Ultimate access to all questions.
A company operates multiple AWS accounts within an AWS Organizations setup, including a dedicated security account. The company requires that all AWS account activities across these member accounts be logged and reported to the dedicated security account. Additionally, these logs must be securely stored within the dedicated security account for a retention period of 2 years, with no possibility of changes or deletions. Which two steps, when taken together, would meet these requirements with the least operational overhead?