The company will create separate child accounts in AWS Organizations for DevOps teams. AWS CloudTrail is enabled in all accounts and delivers audit logs to an Amazon S3 bucket in a central account. The security engineer must prevent DevOps team members from modifying or disabling this configuration. How should this be enforced?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a service control policy (SCP) that denies changes to the specific CloudTrail trail and attach it to the relevant organizational unit (OU) or accounts in Organizations..
Why this is the answer
Creating a Service Control Policy (SCP) is the most effective solution because SCPs apply to all accounts within an Organizational Unit (OU) or directly to individual accounts, including the root user. This ensures that no one, not even the root user in the child accounts, can disable or modify the CloudTrail configuration. IAM policies attached to the root user are not possible, as the root user cannot have IAM policies attached. An S3 bucket policy in the central account would protect the S3 bucket itself, but not prevent the DevOps teams from modifying the CloudTrail trail configuration within their own accounts. Attaching an IAM policy to a new IAM group would only affect users in that group, and would not prevent the root user or other IAM users/roles from making changes.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed