SCS-C02 · Question #466
A security engineer is implementing a logging solution for a company's AWS environment. The security engineer has configured an AWS CloudTrail trail in the company's AWS account. The logs are stored i
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #466. The question stem and answer options stay visible for context.
Question
A security engineer is implementing a logging solution for a company's AWS environment. The security engineer has configured an AWS CloudTrail trail in the company's AWS account. The logs are stored in an Amazon S3 bucket for a third-party service provider to monitor. The service provider has a designated IAM role to access the S3 bucket. The company requires all logs to be encrypted at rest with a customer managed key. The security engineer uses AWS Key Management Service (AWS KMS) to create the customer managed key and key policy. The security engineer also configures CloudTrail to use the key to encrypt the trail. When the security engineer implements this configuration, the service provider no longer can read the logs. What should the security engineer do to allow the service provider to read the logs?
Options
- AEnsure that the S3 bucket policy allows access to the service provider's role to decrypt objects.
- BAdd a statement to the key policy to allow the service provider's role the kms:Decrypt action for
- CAdd the AWSKeyManagementServicePowerUser AWS managed policy to the service provider's
- DMigrate the key to AWS Certificate Manager (ACM) to create a shared endpoint for access to the
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.