Use an AWS Config managed rule with the AWS-EnableCloudTrail remediation to auto re-enable logging

Evaluate the compliance of AWS resources. Troubleshoot logging solutions.
Answer Correct answer: A — an AWS Config managed rule with the AWS-EnableCloudTrail remediation automatically re-enables CloudTrail across Regions.

A security engineer needs to build a solution to turn AWS CloudTrail back on in multiple AWS Regions in case it is ever turned off. What is the MOST efficient way to implement this solution?

  1. Use AWS Config with a managed rule to initiate the AWS-EnableCloudTrail remediation. Correct Answer
  2. Create an Amazon EventBridge event with a cloudtrail.amazonaws.com event source and a StartLogging event name to invoke an AWS Lambda function to call the StartLogging
  3. Create an Amazon CloudWatch alarm with a cloudtrail.amazonaws.com event source and a StopLoggmg event name to invoke an AWS Lambda function to call the StartLogging API.
  4. Monitor AWS Trusted Advisor to ensure CloudTrail logging is enabled.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS Config's managed rule plus the AWS-EnableCloudTrail remediation runs StartLogging automatically whenever a trail is detected off, across Regions, with no custom code. EventBridge (B) and CloudWatch alarms (C) can invoke Lambda but require you to build and maintain that Lambda; Trusted Advisor (D) only advises, it does not remediate. A is most efficient.

To automatically turn CloudTrail back on across multiple Regions if it is disabled, use AWS Config with a managed rule that detects trails being off and a remediation (AWS-EnableCloudTrail) that calls StartLogging. Config is regional and centrally aggregatable, so it is the most efficient, managed, no-code way to enforce logging org-wide.

Building EventBridge/CloudWatch alarm + Lambda (B/C)—works but is custom code you must write and maintain, less efficient than the built-in Config remediation. Relying on Trusted Advisor (D)—it reports but does not automatically re-enable CloudTrail.

Community Discussion (5 comments)

Certified101 👍 6 Selected: A
https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automatically-re-enable-aws-cloudtrail-by-using-a-custom-remediation-rule-in-aws-config.html
PegasusForever 👍 1 Selected: C
AWS-EnableCloudTrail -> Create an AWS CloudTrail trail and configure logging to an S3 bucket not re-enabled for that we require an AWS Config Custom Rule, not listed. MOST Efficient C. Create an Amazon CloudWatch alarm with a cloudtrail.amazonaws.com event source and a StopLoggmg event name to invoke an AWS Lambda function to call the StartLogging API. B is wrong.
xTrayusx 👍 1 Selected: A
To efficiently turn AWS CloudTrail back on in multiple AWS Regions if it is ever turned off, the best approach is to use AWS Config with a managed rule to automatically remediate the situation.
navid1365 👍 1 Selected: A
The "most efficient" solution is A.
Certified101 👍 2 Selected: A
The correct answer is A. The most efficient way to implement this solution is to use AWS Config with a managed rule to initiate the AWS-EnableCloudTrail remediation. This will automatically turn AWS CloudTrail back on if it is ever turned off.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Config can evaluate whether CloudTrail is enabled in each Region and, via the managed remediation AWS-EnableCloudTrail, automatically call StartLogging to turn it back on. Because Config is regional and supports delegation/aggregation, this enforces logging across many Regions with no custom code—the most efficient approach.

Why the Other Options Are Wrong

B and C require you to build and maintain a Lambda function triggered by EventBridge or a CloudWatch alarm, which is more effort than the native Config remediation. D (Trusted Advisor) only surfaces the issue; it does not remediate. A is the built-in, lowest-effort solution.

Community Comment Notes

Community voted A (100). Commenters linked the AWS Prescriptive Guidance pattern for auto re-enabling CloudTrail via a Config (custom) remediation rule and called A the 'most efficient' solution. A confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide