ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 402 - SCS-C01 discussion

Report
Export

Your company has defined a set of S3 buckets in AWS. They need to monitor the S3 buckets and know the source IP address and the person who make requests to the S3 bucket. How can this be achieved? Please select:

A.
Enable VPC flow logs to know the source IP addresses
Answers
A.
Enable VPC flow logs to know the source IP addresses
B.
Monitor the S3 API calls by using Cloudtrail logging
Answers
B.
Monitor the S3 API calls by using Cloudtrail logging
C.
Monitor the S3 API calls by using Cloudwatch logging
Answers
C.
Monitor the S3 API calls by using Cloudwatch logging
D.
Enable AWS Inspector for the S3 bucket
Answers
D.
Enable AWS Inspector for the S3 bucket
Suggested answer: B

Explanation:

The AWS Documentation mentions the following

Amazon S3 is integrated with AWS CloudTrail. CloudTrail is a service that captures specific API calls made to Amazon S3 from your AWS account and delivers the log files to an Amazon S3 bucket that you specify. It captures API calls made from the Amazon S3 console or from the Amazon S3 API.

Using the information collected by CloudTrail, you can determine what request was made to Amazon S3, the source IP address from which the request was made, who made the request when it was made, and so on Options A,C and D are invalid because these services cannot be used to get the source IP address of the calls to S3 buckets For more information on Cloudtrail logging, please refer to the below Link:

https://docs.aws.amazon.com/AmazonS3/latest/dev/cloudtrail-logeins.htmllThe correct answer is: Monitor the S3 API calls by using Cloudtrail logging Submit yourFeedback/Queries to our Experts

asked 16/09/2024
Corey Workman
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first