Medium1 markMultiple Choice
Domain 1.1: Secure AccessAWS OrganizationsSCPCloudTrailSecurity

AWS SAA-C03 · Question 01 · Domain 1.1: Secure Access

A company has multiple AWS accounts in an AWS Organizations organization. The security team wants to ensure that AWS CloudTrail is enabled across all accounts and cannot be disabled by any local account administrators.<br/><br/>What is the MOST secure way to achieve this?

Answer options:

A.

Create an IAM policy in each account that denies the cloudtrail:StopLogging action.

B.

Use AWS Organizations Service Control Policies (SCPs) to deny the disabling of CloudTrail.

C.

Use AWS Config rules to automatically remediate if CloudTrail is disabled.

D.

Enable CloudTrail from the management account.

How to approach this question

Look for centralized, preventive controls when managing multiple accounts.

Full Answer

B.Use AWS Organizations Service Control Policies (SCPs) to deny the disabling of CloudTrail.✓ Correct
Use AWS Organizations Service Control Policies (SCPs) to deny the disabling of CloudTrail.
Service Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts.

Common mistakes

Confusing reactive controls (AWS Config) with preventive controls (SCPs).

Practice the full AWS SAA-C03 Practice Exam 6

65 questions · hints · full answers · grading

More questions from this exam