AWS SAA-C03 · Question 01 · Domain 1.1: Secure Access
A company has multiple AWS accounts in an AWS Organizations organization. The security team wants to ensure that AWS CloudTrail is enabled across all accounts and cannot be disabled by any local account administrators.<br/><br/>What is the MOST secure way to achieve this?
Answer options:
Create an IAM policy in each account that denies the cloudtrail:StopLogging action.
Use AWS Organizations Service Control Policies (SCPs) to deny the disabling of CloudTrail.
Use AWS Config rules to automatically remediate if CloudTrail is disabled.
Enable CloudTrail from the management account.
65 questions · hints · full answers · grading