DOP-C02 exam dumps

DOP-C02 practice question 188 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 188

Select 3

Your company has a multi-account structure in AWS, and you are tasked with implementing a centralized logging solution to ensure compliance with regulatory requirements. The solution must collect CloudTrail logs from all accounts in the organization and store them securely in a single S3 bucket. Additionally, the logs must be encrypted, and access to the logs must be restricted to a specific IAM role used by the security team. Which combination of steps should you take to meet these requirements?

  1. A

    Enable AWS CloudTrail in each individual account and configure it to deliver logs to a shared S3 bucket in the logging account.

  2. B

    Use AWS Organizations to set up a centralized CloudTrail in the management account and configure it to deliver logs to a shared S3 bucket.

  3. C

    Configure S3 bucket policies to allow access only to the security team's IAM role and the CloudTrail service.

  4. D

    Enable default encryption on the S3 bucket using AWS Key Management Service (KMS) and specify a KMS key for encryption.

  5. E

    Use Amazon Macie to automatically classify and secure the logs stored in the S3 bucket.

Show answer and explanation

Correct answers: A, C, D

Explanation

To implement a centralized logging solution in a multi-account AWS environment, you need to enable CloudTrail in each account and configure it to deliver logs to a shared S3 bucket. To secure the logs, you must encrypt them using AWS KMS and restrict access to only the security team's IAM role and the CloudTrail service via S3 bucket policies. Amazon Macie is not required for this use case as it serves a different purpose. Configuring CloudTrail in individual accounts is the correct approach in this scenario.

  • A. Correct.

    Correct. Enabling CloudTrail in each account and routing logs to a shared S3 bucket ensures that logs are collected from all accounts in the organization. This is a common approach in a multi-account setup.

  • B. Incorrect.

    Incorrect. While centralized CloudTrail configuration is possible, AWS Organizations does not directly provide an option to set up CloudTrail in the management account for all accounts. CloudTrail must be configured explicitly in each account.

  • C. Correct.

    Correct. Restricting access to the S3 bucket by using bucket policies ensures that only the security team and CloudTrail can access the logs, meeting compliance and security requirements.

  • D. Correct.

    Correct. Enabling encryption with KMS ensures that the logs are securely stored in the S3 bucket, which is essential for regulatory compliance and data protection.

  • E. Incorrect.

    Incorrect. Amazon Macie is used for sensitive data discovery and classification, not for configuring or securing CloudTrail logs. It is not required to meet the given requirements.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam