AWS SAA-C03 · Question 09 · Domain 1.2: Secure Workloads
A company requires that all AWS API calls are logged. They also need to mathematically prove that the log files have not been tampered with after they were delivered to Amazon S3. How can this be achieved?
Answer options:
Enable S3 Object Lock in compliance mode.
Enable CloudTrail log file integrity validation.
Encrypt the CloudTrail logs using AWS KMS.
Use Amazon Macie to monitor the S3 bucket for changes.
65 questions · hints · full answers · grading