Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 112 discussion

A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account.

All AWS account activity across all member accounts must be logged and reported to the dedicated security account. The company must retain all the activity logs in a secure storage location within the dedicated security account for 2 years. No changes or deletions of the logs are allowed.

Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)

  • A. In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's management account to write to the S3 bucket.
  • B. In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
  • C. In the dedicated security account, create an Amazon S3 bucket that has an S3 Lifecycle configuration that expires objects after 2 years. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
  • D. Create an AWS CloudTrail trail for the organization. Configure logs to be delivered to the logging Amazon S3 bucket in the dedicated security account.
  • E. Turn on AWS CloudTrail in each account. Configure logs to be delivered to an Amazon S3 bucket that is created in the organization's management account. Forward the logs to the S3 bucket in the dedicated security account by using AWS Lambda and Amazon Kinesis Data Firehose.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ahrentom
Highly Voted 10 months, 1 week ago
Selected Answer: BD
I go with BD, because each Member Account has to write into the security Account S3 bucket, not only the Organization Management Account. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-set-bucket-policy-for-multiple-accounts.html
upvoted 9 times
kejam
10 months, 1 week ago
Agreed. CloudTrail for Org requires the destination S3 bucket to allow writes from each member account. Object Lock is enabled to prevent the data from being overwritten/deleted.
upvoted 2 times
...
...
navid1365
Most Recent 2 months, 2 weeks ago
Selected Answer: BD
B and D
upvoted 1 times
...
cumzle_com
3 months, 2 weeks ago
Selected Answer: AD
B increases the surface area for potential security issues since multiple member accounts have write access to the bucket.
upvoted 1 times
...
Ritarocks
7 months ago
AD. A and not B because, member account number tracking does not make sense, when it's easy to use single Org as reference for Bucket policy.
upvoted 1 times
...
Ernestokoro
8 months, 1 week ago
The organization includes a dedicated security account= Member account while ALL OTHER =Management account. this means to me that granting the permission from the Management account reduces operational overhead than doing it at individual member accounts. Therefore I go with option AD.
upvoted 1 times
...
vikasj1in
8 months, 3 weeks ago
A, D Option B covers the storage aspect by configuring a dedicated S3 bucket in the security account, allowing member accounts to write logs. S3 Object Lock in compliance mode ensures the retention requirements. Option D complements this by configuring CloudTrail to capture the logs and deliver them to the dedicated S3 bucket directly. Together, these options cover the log storage, retention, and collection requirements with the least operational overhead.
upvoted 1 times
...
WeepingMaplte
9 months, 1 week ago
Selected Answer: AD
Enable Organization Trail: In the Management Console or CLI, activate an organization trail that logs all events from all member accounts. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html
upvoted 1 times
...
jeff001
9 months, 3 weeks ago
Selected Answer: BD
Member account needs to write to S3.
upvoted 2 times
...
marco25
10 months, 1 week ago
Selected Answer: BD
trails across member accounts, needs permissions to the sender bucket
upvoted 4 times
...
Aamee
10 months, 1 week ago
Selected Answer: AD
If I understand correctly, the reason why the option B can't be a correct one cuz the use case has asked about the logs which must not be deleted or changed which can't be met in option B if we opt for each member's accounts to be given with the full S3 logs access under an organization.
upvoted 1 times
ykhan321
9 months, 2 weeks ago
A has only one account and option B has all the aws accounts.
upvoted 1 times
...
confusedyeti69
10 months ago
If following your logic, the management account can delete and change the logs too. And the options also says to only give write access to S3 only. It is not A because members need to write S3, not only management. In compliance mode, a protected object version can't be overwritten or deleted by any user, including the root user in your AWS account. https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html
upvoted 2 times
...
...
[Removed]
10 months, 2 weeks ago
Selected Answer: AD
A and D are correct
upvoted 1 times
...
oioi
10 months, 2 weeks ago
Selected Answer: AD
correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...