Topic 1 Question 292
A security team wants to use AWS CloudTrail to monitor all actions and API calls in multiple accounts that are in the same organization in AWS Organizations. The security team needs to ensure that account users cannot turn off CloudTrail in the accounts.
Which solution will meet this requirement?
Apply an SCP to all OUs to deny the cloudtrail:StopLogging action and the cloudtrail:DeleteTrail action.
Create IAM policies in each account to deny the cloudtrail:StopLogging action and the cloudtrail:DeleteTrail action.
Set up Amazon CloudWatch alarms to notify the security team when a user disables CloudTrail in an account.
Use AWS Config to automatically re-enable CloudTrail if a user disables CloudTrail in an account.
ユーザの投票
コメント(1)
- 正解だと思う選択肢: A
should be A
👍 2matt2002024/12/29
シャッフルモード