New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 114 Topic 12 Discussion

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 114 Topic 12 Discussion

DOP-C02 Exam Topic 12 Question 114 Discussion:
Question #: 114
Topic #: 12

A security team wants to use AWS CloudTrail to monitor all actions and API calls in multiple accounts that are in the same organization in AWS Organizations. The security team needs to ensure that account users cannot turn off CloudTrail in the accounts.

Which solution will meet this requirement?


A.

Apply an SCP to all OUs to deny the cloudtrail:StopLogging action and the cloudtrail:DeleteTrail action.


B.

Create IAM policies in each account to deny the cloudtrail:StopLogging action and the cloudtrail:DeleteTrail action.


C.

Set up Amazon CloudWatch alarms to notify the security team when a user disables CloudTrail in an account.


D.

Use AWS Config to automatically re-enable CloudTrail if a user disables CloudTrail in an account.


Get Premium DOP-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.