AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An organization's security team manages 50 AWS accounts with AWS Organizations. Compliance mandates that CloudTrail must remain enabled and its configuration must not be altered or deleted by account administrators. The enforcement must cover existing and new accounts automatically with minimal ongoing effort. Which solution satisfies these requirements using the fewest operational steps and aligns with AWS best practices?
Attach an SCP to the organization root that denies cloudtrail:DeleteTrail, cloudtrail:StopLogging, and cloudtrail:UpdateTrail for all principals except those in the centralized logging account.
Use AWS CloudFormation StackSets to deploy an IAM permissions boundary in every account that blocks CloudTrail modification actions.
Configure an AWS Config rule in each account that detects when CloudTrail logging is stopped and sends an SNS notification to the security team.
Create an organization trail in the management account, enable log file validation, and share the trail with all member accounts.
A service control policy (SCP) attached to the organization's root is evaluated before IAM policies in every member account, including the root user. By explicitly denying cloudtrail:DeleteTrail, cloudtrail:StopLogging, and cloudtrail:UpdateTrail and adding an exception condition for the central logging account, the SCP prevents anyone else in any current or future account from disabling or changing CloudTrail. StackSets with permission boundaries only affect principals that use those boundaries and do not protect the root user. Creating an organization trail or AWS Config rules improves visibility but does not prohibit administrators from stopping or deleting the trail, so they do not meet the compliance requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SCP in AWS Organizations?
Open an interactive chat with Bash
How do SCPs interact with IAM policies?
Open an interactive chat with Bash
Why is using SCPs considered a best practice for managing AWS security?
Open an interactive chat with Bash
What is a Service Control Policy (SCP) in AWS Organizations?
Open an interactive chat with Bash
How does attaching an SCP to the organization root impact all AWS accounts under it?
Open an interactive chat with Bash
Why is an SCP preferred over other solutions for ensuring CloudTrail enforcement?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .