A. Add AWS CloudTrail logging for the S3 buckets.
B. Implement IAM policies to allow only the storage team to create S3 buckets.
C. Add the S3_BUCKET_LOGGING_ENABLED AWS Config managed rule.
D. Create an AWS Lambda function to delete the S3 buckets if logging is not turned on.

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.