SCS-C02 · Question #337
You currently operate a web application In the AWS US-East region. The application runs on an auto- scaled layer of EC2 instances and an RDS Multi-AZ database. Your IT security compliance officer has
The correct answer is A. Create a new CloudTrail trail with one new S3 bucket to store the logs and with the global. AWS Identity and Access Management (IAM) is integrated with AWS CloudTrail, a service that logs AWS events made by or on behalf of your AWS account. CloudTrail logs authenticated AWS API calls and also AWS sign-in events, and collects this event information in files that are deli
Question
You currently operate a web application In the AWS US-East region. The application runs on an auto- scaled layer of EC2 instances and an RDS Multi-AZ database. Your IT security compliance officer has tasked you to develop a reliable and durable logging solution to track changes made to your EC2.IAM and RDS resources. The solution must ensure the integrity and confidentiality of your log data. Which of these solutions would you recommend?
Options
- ACreate a new CloudTrail trail with one new S3 bucket to store the logs and with the global
- BCreate a new CloudTrail with one new S3 bucket to store the logs. Configure SNS to send log file
- CCreate a new CloudTrail trail with an existing S3 bucket to store the logs and with the global
- DCreate three new CloudTrail trails with three new S3 buckets to store the logs one for the AWS
How the community answered
(49 responses)- A76% (37)
- B4% (2)
- C6% (3)
- D14% (7)
Explanation
AWS Identity and Access Management (IAM) is integrated with AWS CloudTrail, a service that logs AWS events made by or on behalf of your AWS account. CloudTrail logs authenticated AWS API calls and also AWS sign-in events, and collects this event information in files that are delivered to Amazon S3 buckets. You need to ensure that all services are included. Hence option B is partially correct. Option B is invalid because you need to ensure that global services is select Option C is invalid because you should use bucket policies Option D is invalid because you should ideally just create one S3
Topics
Community Discussion
No community discussion yet for this question.