exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 684 discussion

Exam question from Amazon's AWS-SysOps
Question #: 684
Topic #: 1
[All AWS-SysOps Questions]

A company monitors its account activity using AWS CloudTrail, and is concerned that some log files are being tampered with after the logs have been delivered to the account's Amazon S3 bucket.
Moving forward, how can the SysOps Administrator confirm that the log files have not been modified after being delivered to the S3 bucket.

  • A. Stream the CloudTrail logs to Amazon CloudWatch Logs to store logs at a secondary location.
  • B. Enable log file integrity validation and use digest files to verify the hash value of the log file.
  • C. Replicate the S3 log bucket across regions, and encrypt log files with S3 managed keys.
  • D. Enable S3 server access logging to track requests made to the log bucket for security audits.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
CloudTrail log file integrity validation can be used to check whether a log file was modified, deleted, or unchanged after CloudTrail delivered it

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
karmaah
Highly Voted 6 months, 4 weeks ago
When you enable log file integrity validation, CloudTrail creates a hash for every log file that it delivers. Every hour, CloudTrail also creates and delivers a file that references the log files for the last hour and contains a hash of each. This file is called a digest file. CloudTrail signs each digest file using the private key of a public and private key pair. After delivery, you can use the public key to validate the digest file. CloudTrail uses different key pairs for each AWS region
upvoted 19 times
joyjyothi
6 months, 3 weeks ago
Thank you so much for the details.
upvoted 3 times
...
...
saumenP
Highly Voted 7 months, 1 week ago
B is correct
upvoted 14 times
...
Cyril_the_Squirl
Most Recent 5 months, 4 weeks ago
B is correct. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-log-file-validation-intro.html
upvoted 1 times
...
Huy
5 months, 4 weeks ago
C is correct. VPC Flow Logs is not able to gather operating system log files for analysis. I think C means use EC2Rescure on the new instance to understand the issue, not on the unreachable instances.
upvoted 1 times
Cyril_the_Squirl
5 months, 4 weeks ago
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-log-file-validation-intro.html
upvoted 1 times
...
...
RicardoD
6 months ago
B is the answer
upvoted 1 times
...
abhishek_m_86
6 months ago
B. Enable log file integrity validation and use digest files to verify the hash value of the log file.
upvoted 3 times
...
jackdryan
6 months, 1 week ago
I'll go with B
upvoted 1 times
...
gilbertlelancelo
6 months, 1 week ago
B. Enable log file integrity validation and use digest files to verify the hash value of the log file.
upvoted 1 times
...
waterzhong
6 months, 2 weeks ago
B is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago