ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 97 - SCS-C02 discussion

Report
Export

A security engineer needs to build a solution to turn IAM CloudTrail back on in multiple IAM Regions in case it is ever turned off.

What is the MOST efficient way to implement this solution?

A.
Use IAM Config with a managed rule to trigger the IAM-EnableCloudTrail remediation.
Answers
A.
Use IAM Config with a managed rule to trigger the IAM-EnableCloudTrail remediation.
B.
Create an Amazon EventBridge (Amazon CloudWatch Events) event with a cloudtrail.amazonIAM.com event source and a StartLogging event name to trigger an IAM Lambda function to call the StartLogging API.
Answers
B.
Create an Amazon EventBridge (Amazon CloudWatch Events) event with a cloudtrail.amazonIAM.com event source and a StartLogging event name to trigger an IAM Lambda function to call the StartLogging API.
C.
Create an Amazon CloudWatch alarm with a cloudtrail.amazonIAM.com event source and a StopLogging event name to trigger an IAM Lambda function to call the StartLogging API.
Answers
C.
Create an Amazon CloudWatch alarm with a cloudtrail.amazonIAM.com event source and a StopLogging event name to trigger an IAM Lambda function to call the StartLogging API.
D.
Monitor IAM Trusted Advisor to ensure CloudTrail logging is enabled.
Answers
D.
Monitor IAM Trusted Advisor to ensure CloudTrail logging is enabled.
Suggested answer: B
asked 16/09/2024
Tobias Wartenweiler
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first