SCS-C02 exam dumps

SCS-C02 practice question 238 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 238

Select 2

An organization is using AWS Organizations to manage multiple AWS accounts. The Security team needs to ensure that no account within the organization can disable AWS CloudTrail or delete its logs from the associated S3 bucket. How can this be achieved?

  1. A

    Use Service Control Policies (SCPs) to deny actions related to disabling CloudTrail across all accounts in the organization.

  2. B

    Enable CloudTrail log file integrity validation to prevent log tampering or deletion.

  3. C

    Configure an S3 bucket policy to explicitly deny deletion of CloudTrail logs by any IAM user or role.

  4. D

    Use an IAM policy attached to the root user of each account to restrict actions on CloudTrail and S3 log buckets.

  5. E

    Enable AWS Config to monitor and alert on any changes to CloudTrail settings or log bucket configurations.

Show answer and explanation

Correct answers: A, C

Explanation

To ensure that CloudTrail cannot be disabled and logs cannot be deleted, you need a combination of organizational-level and resource-level controls. Service Control Policies (SCPs) are used at the AWS Organizations level to enforce restrictions across all accounts, ensuring no user or role can disable CloudTrail. Additionally, configuring an explicit deny in the S3 bucket policy for the CloudTrail logs ensures that no one can delete the logs, even if they have permissions to access the bucket. Together, these measures provide a secure, organization-wide approach to protecting CloudTrail and its logs.

  • A. Correct.

    This is correct. Service Control Policies (SCPs) can be applied at the organizational level to enforce that no member accounts can disable CloudTrail.

  • B. Incorrect.

    This is incorrect. While log file integrity validation ensures the logs haven't been tampered with, it does not prevent the disabling of CloudTrail or the deletion of logs.

  • C. Correct.

    This is correct. An S3 bucket policy can explicitly deny deletion of CloudTrail logs, which ensures that no IAM user or role can remove the logs from the bucket.

  • D. Incorrect.

    This is incorrect. IAM policies attached to the root user are not the recommended way to enforce restrictions, and the root user should not be used for such configurations.

  • E. Incorrect.

    This is incorrect. AWS Config can monitor and alert on changes but does not enforce restrictions to prevent the disabling of CloudTrail or deletion of logs.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam