Q151. A large company starts to use AWS organizations with consolidated billing feature to manage its separate departments. The AWS operation team has just
Created 3 OUs (organization units) with 2 AW

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q151. A large company starts to use AWS organizations with consolidated billing feature to manage its separate departments. The AWS operation team has just
Created 3 OUs (organization units) with 2 AWS accounts each. To be compliant with company-wide security policy CloudTrail is required for all AWS accounts which is already been set up. However after some time there are cases that users in certain OU have turned off the CloudTrail of their accounts. What is the best way for the AWS operation team to prevent this from happening again?

A.Update the AWS Organizations feature sets to features?and then create a Service Control Policies (SCP) to Prevent Users from Disabling AWS CloudTrail. This can be achieved by a deny policy with cloudtrail:StopLogging denied.
B.This can be achieved by Service Control Policies (SCP) in features?set. The team needs to delete and recreate the AWS Organizations with features?enabled and then use a proper control policy to limit the operation of cloudtrail:StopLogging.
C.In each AWS account in this organization create an IAM policy to deny cloudtrail:StopLogging for all users including administrators.
D.Use a Service Control Policies (SCP) to prevent users from disabling AWS CloudTrail. This can be done by a allow policy which denies cloudtrail:StopLogging
正确答案A
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top