A company's organization CloudTrail trail must deliver logs from every member account to one S3 bucket. Engineers who administer GuardDuty and Security Hub CSPM for the organization must not be able to alter delivered logs, and the bucket must not sit in an account that runs workloads. Following the AWS reference multi-account layout, where should the bucket be created?
Choose one.
The reference layout separates evidence (the log-archive account) from security tooling (the audit account); neither runs workloads.
The log-archive account is the purpose-built destination for organization CloudTrail logs: it runs no workloads and is separate from the audit account, so the people who administer the security services do not administer the evidence. The audit account is the tempting near-twin, but that is exactly where the security-service administrators work. The management account and a shared-services account both fail the isolation requirement.
- Separate the two Security OU accounts by purpose: evidence storage versus security tooling.
- Match the stem constraint that the tooling administrators must not alter the logs.
- Rule out accounts that run workloads or hold the organization’s highest privileges.
Exam tip: Organization logs go to the log-archive account; security tooling goes to the audit account.
AWS Organizations, SCPs, and Control Tower: Multi-Account Security Strategy — the lesson that teaches this.