SCS-C02 · Question #138
A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account. All AWS account activity across all member accounts must be logged and repor
The correct answer is B. In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in D. Create an AWS CloudTrail trail for the organization. Configure logs to be delivered to the logging. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-set-bucket-policy-for- multiple-accounts.html
Question
A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account. All AWS account activity across all member accounts must be logged and reported to the dedicated security account. The company must retain all the activity logs in a secure storage location within the dedicated security account for 2 years. No changes or deletions of the logs are allowed. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)
Options
- AIn the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in
- BIn the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in
- CIn the dedicated security account, create an Amazon S3 bucket that has an S3 Lifecycle
- DCreate an AWS CloudTrail trail for the organization. Configure logs to be delivered to the logging
- ETurn on AWS CloudTrail in each account. Configure logs to be delivered to an Amazon S3 bucket
How the community answered
(38 responses)- A16% (6)
- B76% (29)
- C5% (2)
- E3% (1)
Explanation
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-set-bucket-policy-for- multiple-accounts.html
Topics
Community Discussion
No community discussion yet for this question.