Correct Answer:D
Option A is INCORRECT because CloudTrail is a tool to track AWS API activities.
Option B is INCORRECT because IAM Roles are typically utilized when one AWS service grants access to another. The use case requires access management to several services.
Option C is INCORRECT because implementation of IAM Policies cannot manage access to specific sets of AWS services. Thus this option does not meet the requirements of the use case.
Option D is CORRECT because AWS Organisations orders AWS accounts into logical groups called organization units and is a suitable tool to manage many AWS accounts.