Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam SOA-C01 All Questions
Exam SOA-C01 All Questions

View all questions & answers for the SOA-C01 exam

Amazon Web Services AWS Certified Associate SOA-C01 Question # 71 Topic 8 Discussion

SOA-C01 Exam Topic 8 Question 71 Discussion:
Question #: 71
Topic #: 8

A company monitors its account activity using AWS CloudTrail, and is concerned that some log files are being tampered with after the logs have been delivered to the account’s Amazon S3 bucket.

Moving forward, how can the SysOps Administrator confirm that the log files have not been modified after being delivered to the S3 bucket.


A.

Stream the CloudTrail logs to Amazon CloudWatch to store logs at a secondary location.


B.

Enable log file integrity validation and use digest files to verify the hash value of the log file.


C.

Replicate the S3 log bucket across regions, and encrypt log files with S3 managed keys.


D.

Enable S3 server access logging to track requests made to the log bucket for security audits.


Get Premium SOA-C01 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.