ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 208 - SCS-C01 discussion

Report
Export


A company has five AWS accounts and wants to use AWS CloudTrail to log API calls. The log files must be stored in an Amazon S3 bucket that resides in a new account specifically built for centralized services with a unique top-level prefix for each trail. The configuration must also enable detection of any modification to the logs.

Which of the following steps will implement these requirements? (Choose three.)

A.
Create a new S3 bucket in a separate AWS account for centralized storage of CloudTrail logs, and enable “Log File Validation” on all trails.
Answers
A.
Create a new S3 bucket in a separate AWS account for centralized storage of CloudTrail logs, and enable “Log File Validation” on all trails.
B.
Use an existing S3 bucket in one of the accounts, apply a bucket policy to the new centralized S3 bucket that permits the CloudTrail service to use the "s3: PutObject" action and the "s3 GetBucketACL" action, and specify the appropriate resource ARNs for the CloudTrail trails.
Answers
B.
Use an existing S3 bucket in one of the accounts, apply a bucket policy to the new centralized S3 bucket that permits the CloudTrail service to use the "s3: PutObject" action and the "s3 GetBucketACL" action, and specify the appropriate resource ARNs for the CloudTrail trails.
C.
Apply a bucket policy to the new centralized S3 bucket that permits the CloudTrail service to use the "s3 PutObject" action and the "s3 GelBucketACL" action, and specify the appropriate resource ARNs for the CloudTrail trails.
Answers
C.
Apply a bucket policy to the new centralized S3 bucket that permits the CloudTrail service to use the "s3 PutObject" action and the "s3 GelBucketACL" action, and specify the appropriate resource ARNs for the CloudTrail trails.
D.
Use unique log file prefixes for trails in each AWS account.
Answers
D.
Use unique log file prefixes for trails in each AWS account.
E.
Configure CloudTrail in the centralized account to log all accounts to the new centralized S3 bucket.
Answers
E.
Configure CloudTrail in the centralized account to log all accounts to the new centralized S3 bucket.
F.
Enable encryption of the log files by using AWS Key Management Service
Answers
F.
Enable encryption of the log files by using AWS Key Management Service
Suggested answer: A, C, E

Explanation:

https://docs.aws.amazon.com/awscloudtrail/latest/userguide/best-practices-security.htmlIf you have created an organization in AWS Organizations, you can create a trail that will log allevents for all AWS accounts in that organization. This is sometimes referred to as an organizationtrail. You can also choose to edit an existing trail in the master account and apply it to anorganization, making it an organization trail. Organization trails log events for the master account andall member accounts in the organization. For more information about AWS Organizations, seeOrganizations Terminology and Concepts. Note Reference:

https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html Youmust be logged in with the master account for the organization in order to create an organizationtrail. You must also have sufficient permissions for the IAM user or role in the master account inorder to successfully create an organization trail. If you do not have sufficient permissions, you willnot see the option to apply a trail to an organization.

asked 16/09/2024
Rahul Chugh
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first