exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 112 discussion

A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account.

All AWS account activity across all member accounts must be logged and reported to the dedicated security account. The company must retain all the activity logs in a secure storage location within the dedicated security account for 2 years. No changes or deletions of the logs are allowed.

Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)

  • A. In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's management account to write to the S3 bucket.
  • B. In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
  • C. In the dedicated security account, create an Amazon S3 bucket that has an S3 Lifecycle configuration that expires objects after 2 years. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
  • D. Create an AWS CloudTrail trail for the organization. Configure logs to be delivered to the logging Amazon S3 bucket in the dedicated security account.
  • E. Turn on AWS CloudTrail in each account. Configure logs to be delivered to an Amazon S3 bucket that is created in the organization's management account. Forward the logs to the S3 bucket in the dedicated security account by using AWS Lambda and Amazon Kinesis Data Firehose.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ahrentom
Highly Voted 1 year ago
Selected Answer: BD
I go with BD, because each Member Account has to write into the security Account S3 bucket, not only the Organization Management Account. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-set-bucket-policy-for-multiple-accounts.html
upvoted 9 times
kejam
1 year ago
Agreed. CloudTrail for Org requires the destination S3 bucket to allow writes from each member account. Object Lock is enabled to prevent the data from being overwritten/deleted.
upvoted 2 times
...
...
Pmktechno
Most Recent 1 month, 1 week ago
Selected Answer: AD
A and D
upvoted 1 times
...
lovekiller
1 month, 3 weeks ago
Selected Answer: AD
To all who are choosing B, the answer is A. Here's the reasoning: In an AWS Organizations setup, the management account can be configured to collect CloudTrail logs from all member accounts and forward them to a centralized Amazon S3 bucket in a dedicated security account. This centralized logging approach ensures that all account activity across the organization is captured and securely stored.
upvoted 1 times
...
navid1365
4 months, 2 weeks ago
Selected Answer: BD
B and D
upvoted 1 times
...
cumzle_com
5 months, 2 weeks ago
Selected Answer: AD
B increases the surface area for potential security issues since multiple member accounts have write access to the bucket.
upvoted 1 times
...
Ritarocks
9 months ago
AD. A and not B because, member account number tracking does not make sense, when it's easy to use single Org as reference for Bucket policy.
upvoted 1 times
...
Ernestokoro
10 months, 1 week ago
The organization includes a dedicated security account= Member account while ALL OTHER =Management account. this means to me that granting the permission from the Management account reduces operational overhead than doing it at individual member accounts. Therefore I go with option AD.
upvoted 1 times
...
vikasj1in
10 months, 3 weeks ago
A, D Option B covers the storage aspect by configuring a dedicated S3 bucket in the security account, allowing member accounts to write logs. S3 Object Lock in compliance mode ensures the retention requirements. Option D complements this by configuring CloudTrail to capture the logs and deliver them to the dedicated S3 bucket directly. Together, these options cover the log storage, retention, and collection requirements with the least operational overhead.
upvoted 1 times
...
WeepingMaplte
11 months, 2 weeks ago
Selected Answer: AD
Enable Organization Trail: In the Management Console or CLI, activate an organization trail that logs all events from all member accounts. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html
upvoted 1 times
...
jeff001
11 months, 3 weeks ago
Selected Answer: BD
Member account needs to write to S3.
upvoted 2 times
...
marco25
1 year ago
Selected Answer: BD
trails across member accounts, needs permissions to the sender bucket
upvoted 4 times
...
Aamee
1 year ago
Selected Answer: AD
If I understand correctly, the reason why the option B can't be a correct one cuz the use case has asked about the logs which must not be deleted or changed which can't be met in option B if we opt for each member's accounts to be given with the full S3 logs access under an organization.
upvoted 1 times
ykhan321
11 months, 2 weeks ago
A has only one account and option B has all the aws accounts.
upvoted 1 times
...
confusedyeti69
12 months ago
If following your logic, the management account can delete and change the logs too. And the options also says to only give write access to S3 only. It is not A because members need to write S3, not only management. In compliance mode, a protected object version can't be overwritten or deleted by any user, including the root user in your AWS account. https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html
upvoted 2 times
...
...
[Removed]
1 year ago
Selected Answer: AD
A and D are correct
upvoted 1 times
...
oioi
1 year ago
Selected Answer: AD
correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...