SCS-C02 exam dumps

SCS-C02 practice question 140 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 140

Select 3

An organization is using AWS CloudTrail to monitor API activity across its accounts. The security team wants to ensure that logs are retained for 7 years for compliance purposes and that they are stored securely. They also want to protect the logs from accidental or intentional deletion. Which combination of actions should the security team take to meet these requirements?

  1. A

    Enable CloudTrail log file validation.

  2. B

    Configure the S3 bucket where logs are stored with a lifecycle policy to transition logs to Amazon S3 Glacier after 90 days.

  3. C

    Use an S3 bucket policy to deny delete actions for everyone, including the root user.

  4. D

    Enable S3 Object Lock with Compliance mode and configure a retention period of 7 years.

  5. E

    Set up an Amazon EventBridge rule to archive logs to Amazon S3 Glacier after 90 days.

Show answer and explanation

Correct answers: A, B, D

Explanation

The combination of enabling CloudTrail log file validation, configuring a lifecycle policy to transition logs to S3 Glacier for cost-effective long-term storage, and using S3 Object Lock in Compliance mode ensures that the logs are securely stored, retained for the required 7 years, and protected against accidental or intentional deletions. These actions collectively meet the organization's security and compliance requirements.

  • A. Correct.

    Correct. Enabling CloudTrail log file validation ensures the integrity of the log files and verifies that they have not been tampered with, which aligns with secure storage requirements.

  • B. Correct.

    Correct. Configuring a lifecycle policy to transition logs to S3 Glacier after 90 days ensures cost-effective long-term storage while meeting compliance retention requirements.

  • C. Incorrect.

    Incorrect. While an S3 bucket policy can control access, it is not sufficient to protect against accidental or intentional deletions by the root user. Instead, S3 Object Lock should be used.

  • D. Correct.

    Correct. Enabling S3 Object Lock in Compliance mode with a retention period of 7 years ensures logs cannot be deleted or altered, meeting the compliance and security requirements.

  • E. Incorrect.

    Incorrect. Using an EventBridge rule to archive logs is unnecessary in this case, as a lifecycle policy is the recommended approach for transitioning objects to S3 Glacier.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam