A security team has received an alert from Amazon GuardDuty that AWS CloudTrail logging has been disabled. The security team’s account has AWS Config, Amazon Inspector, Amazon Detective, and AWS Security Hub enabled. The security team wants to identify who disabled CloudTrail and what actions were performed while CloudTrail was disabled.
What should the security team do to obtain this information?
Phongsanth
Highly Voted 2 years, 4 months agoAzureDP900
2 years, 2 months agoSinghh
Highly Voted 2 years, 5 months agoTeknoklutz
2 years, 4 months agoAgboolaKun
1 year, 5 months agosam15
Most Recent 2 years, 2 months agocherry23
1 year, 10 months agoTeknoklutz
2 years, 4 months agomaddyr
2 years, 4 months ago