What should the security team do to obtain this information?

2 Comments

  1. Alexis
    Author

    I sort that the answer is:
    Use Detective to find the details of the CloudTrailLoggingDisabled event from GuardDuty, including the user name and all activity that occurred when CloudTrail was disabled.

  2. Lucas
    Author

    I surmise that the answer is:
    Use Detective to find the details of the CloudTrailLoggingDisabled event from GuardDuty, including the user name and all activity that occurred when CloudTrail was disabled.

Leave a Reply

Your email address will not be published. Required fields are marked *

4 × 5 =