exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 192 discussion

AWS CloudTrail is being used to monitor API calls in an organization. An audit revealed that CloudTrail is failing to deliver events to Amazon S3 as expected.

What initial actions should be taken to allow delivery of CloudTrail events to S3? (Choose two.)

  • A. Verify that the S3 bucket policy allows CloudTrail to write objects.
  • B. Verify that the IAM role used by CloudTrail has access to write to Amazon CloudWatch Logs.
  • C. Remove any lifecycle policies on the S3 bucket that are archiving objects to S3 Glacier Flexible Retrieval.
  • D. Verify that the S3 bucket defined in CloudTrail exists.
  • E. Verify that the log file prefix defined in CloudTrail exists in the S3 bucket.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
youonebe
3 months, 2 weeks ago
Selected Answer: AD
While the log file prefix is important for organizing logs within the S3 bucket, the prefix does not need to exist beforehand. CloudTrail will automatically create the necessary directories (based on the prefix) in the S3 bucket when logs are delivered. The existence of the prefix itself is not a critical requirement for the delivery of CloudTrail logs.
upvoted 2 times
...
IPLogic
4 months, 3 weeks ago
Selected Answer: AD
To address the issue of CloudTrail failing to deliver events to Amazon S3, the initial actions you should take are: A. Verify that the S3 bucket policy allows CloudTrail to write objects. D. Verify that the S3 bucket defined in CloudTrail exists. These steps ensure that CloudTrail has the necessary permissions to write logs to the S3 bucket and that the specified bucket is correctly set up and accessible
upvoted 1 times
...
723993f
5 months ago
Selected Answer: AD
obvious
upvoted 1 times
...
J0_e
5 months ago
Selected Answer: AD
AD. Prefix is optional when creating a trail
upvoted 1 times
...
daburahjail
5 months, 2 weeks ago
Selected Answer: AE
(E) According to this, log file prefixes should be configured correctly both in the bucket policy and in CTrail configuration. I am assuming if the bucket does not exist, the Trail configuration should fail prematurely. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/turn-on-cloudtrail-in-additional-accounts.html
upvoted 1 times
...
Xelnak
6 months ago
AE read the documentation
upvoted 1 times
...
dhewa
6 months, 1 week ago
Selected Answer: AD
AD it is.
upvoted 1 times
...
Bad_Mat
6 months, 1 week ago
It's AD
upvoted 1 times
...
SkyBlueUS
6 months, 3 weeks ago
AE might be the right answer?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago