ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 44 - SCS-C02 discussion

Report
Export

An organization wants to log all IAM API calls made within all of its IAM accounts, and must have a central place to analyze these logs. What steps should be taken to meet these requirements in the MOST secure manner? (Select TWO)

A.
Turn on IAM CloudTrail in each IAM account
Answers
A.
Turn on IAM CloudTrail in each IAM account
B.
Turn on CloudTrail in only the account that will be storing the logs
Answers
B.
Turn on CloudTrail in only the account that will be storing the logs
C.
Update the bucket ACL of the bucket in the account that will be storing the logs so that other accounts can log to it
Answers
C.
Update the bucket ACL of the bucket in the account that will be storing the logs so that other accounts can log to it
D.
Create a service-based role for CloudTrail and associate it with CloudTrail in each account
Answers
D.
Create a service-based role for CloudTrail and associate it with CloudTrail in each account
E.
Update the bucket policy of the bucket in the account that will be storing the logs so that other accounts can log to it
Answers
E.
Update the bucket policy of the bucket in the account that will be storing the logs so that other accounts can log to it
Suggested answer: A, E

Explanation:

these are the steps that can meet the requirements in the most secure manner. CloudTrail is a service that records AWS API calls and delivers log files to an S3 bucket. Turning on CloudTrail in each IAM account can help capture all IAM API calls made within those accounts. Updating the bucket policy of the bucket in the account that will be storing the logs can help grant other accounts permission to write log files to that bucket. The other options are either unnecessary or insecure for logging and analyzing IAM API calls.

asked 16/09/2024
Gabriel Pereira Dias
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first