ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 87 - SCS-C02 discussion

Report
Export

A company plans to create individual child accounts within an existing organization in IAM Organizations for each of its DevOps teams. IAM CloudTrail has been enabled and configured on all accounts to write audit logs to an Amazon S3 bucket in a centralized IAM account. A security engineer needs to ensure that DevOps team members are unable to modify or disable this configuration.

How can the security engineer meet these requirements?

A.
Create an IAM policy that prohibits changes to the specific CloudTrail trail and apply the policy to the IAM account root user.
Answers
A.
Create an IAM policy that prohibits changes to the specific CloudTrail trail and apply the policy to the IAM account root user.
B.
Create an S3 bucket policy in the specified destination account for the CloudTrail trail that prohibits configuration changes from the IAM account root user in the source account.
Answers
B.
Create an S3 bucket policy in the specified destination account for the CloudTrail trail that prohibits configuration changes from the IAM account root user in the source account.
C.
Create an SCP that prohibits changes to the specific CloudTrail trail and apply the SCP to the appropriate organizational unit or account in Organizations.
Answers
C.
Create an SCP that prohibits changes to the specific CloudTrail trail and apply the SCP to the appropriate organizational unit or account in Organizations.
D.
Create an IAM policy that prohibits changes to the specific CloudTrail trail and apply the policy to a new IAM group. Have team members use individual IAM accounts that are members of the new IAM group.
Answers
D.
Create an IAM policy that prohibits changes to the specific CloudTrail trail and apply the policy to a new IAM group. Have team members use individual IAM accounts that are members of the new IAM group.
Suggested answer: D
asked 16/09/2024
Maheshkumar Karuppaiah
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first