ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 314 - SCS-C01 discussion

Report
Export

You need to ensure that the cloudtrail logs which are being delivered in your AWS account is encrypted. How can this be achieved in the easiest way possible? Please select:

A.
Don't do anything since CloudTrail logs are automatically encrypted.
Answers
A.
Don't do anything since CloudTrail logs are automatically encrypted.
B.
Enable S3-SSE for the underlying bucket which receives the log files
Answers
B.
Enable S3-SSE for the underlying bucket which receives the log files
C.
Enable S3-KMS for the underlying bucket which receives the log files
Answers
C.
Enable S3-KMS for the underlying bucket which receives the log files
D.
Enable KMS encryption for the logs which are sent to Cloudwatch
Answers
D.
Enable KMS encryption for the logs which are sent to Cloudwatch
Suggested answer: A

Explanation:

The AWS Documentation mentions the following

By default the log files delivered by CloudTrail to your bucket are encrypted by Amazon server-side encryption with Amazon S3-managed encryption keys (SSE-S3) Option B,C and D are all invalid because by default all logs are encrypted when they sent by Cloudtrail to S3 buckets For more information on AWS Cloudtrail log encryption, please visit the following URL:

https://docs.aws.amazon.com/awscloudtrail/latest/usereuide/encryptine-cloudtrail-loe-files-withaws-kms.htmllThe correct answer is: Don't do anything since CloudTrail logs are automatically encrypted. Submityour Feedback/Queries to our Experts

asked 16/09/2024
ozgur yilmaz
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first