CV0-002 · Question #510
A cloud engineer is required to ensure all servers in the cloud environment meet requirements for PCI compliance. One of the requirements is to make certain all administrator logins and commands are l
The correct answer is A. Enable configuration change tracking for all servers in the public cloud provider's. To meet PCI compliance requiring logging of all administrator logins and commands across cloud servers, enabling configuration change tracking is the most effective method as it provides a centralized and comprehensive audit trail of system changes and administrative actions. Thi
Question
A cloud engineer is required to ensure all servers in the cloud environment meet requirements for PCI compliance. One of the requirements is to make certain all administrator logins and commands are logged. Which of the following is the BEST approach to meet these requirements?
Options
- AEnable configuration change tracking for all servers in the public cloud provider's
- BEnable detailed monitoring for all servers in the public cloud provider's dashboard.
- CDefine and enable audit tracking rules on each server in the public cloud environment.
- DModify the cloud provider's role-based authorization policies to log user session activity.
How the community answered
(41 responses)- A83% (34)
- B10% (4)
- C5% (2)
- D2% (1)
Why each option
To meet PCI compliance requiring logging of all administrator logins and commands across cloud servers, enabling configuration change tracking is the most effective method as it provides a centralized and comprehensive audit trail of system changes and administrative actions. This capability helps ensure that all critical activities are recorded, satisfying the compliance mandate.
Configuration change tracking services automatically record changes to server configurations, including OS settings, software installations, and often user activity like logins and command executions, providing a centralized and auditable log that is crucial for PCI compliance without manual configuration on each server.
Detailed monitoring typically refers to performance metrics and basic health checks, not granular logging of administrator logins or commands.
Manually defining and enabling audit rules on each server is an inefficient, error-prone, and non-scalable approach for 'all servers' in a cloud environment compared to a cloud provider's centralized service.
Role-based authorization policies control who can do what, not directly logging specific administrator logins or executed commands; logging is a separate feature often integrated with monitoring or change tracking services.
Concept tested: Cloud compliance logging and auditing (PCI DSS, Change Tracking)
Source: https://learn.microsoft.com/en-us/azure/automation/change-tracking-and-inventory/overview
Topics
Community Discussion
No community discussion yet for this question.