Answered step by step
Verified Expert Solution
Question
1 Approved Answer
A technology company has multiple production accounts grouped into a production organizational unit ( OU ) in AWS Organizations. The company wants to prevent all
A technology company has multiple production accounts grouped into a production organizational unit OU in AWS Organizations. The company wants to prevent all AWS Identity and Access Management IAM users in the production accounts from deleting AWS CloudTrail logs How can a system administrator enforce this restriction? Create a tag policy and attach it to the production accounts. Create an IAM policy and attach it to each IAM user in the production accounts. Create a service control policy SCP and attach it to the production OU Create an Amazon S bucket policy and associate with all buckets containing AWS CloudTrail logs
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started