ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 100 - 312-40 discussion

Report
Export

Allen Smith works as a cloud security engineer in a multinational company. Using an intrusion detection system, the incident response team of this company identified that an attacker has been continuously attacking the organization's AWS services. The team leader asked Allen to track the changes made to AWS resources and perform security analysis. Which AWS service can provide the AWS API call history for AWS accounts, including calls made via the AWS Management Console or Command Line tools, AWS Software Development Kits, and other AWS services to Allen?

A.
Amazon CloudFront
Answers
A.
Amazon CloudFront
B.
AWS CloudFormation
Answers
B.
AWS CloudFormation
C.
Amazon CloudTrail
Answers
C.
Amazon CloudTrail
D.
Amazon CloudWatch
Answers
D.
Amazon CloudWatch
Suggested answer: C

Explanation:

1.Amazon CloudTrail: AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account1.

1.API Call History: It provides an event history of your AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command line tools, and other AWS services1.

1.Security Analysis: The AWS API call history produced by CloudTrail enables security analysis, resource change tracking, and compliance auditing1.

1.Operational Auditing: CloudTrail continuously monitors and logs account activity across all AWS services, including actions taken by a user, role, or AWS service1.

1.Compliance Auditing: CloudTrail logs provide detailed records of all API calls, which can be used to audit compliance with regulatory standards like HIPAA and PCI2.

AWS Security Hub documentation on CloudTrail controls1.

Medium article on exploring AWS CloudTrail2.

asked 18/09/2024
Marc Casin Martinez
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first