List of questions
Related questions
Question 90 - DEA-C01 discussion
A company stores its processed data in an S3 bucket. The company has a strict data access policy. The company uses IAM roles to grant teams within the company different levels of access to the S3 bucket.
The company wants to receive notifications when a user violates the data access policy. Each notification must include the username of the user who violated the policy.
Which solution will meet these requirements?
Use AWS Config rules to detect violations of the data access policy. Set up compliance alarms.
Use Amazon CloudWatch metrics to gather object-level metrics. Set up CloudWatch alarms.
Use AWS CloudTrail to track object-level events for the S3 bucket. Forward events to Amazon CloudWatch to set up CloudWatch alarms.
Use Amazon S3 server access logs to monitor access to the bucket. Forward the access logs to an Amazon CloudWatch log group. Use metric filters on the log group to set up CloudWatch alarms.
0 comments
Leave a comment first