🔍

AWS Certified Security - Specialty SCS-C02 — Question 78

Topic 1 · Question 78 of 307

Topic 1 · Question 78

A company plans to create individual child accounts within an existing organization in AWS Organizations for each of its DevOps teams. AWS CloudTrail has been enabled and configured on all accounts to write audit logs to an Amazon S3 bucket in a centralized AWS account. A security engineer needs to ensure that DevOps team members are unable to modify or disable this configuration. How can the security engineer meet these requirements?