The security team must ensure CloudTrail stays enabled across all accounts in an AWS Organization and prevent account users from turning it off. Which control will enforce this?
Choose an answer
Tap an option to check your answer.
Correct answer: Attach an SCP to all OUs that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail actions..
Why this is the answer
Attaching a Service Control Policy (SCP) to all Organizational Units (OUs) that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail actions is the most effective and centralized way to enforce CloudTrail enablement across an AWS Organization. SCPs apply to all accounts within the OUs they are attached to, including the root, and cannot be overridden by IAM policies within those accounts. This ensures that no user or role, even with administrative privileges, can disable or delete CloudTrail. Creating IAM deny policies in each account is less scalable and prone to human error, as new accounts might not have the policy applied, and existing policies could be inadvertently modified or deleted. CloudWatch alarms only provide notification after the fact, not prevention. AWS Config can re-enable CloudTrail, but this is a reactive measure; an SCP provides proactive prevention.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed