A company wants to prevent users in their AWS account from disabling AWS CloudTrail. Which is the MOST effective way to enforce this?
-
A
Send CloudTrail logs to a separate S3 bucket with a bucket policy
-
B
Apply a Service Control Policy (SCP) that denies cloudtrail:DeleteTrail
-
C
Enable MFA Delete on the CloudTrail S3 bucket
-
D
Use AWS Config to monitor CloudTrail status