A company wants to enable AWS CloudTrail to log all API calls across multiple accounts in AWS Organizations. The security team requires that logs be encrypted at rest and that any unauthorized deletion of log files be prevented. Which TWO actions should the security team take? (Choose TWO.)
By creating an organization trail in the management account (using AWS Organizations), CloudTrail automatically logs API activity for all member accounts, including the management account itself, without needing to configure trails in each account. This centralizes governance and ensures the requirement of logging all API calls across the entire AWS environment is met, as organization trails deliver log files for every account to a single S3 bucket.
Why this answer
Enabling CloudTrail for all accounts in the organization ensures centralized logging. Option D is correct because S3 Object Lock prevents deletion of log files. Option B is incorrect because KMS with a customer managed key provides encryption, but the key must be created beforehand, not just enabled.
Option C is incorrect because CloudWatch Logs encryption uses KMS, not S3 SSE. Option E is incorrect because CloudTrail can be configured to log management events by default, and this is not about data events.