A company uses AWS CodePipeline to deploy a critical application. The pipeline has a manual approval step before deployment. Which TWO actions should be taken to improve security and auditability? (Choose two.)
Enabling AWS CloudTrail records the PutApprovalResult API calls made through CodePipeline when an approver clicks Approve or Reject. CloudTrail logs the IAM principal or federated user identity, the timestamp, the source IP address, and the decision, providing an immutable audit trail that satisfies compliance and forensic needs. This is the correct answer because the company's explicit requirement is to know who approved the deployment and when.
Why this answer
Enabling AWS CloudTrail to log all approval actions provides a detailed, immutable audit trail of who approved or rejected a pipeline stage, when it happened, and from which IP address. This is essential for compliance and forensic analysis, as CloudTrail captures the `Approval` API calls made by CodePipeline, including the `approve` and `reject` actions, along with the IAM user or role identity. Without CloudTrail, there is no native logging of manual approval events, making it impossible to prove accountability.
Exam trap
The trap here is that candidates often think automated approvals (Option D) are always more secure, but the question specifically asks for improving security and auditability of a manual approval step, and removing human oversight actually reduces security for critical deployments.