AWS SAA-C03 · Question 02 · Domain 1.1: Secure Access
A large enterprise uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no user, including root users, can disable AWS CloudTrail in any member account. Which TWO actions should the solutions architect take? (Select TWO.)
Answer options:
Create a Service Control Policy (SCP) that explicitly denies the cloudtrail:StopLogging action.
Attach an IAM permissions boundary to all IAM users in the member accounts.
Attach the SCP to the root of the AWS Organization.
Use AWS Config rules to automatically remediate disabled CloudTrail instances.
Create an IAM role in the management account to monitor CloudTrail status.
65 questions · hints · full answers · grading