QuestionQ27

Incident Response

A security engineer must create a solution that turns AWS CloudTrail back on across multiple AWS Regions if it is ever disabled.

What is the MOST efficient way to implement this solution?

Explanation

The AWS Config managed rule cloudtrail-enabled identifies an account as noncompliant when an AWS CloudTrail trail is not enabled. AWS Config supports automatic remediation actions for noncompliant managed rules, allowing the AWS-managed AWS-EnableCloudTrail Automation runbook to restore CloudTrail logging without custom Lambda or event-processing code.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!