ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 84 - SCS-C02 discussion

Report
Export

A company manages multiple IAM accounts using IAM Organizations. The company's security team notices that some member accounts are not sending IAM CloudTrail logs to a centralized Amazon S3 logging bucket. The security team wants to ensure there is at least one trail configured (or all existing accounts and for any account that is created in the future.

Which set of actions should the security team implement to accomplish this?

A.
Create a new trail and configure it to send CloudTrail logs to Amazon S3. Use Amazon EventBridge (Amazon CloudWatch Events) to send notification if a trail is deleted or stopped.
Answers
A.
Create a new trail and configure it to send CloudTrail logs to Amazon S3. Use Amazon EventBridge (Amazon CloudWatch Events) to send notification if a trail is deleted or stopped.
B.
Deploy an IAM Lambda function in every account to check if there is an existing trail and create a new trail, if needed.
Answers
B.
Deploy an IAM Lambda function in every account to check if there is an existing trail and create a new trail, if needed.
C.
Edit the existing trail in the Organizations master account and apply it to the organization.
Answers
C.
Edit the existing trail in the Organizations master account and apply it to the organization.
D.
Create an SCP to deny the cloudtrail:Delete' and cloudtrail:Stop' actions. Apply the SCP to all accounts.
Answers
D.
Create an SCP to deny the cloudtrail:Delete' and cloudtrail:Stop' actions. Apply the SCP to all accounts.
Suggested answer: C

Explanation:

Users in member accounts will not have sufficient permissions to delete the organization trail, turn logging on or off, change what types of events are logged, or otherwise alter the organization trail in any way. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html

asked 16/09/2024
Reginald Curtis Jr
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first