SCS-C02 exam dumps

SCS-C02 practice question 160 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 160

Select 2

Your organization has set up AWS CloudTrail to log all API activity in your AWS environment. The logs are stored in an S3 bucket named 'company-logs-bucket'. After testing, you notice that the logs are not being delivered to the bucket. Which of the following permissions must be configured to ensure that CloudTrail can write logs to the S3 bucket?

  1. A

    The S3 bucket policy must grant the 's3:PutObject' permission to the CloudTrail service principal.

  2. B

    The IAM role assumed by CloudTrail must have the 's3:PutObject' permission for the S3 bucket.

  3. C

    The S3 bucket policy must grant the 's3:GetObject' permission to the CloudTrail service principal.

  4. D

    The S3 bucket policy must explicitly deny access to unauthorized principals.

  5. E

    The IAM role assumed by CloudTrail must have the 's3:ListBucket' permission for the S3 bucket.

Show answer and explanation

Correct answers: A, B

Explanation

For CloudTrail to deliver logs to an S3 bucket, the service requires the 's3:PutObject' permission. This can be granted either through the S3 bucket policy or via the IAM role assumed by CloudTrail, depending on how the organization has configured permissions. Ensuring these permissions are in place allows CloudTrail to successfully write log files to the designated bucket.

  • A. Correct.

    Correct: CloudTrail requires the 's3:PutObject' permission in the S3 bucket policy to deliver log files to the bucket.

  • B. Correct.

    Correct: The IAM role assumed by CloudTrail must have the 's3:PutObject' permission to write logs to the bucket.

  • C. Incorrect.

    Incorrect: The 's3:GetObject' permission is not required for CloudTrail to write logs to the S3 bucket. It is only needed for reading objects.

  • D. Incorrect.

    Incorrect: While denying access to unauthorized principals is a good security practice, it is not directly related to granting CloudTrail the necessary permissions to write logs.

  • E. Incorrect.

    Incorrect: The 's3:ListBucket' permission is not required for CloudTrail to deliver logs. It is typically used for listing objects in a bucket, which is unrelated to log delivery.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam