1 Answer
- Newest
- Most votes
- Most comments
1
It doesn't prevent logs from being modified or deleted. You should implement least privilege access and enable MFA delete on the S3 bucket. Please refer to CloudTrail preventative security best practices.
Relevant content
- asked 4 years ago
- AWS OFFICIALUpdated 3 months ago
