A log archive account will receive organization CloudTrail and other logs. The bucket design must allow only approved trails or log writers to put objects and must prevent premature deletion. Which approach best meets those controls?
Select an answer to reveal the explanation.
Short Explanation
The archive is a locked evidence vault, not a shared junk drawer. Only the approved trail delivery roles get a write key, and nobody gets an early shredder — restrictive policies plus retention keep the record intact.
Full Explanation
Central logging accounts typically use dedicated S3 buckets with least-privilege policies that allow organization trails or designated log writers to deliver objects while denying broad delete or overwrite by workload principals. Object Lock or retention-oriented deny statements help meet immutability expectations for audits. Broad delete grants, public write, or per-account tidy-up rights defeat the purpose of a log archive.