exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 591 discussion

Exam question from Amazon's AWS-SysOps
Question #: 591
Topic #: 1
[All AWS-SysOps Questions]

A company's auditor implemented a compliance requirement that all Amazon S3 buckets must have logging enabled. A SysOps administrator is tasked to ensure this compliance requirement is met, while still permitting developers to create and use new S3 buckets.
Which action should be taken to accomplish this?

  • A. Add AWS CloudTrail logging for the S3 buckets.
  • B. Implement IAM policies to allow only the storage team to create S3 buckets.
  • C. Add the S3_BUCKET_LOGGING_ENABLED AWS Config managed rule.
  • D. Create an AWS Lambda function to delete the S3 buckets if logging is not turned on.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config-rules.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
albert_kuo
9 months, 4 weeks ago
Selected Answer: C
By adding the S3_BUCKET_LOGGING_ENABLED AWS Config managed rule, you can automatically check if logging is enabled for all S3 buckets in your AWS account. This rule evaluates the S3 bucket configuration and checks if server access logging is enabled. If any bucket is found without logging enabled, it will be flagged as non-compliant. This approach allows you to enforce the compliance requirement without restricting developers from creating and using new S3 buckets. The AWS Config managed rule provides continuous monitoring and automatic evaluation of compliance, ensuring that logging is enabled for all S3 buckets in your environment.
upvoted 1 times
...
okm1997_2
1 year, 2 months ago
Selected Answer: C
Ans => C => https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-logging-enabled.html
upvoted 1 times
...
Adeshina
2 years, 2 months ago
Answer is C
upvoted 1 times
...
johnyjohny1
2 years, 4 months ago
Selected Answer: A
I think it's A, the suggested answer and even the comment by wahlbergusa points to a link where the "S3_BUCKET_LOGGING_ENABLED" is just a boolean that checks if logging is enabled, therefore doesn't really activate or deactivate anything. Supporting evidence for A: https://docs.aws.amazon.com/AmazonS3/latest/userguide/enable-cloudtrail-logging-for-s3.html
upvoted 2 times
DAAJ
10 months, 4 weeks ago
Correct answer is C. Question states- compliance requirement that all Amazon S3 buckets must have logging enabled AWS Config rule S3_BUCKET_LOGGING_ENABLED acts as a control to prevent any non-compliant S3 bucket with logging disabled. https://aws.amazon.com/blogs/mt/aws-config-auto-remediation-s3-compliance/
upvoted 1 times
...
...
wahlbergusa
2 years, 6 months ago
Answer is C. => https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-logging-enabled.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago