AWS SAA-C03 · Question 01 · Domain 1.1: Secure Access
A company has multiple AWS accounts in an AWS Organizations organization. The security team wants to ensure that no user or role in any member account can disable AWS CloudTrail. <br/><br/>Which solution is the MOST secure and requires the LEAST operational overhead?
Answer options:
Create an IAM permissions boundary in each account that denies the cloudtrail:StopLogging action.
Create a Service Control Policy (SCP) that denies the cloudtrail:StopLogging action and attach it to the organization root.
Use AWS Config rules to automatically remediate and re-enable CloudTrail if it is disabled.
Modify the resource-based policy of the CloudTrail S3 bucket to deny the StopLogging API call.
65 questions · hints · full answers · grading