AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A global media company uses AWS Organizations to manage over 100 AWS accounts. They need to ensure that all API calls made to AWS services across the entire organization are consistently logged to a central Amazon S3 bucket in a dedicated security account. This setup must apply to all existing and newly created accounts automatically. Which feature of AWS CloudTrail should be used?

  1. ACreating an organization trail in the management account and configuring it to log events from all accounts in the organization to a central S3 bucket.
  2. BCreating individual CloudTrail trails in each account and configuring S3 bucket policies to allow cross-account writes.
  3. CConfiguring a single CloudTrail trail in the master account and enabling logging to an S3 bucket in the security account.
  4. DUsing AWS Config rules to monitor CloudTrail configurations in each account and trigger remediation for non-compliant accounts.
Show answer & explanation

Correct answer: A. Creating an organization trail in the management account and configuring it to log events from all accounts in the organization to a central S3 bucket.

An organization trail in AWS CloudTrail allows the management account to create a trail that logs all events from all accounts in an AWS Organization. This trail automatically applies to all existing and newly created accounts, ensuring consistent, centralized logging to a specified S3 bucket, which directly meets the requirements.

Why the other options are wrong

  • B. This approach requires manual configuration for each account and doesn't automatically apply to new accounts, making it inefficient and prone to errors for 100+ accounts.
  • C. A single trail in the master account only logs events from the master account, not from all member accounts in the organization.
  • D. AWS Config can monitor compliance, but it doesn't *create* the central audit trail itself. It would only detect if CloudTrail isn't configured correctly, rather than being the solution for centralized logging.

CloudTrail Organization Trails

An AWS CloudTrail organization trail is a trail created in the management account of an AWS Organization that logs all events from all member accounts in that organization to a specified Amazon S3 bucket.

  • Created by the management account in AWS Organizations.
  • Logs events from all member accounts (current and future).
  • Ensures consistent and centralized audit logging.

Memory trick: Org Trail: One Trail to Rule All Accounts' Logs.

More Design Secure Architectures questions