A DevOps engineer needs to prevent any IAM user in a member account from disabling AWS CloudTrail logging. Which mechanism enforces this across all accounts in an AWS Organization?
-
A
IAM permission boundaries on all users
-
B
An SCP (Service Control Policy) attached at the root or OU level
-
C
A CloudWatch Events rule that re-enables CloudTrail
-
D
AWS Config auto-remediation with a Lambda function