled and its configuration must not be altered or deleted by account administrators. The enforcement must cover existing and new accounts automatically with minimal ongoing effort. Which solution satisfies these requirements using the fewest operational steps and aligns with AWS best practices?

  • Create an organization trail in the management account, enable log file validation, and share the trail with all member accounts.

  • Use AWS CloudFormation StackSets to deploy an IAM permissions boundary in every account that blocks CloudTrail modification actions.

  • Configure an AWS Config rule in each account that detects when CloudTrail logging is stopped and sends an SNS notification to the security team.

  • Attach an SCP to the organization root that denies cloudtrail:DeleteTrail, cloudtrail:StopLogging, and cloudtrail:UpdateTrail for all principals except those in the centralized logging account.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot