A company uses AWS Organizations and has AWS CloudTrail enabled in all Regions. A security engineer must ensure CloudTrail cannot be disabled. Which solution meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a service control policy (SCP) with an explicit Deny for the StopLogging and DeleteTrail actions. Attach the SCP to the root OU..
Why this is the answer
The correct solution is to create a Service Control Policy (SCP) with an explicit Deny for the StopLogging and DeleteTrail actions and attach it to the root OU. SCPs are a feature of AWS Organizations that allow you to centrally manage permissions for all accounts in your organization. An explicit Deny in an SCP overrides any Allow permissions, even those granted by an administrator, effectively preventing anyone in any member account from stopping or deleting CloudTrail trails. Enabling CloudTrail log file integrity validation ensures logs haven't been tampered with, but doesn't prevent trails from being disabled. Enabling SSE-KMS encrypts logs but doesn't prevent their deletion or stopping the trail. Creating IAM policies for users to prevent DescribeTrails and GetTrailStatus only restricts viewing trail status, not disabling it, and would need to be applied to every user, which is not scalable or comprehensive enough.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed