All CloudTrail management events from every municipal AWS account must be delivered to an immutable logging-account bucket that member accounts cannot alter. Which auditing strategy best meets this requirement?
Select an answer to reveal the explanation.
Short Explanation
Central logging is the black box in a locked hangar—every plane writes there, nobody in the fleet can erase the tape. Organization CloudTrail into a hardened logging-account bucket is that hangar. Per-account editable buckets invite silent gaps.
Full Explanation
Organization-level CloudTrail delivers management (and optionally data) events from all member accounts to a central S3 bucket typically owned by a Log Archive or security account. Bucket policies, SCP constraints, encryption, and optional S3 Object Lock support immutability and non-repudiation for auditors. Local-only editable trails, disabled logging, or mailbox storage fail centralized immutable audit requirements.