AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A global media company uses AWS Organizations to manage over 100 AWS accounts. They need to establish a centralized logging solution for all API calls made to AWS services across all accounts for auditing and security analysis. The solution must ensure that logs are immutable and stored in a central, secure S3 bucket in a dedicated logging account. Which feature should be implemented?

  1. ACreate an organization trail in AWS CloudTrail.
  2. BEnable AWS Config rules to monitor API calls and send notifications to the central logging account.
  3. CConfigure individual CloudTrail trails in each account to log to the central S3 bucket.
  4. DUse Amazon Kinesis Data Firehose to stream all API calls to the central S3 bucket.
Show answer & explanation

Correct answer: A. Create an organization trail in AWS CloudTrail.

An organization trail in AWS CloudTrail is specifically designed to log all events from all member accounts in an AWS Organization to a single S3 bucket in a designated management or logging account, ensuring centralized and immutable logging for auditing purposes.

Why the other options are wrong

  • B. AWS Config monitors resource configurations and compliance, not API calls for security auditing. It's a detective control, not a logging solution for all API events.
  • C. While technically possible, configuring individual CloudTrail trails across 100+ accounts is complex, error-prone, and difficult to manage consistently, especially for enforcing immutability and central storage.
  • D. Amazon Kinesis Data Firehose is a delivery service for streaming data, but it requires a source for the API call data. CloudTrail is the native service for logging AWS API calls, and an organization trail is the correct way to centralize this across accounts.

CloudTrail Organization Trails

An AWS CloudTrail organization trail logs all events from all AWS accounts in an AWS Organization to a single Amazon S3 bucket, providing centralized and immutable audit logging.

  • Centralizes CloudTrail logs from all member accounts.
  • Created and managed from the management account.
  • Logs events to a single S3 bucket (often in a dedicated logging account).
  • Ensures immutable audit trails for compliance.

Memory trick: Organization Trails Optimize CloudTrail's Centralized Logging.

More Design Secure Architectures questions