SCS-C02 exam dumps

SCS-C02 practice question 123 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 123

Select 3

Your organization requires centralized logging for all AWS accounts in a multi-account setup managed through AWS Organizations. Security compliance mandates that all CloudTrail logs and Config logs be aggregated into a central S3 bucket in the logging account, and logs must be protected against accidental or malicious deletion. Which combination of steps should you take to design and implement this logging solution?

  1. A

    Configure CloudTrail in each member account to deliver logs to an S3 bucket in the logging account and enable multi-region trails.

  2. B

    Enable Amazon S3 Object Lock on the central logging bucket to enforce a write-once-read-many (WORM) model.

  3. C

    Set up a cross-account IAM role in the logging account and grant S3 bucket write permissions to all member accounts.

  4. D

    Configure AWS Config in each member account to deliver configuration snapshots and compliance data to the central S3 bucket.

  5. E

    Create an S3 bucket policy that explicitly denies DeleteObject actions for all users, including the root user.

Show answer and explanation

Correct answers: A, B, D

Explanation

To design a centralized logging solution for a multi-account AWS environment, you must configure both CloudTrail and AWS Config to send logs to a central bucket in the logging account. To meet compliance requirements for log immutability, S3 Object Lock should be enabled on the central bucket. Other options, such as cross-account IAM roles or bucket policies, do not address all aspects of this scenario effectively.

  • A. Correct.

    Correct. CloudTrail logs must be delivered to the central S3 bucket from all member accounts. Enabling multi-region trails ensures comprehensive logging across all AWS regions.

  • B. Correct.

    Correct. Enabling S3 Object Lock on the central bucket ensures the logs are immutable and cannot be deleted or altered during the retention period.

  • C. Incorrect.

    Incorrect. While cross-account IAM roles can facilitate access, this step is not necessary for configuring CloudTrail and AWS Config to deliver logs to the logging account’s S3 bucket.

  • D. Correct.

    Correct. AWS Config needs to be enabled in each member account to deliver configuration snapshots and compliance data to the central S3 bucket.

  • E. Incorrect.

    Incorrect. An S3 bucket policy can prevent deletions but cannot override the root user’s permissions. S3 Object Lock is the proper mechanism to protect against accidental or malicious deletions.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam