A global media company uses AWS Organizations to manage over 100 AWS accounts. They need to ensure that all AWS accounts consistently log all API activity to a central S3 bucket in a dedicated logging account. This must be a mandatory control that cannot be disabled or altered by individual account administrators. Which design approach should be used?
- AEnable AWS Organizations CloudTrail integration, which automatically creates an organization trail that sends logs to the central S3 bucket.
- BUse a CloudFormation StackSet to deploy CloudTrail in each account, configured to send logs to the central S3 bucket.
- CManually configure CloudTrail in each account and grant cross-account access to the central S3 bucket.
- DImplement Service Control Policies (SCPs) to restrict CloudTrail configuration changes in all member accounts.
Show answer & explanationAnswer & explanation
Correct answer: A. Enable AWS Organizations CloudTrail integration, which automatically creates an organization trail that sends logs to the central S3 bucket.
AWS Organizations CloudTrail integration allows you to create an organization trail from the management account. This trail automatically logs all events for all accounts in the organization to a single, designated S3 bucket. Crucially, member accounts cannot disable or alter this organization trail, making it a mandatory and centralized logging solution.
Why the other options are wrong
- B. CloudFormation StackSets can deploy CloudTrail consistently, but account administrators can still disable or alter the deployed CloudTrail, violating the mandatory control requirement.
- C. Manual configuration is prone to errors and can be disabled by account administrators, failing the mandatory control requirement.
- D. While SCPs can restrict changes, they don't *create* the central logging mechanism. The organization trail itself is the most effective way to ensure mandatory, centralized logging, and implicitly prevents modification by member accounts.
AWS Organizations CloudTrail Integration
A feature of AWS Organizations that allows creating an 'organization trail' from the management account, which automatically logs all events for all accounts in the organization to a single S3 bucket.
- Centralizes CloudTrail logs from all member accounts.
- Member accounts cannot disable or modify the organization trail.
- Created and managed from the AWS Organizations management account.
- Ensures mandatory logging across the entire organization.
Memory trick: Org Trail: The 'O'rganization's 'R'equired 'G'uardian 'T'rail.