Hard1 markMultiple Choice
Domain 1.1: Secure AccessAWS OrganizationsSCPCloudTrail

AWS SAA-C03 · Question 04 · Domain 1.1: Secure Access

A large enterprise uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no user or role in any member account can disable AWS CloudTrail. What is the MOST efficient way to enforce this?

Answer options:

A.

Create an IAM policy denying cloudtrail:StopLogging and attach it to all users in all accounts.

B.

Create a Service Control Policy (SCP) that denies the cloudtrail:StopLogging action and attach it to the root of the organization.

C.

Use AWS Config rules to automatically remediate if CloudTrail is disabled.

D.

Configure CloudTrail to use a KMS key that no one has access to.

How to approach this question

Identify the requirement for cross-account permission boundaries and select SCPs.

Full Answer

B.Create a Service Control Policy (SCP) that denies the cloudtrail:StopLogging action and attach it to the root of the organization.✓ Correct
Create a Service Control Policy (SCP) that denies the cloudtrail:StopLogging action and attach it to the root of the organization.
Service Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. They ensure that accounts stay within your organization's access control guidelines.

Common mistakes

Confusing SCPs with standard IAM policies.

Practice the full AWS SAA-C03 Practice Exam 5

65 questions · hints · full answers · grading

More questions from this exam