AWS SAA-C03 · Question 13 · Domain 1.2: Secure Workloads
A company uses AWS CloudTrail to log all API activity in its AWS account. The security team needs to ensure that the CloudTrail log files have not been tampered with after they are delivered to Amazon S3. How can this be achieved?
Answer options:
Enable Amazon S3 Object Lock on the destination bucket.
Enable CloudTrail log file integrity validation.
Encrypt the CloudTrail logs using AWS KMS.
Use Amazon Macie to monitor the S3 bucket for unauthorized changes.
65 questions · hints · full answers · grading