ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 255 - SCS-C01 discussion

Report
Export

Your company has mandated that all calls to the AWS KMS service be recorded. How can this be achieved? Please select:

A.
Enable logging on the KMS service
Answers
A.
Enable logging on the KMS service
B.
Enable a trail in Cloudtrail
Answers
B.
Enable a trail in Cloudtrail
C.
Enable Cloudwatch logs
Answers
C.
Enable Cloudwatch logs
D.
Use Cloudwatch metrics
Answers
D.
Use Cloudwatch metrics
Suggested answer: B

Explanation:

The AWS Documentation states the following

AWS KMS is integrated with CloudTrail, a service that captures API calls made by or on behalf of AWS KMS in your AWS account and delivers the log files to an Amazon S3 bucket that you specify. CloudTrail captures API calls from the AWS KMS console or from the AWS KMS API. Using the information collected by CloudTrail, you can determine what request was made, the source IP address from which the request was made, who made the request when it was made, and so on.

Option A is invalid because logging is not possible in the KMS service Option C and D are invalid because Cloudwatch cannot be used to monitor API calls For more information on logging using Cloudtrail please visit the below URL https://docs.aws.amazon.com/kms/latest/developerguide/loeeing-usine-cloudtrail.htmlThe correct answer is: Enable a trail in CloudtrailJubmit your Feedback/Queries to our Experts

asked 16/09/2024
AHOPlvaro Zorrilla
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first