nerdexam
Amazon

SOA-C02 · Question #357

A company runs an application that hosts critical data for several clients. The company uses AWS CloudTrail to track user activities on various AWS resources. To meet new security requirements, the co

Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #357. The question stem and answer options stay visible for context.

Submitted by cyberguy42· Mar 30, 2026Security and Compliance

Question

A company runs an application that hosts critical data for several clients. The company uses AWS CloudTrail to track user activities on various AWS resources. To meet new security requirements, the company needs to protect the CloudTrail log files from being modified, deleted, or forged. Which solution will meet these requirement?

Options

  • AEnable CloudTrail log file integrity validation.
  • BUse Amazon S3 MFA Delete on the S3 bucket where the CloudTrail log files are stored.
  • CUse Amazon S3 Versioning to keep all versions of the CloudTrail log files.
  • DUse AWS Key Management Service (AWS KMS) security keys to secure the CloudTrail log files.

Unlock SOA-C02 to see the answer

You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CloudTrail#log integrity validation#log tampering prevention#audit security
Full SOA-C02 Practice