After a questionable change in the city's cloud management account, security needs to review who performed which actions last week. Which capability should they rely on?
Select an answer to reveal the explanation.
Short Explanation
When something weird happens in the management account, you want a flight recorder—not a shrug and a hallway rumor. Audit trails show who clicked what and when so security can reconstruct last week. Turning logs off or wiping them weekly leaves the city flying blind.
Full Explanation
Accounting and audit trails for IAM and management actions provide attributable records of who performed which operations and when. Security teams use those logs to investigate suspicious changes in management accounts. Deleting or disabling management logs, or relying solely on verbal recollection, removes forensic evidence and weakens accountability. Cloud+ identity objectives include audit trails as part of access governance.