Question 1 · choose 1
An organization needs a record of API activity from every current and future account. The records must be stored in an S3 bucket in a dedicated log archive account, and administrators in member accounts must not be able to stop or change the logging. What should the security team do?
- AUse a StackSet to create a multi-Region trail in each account that delivers to the log archive bucket
- BCreate an organization trail from the management account that logs to the log archive bucket
- CRely on CloudTrail event history in each account and export it to the log archive account each month
- DCreate a multi-Region trail in the management account that delivers to the log archive account's bucket
Show the answer and why
AUse a StackSet to create a multi-Region trail in each account that delivers to the log archive bucket
Incorrect
A trail created in a member account belongs to that account, so its administrators can stop or delete it.
BCreate an organization trail from the management account that logs to the log archive bucket
Correct
An organization trail logs events for the management account and all member accounts, is added to accounts that join later, and member accounts cannot remove or modify it.
CRely on CloudTrail event history in each account and export it to the log archive account each month
Incorrect
Event history holds only 90 days of management events per Region and account. It is not a durable, centrally controlled record.
DCreate a multi-Region trail in the management account that delivers to the log archive account's bucket
Incorrect
A trail that is not applied to the organization logs only the account it is created in, so member account activity is missing.
The organization trail is the control that member accounts cannot touch. It can also be created by a CloudTrail delegated administrator account, and the bucket policy must allow CloudTrail to write the organization's log files.
AWS documentation