passdrill
AWS SAA-C03 · IAM & Security · Card 005/014 medium

A company manages many AWS accounts under AWS Organizations. The security team wants one guardrail, applied at the organizational unit level, that prevents every IAM principal in every member account under that OU from ever disabling AWS CloudTrail — even a principal that has full administrator permissions from a local identity-based policy. Which control should they use?

  1. An IAM permissions boundary applied individually to every administrator role in every member account
  2. A service control policy attached to the OU that explicitly denies the CloudTrail-disabling actions for every principal in every account under it
  3. A resource-based policy attached directly to the CloudTrail trail
  4. An IAM group in the organization's management account that contains all administrators
Next card → Shuffle