SCS-C02 exam dumps

SCS-C02 practice question 159 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 159

Select 2

An organization is setting up centralized logging for all AWS accounts in its environment. An S3 bucket in the logging account is designated to store logs from services like AWS CloudTrail, AWS Config, and Amazon VPC Flow Logs. What permissions must be granted to ensure that logs from other AWS accounts can be delivered to the S3 bucket in the logging account?

  1. A

    Grant the logging services 's3:PutObject' permission on the S3 bucket policy in the logging account.

  2. B

    Add a Bucket ACL in the logging account's S3 bucket that grants 'FULL_CONTROL' to the source accounts.

  3. C

    Enable cross-account access by adding the source AWS accounts' AWS principals to the S3 bucket policy.

  4. D

    Grant the logging services 's3:GetBucketLocation' permission on the S3 bucket policy in the logging account.

  5. E

    Ensure that the IAM role assumed by the logging services has 's3:PutObjectAcl' permission on the bucket.

Show answer and explanation

Correct answers: A, C

Explanation

To enable centralized logging in a multi-account setup, the S3 bucket policy in the destination account must grant 's3:PutObject' permission to the logging services so they can write logs to the bucket. Additionally, the bucket policy must allow cross-account access by specifying the AWS principals of the source accounts. ACLs are not recommended, and other permissions like 's3:GetBucketLocation' or 's3:PutObjectAcl' are unnecessary for this specific use case.

  • A. Correct.

    Correct: The 's3:PutObject' permission is required for AWS services like CloudTrail, Config, and VPC Flow Logs to write logs to the S3 bucket.

  • B. Incorrect.

    Incorrect: Bucket ACLs are no longer recommended for granting access to S3 buckets. AWS recommends using bucket policies instead.

  • C. Correct.

    Correct: To enable cross-account logging, the S3 bucket policy must explicitly allow access from the principals of the source AWS accounts.

  • D. Incorrect.

    Incorrect: The 's3:GetBucketLocation' permission is not required for logging services to deliver logs to the S3 bucket.

  • E. Incorrect.

    Incorrect: The 's3:PutObjectAcl' permission is not necessary for logging services to write objects to the bucket. The required permission is 's3:PutObject'.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam