nerdexam
Amazon

SCS-C02 · Question #389

An auditor needs access to logs that record all API events on AWS. The auditor only needs read- only access to the log files and does not need access to each AWS account. The company has multiple…

The correct answer is D. Configure the CloudTrail service in each AWS account and have the logs delivered to a single. Given the current requirements, assume the method of "least privilege" security design and only allow the auditor access to the minimum amount of AWS resources as possibli AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing…

Submitted by haruto_sh· Mar 6, 2026Security Logging and Monitoring

Question

An auditor needs access to logs that record all API events on AWS. The auditor only needs read- only access to the log files and does not need access to each AWS account. The company has multiple AWS accounts, and the auditor needs access to all the logs for all the accounts. What is the best way to configure access for the auditor to view event logs from all accounts? Choose the correct answer from the options below

Options

  • AConfigure the CloudTrail service in each AWS account, and have the logs delivered to an AWS
  • BConfigure the CloudTrail service in the primary AWS account and configure consolidated billing
  • CConfigure the CloudTrail service in each AWS account and enable consolidated logging inside of
  • DConfigure the CloudTrail service in each AWS account and have the logs delivered to a single

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    10% (2)
  • D
    80% (16)

Explanation

Given the current requirements, assume the method of "least privilege" security design and only allow the auditor access to the minimum amount of AWS resources as possibli AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With CloudTrail, you can log, continuously monitor, and retain events related to API calls across your AWS infrastructure. CloudTrail provides a history of AWS API calls for your account including API calls made through the AWS Management Console, AWS SDKs, command line tools, and other AWS services. This history simplifies security analysis, resource change tracking, and troubleshooting only be granted access in one location Option Option A is incorrect since the auditor should B is incorrect since consolidated billing is not a key requirement as part of the question Option C is incorrect since there is not consolidated logging

Topics

#CloudTrail#multi-account logging#centralized logging#audit logs

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice