Medium1 markMultiple Choice
Domain 1.2: Secure WorkloadsCloudTrailSecurityLogging

AWS SAA-C03 · Question 09 · Domain 1.2: Secure Workloads

A company requires that all AWS API calls are logged. They also need to mathematically prove that the log files have not been tampered with after they were delivered to Amazon S3. How can this be achieved?

Answer options:

A.

Enable S3 Object Lock in compliance mode.

B.

Enable CloudTrail log file integrity validation.

C.

Encrypt the CloudTrail logs using AWS KMS.

D.

Use Amazon Macie to monitor the S3 bucket for changes.

How to approach this question

Look for the specific CloudTrail feature designed for mathematical proof of log integrity.

Full Answer

B.Enable CloudTrail log file integrity validation.✓ Correct
CloudTrail log file integrity validation uses industry-standard algorithms (SHA-256 and RSA) to create a hash for every log file delivered, allowing you to assert that no log files were modified or deleted.

Common mistakes

Choosing S3 Object Lock, which is for immutability but doesn't provide the mathematical proof feature CloudTrail offers natively.

Practice the full AWS SAA-C03 Practice Exam 5

65 questions · hints · full answers · grading

More questions from this exam