ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 263 - SCS-C01 discussion

Report
Export

You have enabled Cloudtrail logs for your company's AWS account. In addition, the IT Security department has mentioned that the logs need to be encrypted. How can this be achieved? Please select:

A.
Enable SSL certificates for the Cloudtrail logs
Answers
A.
Enable SSL certificates for the Cloudtrail logs
B.
There is no need to do anything since the logs will already be encrypted
Answers
B.
There is no need to do anything since the logs will already be encrypted
C.
Enable Server side encryption for the trail
Answers
C.
Enable Server side encryption for the trail
D.
Enable Server side encryption for the destination S3 bucket
Answers
D.
Enable Server side encryption for the destination S3 bucket
Suggested answer: B

Explanation:

The AWS Documentation mentions the following.

By default CloudTrail event log files are encrypted using Amazon S3 server-side encryption (SSE). You can also choose to encryption your log files with an AWS Key Management Service (AWS KMS) key. You can store your log files in your bucket for as long as you want. You can also define Amazon S3 lifecycle rules to archive or delete log files automatically. If you want notifications about lo file delivery and validation, you can set up Amazon SNS notifications.

Option A.C and D are not valid since logs will already be encrypted

For more information on how Cloudtrail works, please visit the following URL:

https://docs.aws.amazon.com/awscloudtrail/latest/usereuide/how-cloudtrail-works.htmllThe correct answer is: There is no need to do anything since the logs will already be encryptedSubmit your Feedback/Queries to our Experts

asked 16/09/2024
Jose Rodrigues
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first