AWS Certified DevOps Engineer – Professional — Question 127

The security team depends on AWS CloudTrail to detect sensitive security issues in the company's AWS account The DevOps engineer needs a solution to auto-remediate CloudTrail being turned off in an AWS account.

What solution ensures the LEAST amount of downtime for the CloudTrail log deliveries?

Answer options

Correct answer: A

Explanation

Option A is the most efficient as it immediately responds to the StopLogging event, ensuring minimal downtime by directly invoking StartLogging when logging is turned off. Option B introduces a delay due to the hourly checks, while Option C's 5-minute schedule may still result in a gap in logging. Option D is less efficient since it requires an EC2 instance and a script, introducing unnecessary complexity and potential latency.