AWS SAP-C02 · Question 06 · Domain 1.2: Security Controls
An enterprise uses AWS Organizations with all features enabled. The CISO mandates that no AWS account can disable AWS CloudTrail, and this rule must apply to the root user of member accounts. What is the MOST secure way to enforce this?
Answer options:
Create an IAM policy denying cloudtrail:StopLogging and attach it to all users in all accounts.
Apply a Service Control Policy (SCP) to the Organization root that denies the cloudtrail:StopLogging action.
Use AWS Config rules to automatically remediate if CloudTrail is disabled.
Enable CloudTrail Organization trails from the management account.
75 questions · hints · full answers · grading