nerdexam
CompTIA

CV0-002 · Question #510

A cloud engineer is required to ensure all servers in the cloud environment meet requirements for PCI compliance. One of the requirements is to make certain all administrator logins and commands are l

The correct answer is A. Enable configuration change tracking for all servers in the public cloud provider's. To meet PCI compliance requiring logging of all administrator logins and commands across cloud servers, enabling configuration change tracking is the most effective method as it provides a centralized and comprehensive audit trail of system changes and administrative actions. Thi

Security

Question

A cloud engineer is required to ensure all servers in the cloud environment meet requirements for PCI compliance. One of the requirements is to make certain all administrator logins and commands are logged. Which of the following is the BEST approach to meet these requirements?

Options

  • AEnable configuration change tracking for all servers in the public cloud provider's
  • BEnable detailed monitoring for all servers in the public cloud provider's dashboard.
  • CDefine and enable audit tracking rules on each server in the public cloud environment.
  • DModify the cloud provider's role-based authorization policies to log user session activity.

How the community answered

(41 responses)
  • A
    83% (34)
  • B
    10% (4)
  • C
    5% (2)
  • D
    2% (1)

Why each option

To meet PCI compliance requiring logging of all administrator logins and commands across cloud servers, enabling configuration change tracking is the most effective method as it provides a centralized and comprehensive audit trail of system changes and administrative actions. This capability helps ensure that all critical activities are recorded, satisfying the compliance mandate.

AEnable configuration change tracking for all servers in the public cloud provider'sCorrect

Configuration change tracking services automatically record changes to server configurations, including OS settings, software installations, and often user activity like logins and command executions, providing a centralized and auditable log that is crucial for PCI compliance without manual configuration on each server.

BEnable detailed monitoring for all servers in the public cloud provider's dashboard.

Detailed monitoring typically refers to performance metrics and basic health checks, not granular logging of administrator logins or commands.

CDefine and enable audit tracking rules on each server in the public cloud environment.

Manually defining and enabling audit rules on each server is an inefficient, error-prone, and non-scalable approach for 'all servers' in a cloud environment compared to a cloud provider's centralized service.

DModify the cloud provider's role-based authorization policies to log user session activity.

Role-based authorization policies control who can do what, not directly logging specific administrator logins or executed commands; logging is a separate feature often integrated with monitoring or change tracking services.

Concept tested: Cloud compliance logging and auditing (PCI DSS, Change Tracking)

Source: https://learn.microsoft.com/en-us/azure/automation/change-tracking-and-inventory/overview

Topics

#PCI Compliance#Audit Logging#Configuration Management#Cloud Security Monitoring

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice