AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementHard

A company wants to centralize logging and auditing across all its AWS accounts, which are managed under AWS Organizations. They need to ensure that all AWS CloudTrail logs are delivered to a single, dedicated S3 bucket in a central logging account. No AWS account or user should be able to disable CloudTrail or modify its configuration to prevent logs from reaching the central bucket. Which solution provides the strongest, preventative control?

  1. AImplement an IAM policy in each account that explicitly denies 'cloudtrail:StopLogging' and 'cloudtrail:DeleteTrail'.
  2. BDeploy an AWS Config rule to detect non-compliant CloudTrail configurations and remediate them automatically.
  3. CEnable AWS Organizations delegated administrator for CloudTrail and create an organization trail from the central logging account.
  4. DConfigure a multi-region CloudTrail trail in each account and grant the central logging account S3 PutObject permissions.
Show answer & explanation

Correct answer: C. Enable AWS Organizations delegated administrator for CloudTrail and create an organization trail from the central logging account.

Enabling AWS Organizations delegated administrator for CloudTrail and creating an organization trail from the central logging account is the most robust solution. An organization trail logs all events from all accounts in the organization, and crucially, member accounts cannot disable it, modify it, or delete it, providing a strong preventative control.

Why the other options are wrong

  • A. IAM policies, while helpful, can be circumvented by the root user or other administrative roles if not carefully managed. An organization trail provides a stronger, organization-level immutability guarantee.
  • B. AWS Config is reactive; it detects non-compliance after it occurs. The requirement is for a *preventative* control to ensure logs are never prevented from reaching the central bucket.
  • D. Configuring individual trails in each account is prone to misconfiguration or accidental/malicious disabling. It's not a centralized, preventative control.

CloudTrail Organization Trails

An organization trail in AWS CloudTrail logs events for all AWS accounts in an AWS Organization, with centralized management and immutability from member accounts.

  • Centralized logging for all accounts in an organization.
  • Managed by the management account or a delegated administrator.
  • Member accounts cannot disable, modify, or delete organization trails.
  • Delivers logs to a single S3 bucket.

Memory trick: Organization Trails are the immutable logs for all accounts.

More Domain 4: Identity and Access Management questions