A city must prove who changed IAM policies last quarter as part of access governance. Which design element supports that accountability without replacing least privilege?
Select an answer to reveal the explanation.
Short Explanation
Least privilege decides what people may do; CloudTrail (and Config) write down what they actually did. You still need tight IAM—logs do not lock the door—but without an audit trail you cannot prove who changed policies last quarter. Turn logging on, not off.
Full Explanation
Accountability for IAM changes depends on management and governance services such as AWS CloudTrail for API history and AWS Config for configuration timelines. Those controls complement—not replace—least-privilege identity design. Disabling logs, broadening AdministratorAccess, or removing authenticated principals undermines both prevention and forensic proof.