Exit 35 / 40

Question 35

Domain 6: Management and Security Governance

A security architect at a large enterprise wants to ensure that even if an account's root user credentials are compromised, the attacker cannot create new IAM users or disable CloudTrail in any member account. The accounts already have CloudTrail trails defined by the management account. Which control most directly enforces this guardrail?