Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 55 discussion

A company uses an Amazon CloudFront distribution to deliver its website. Traffic logs for the website must be centrally stored, and all data must be encrypted at rest.
Which solution will meet these requirements?

  • A. Create an Amazon OpenSearch Service (Amazon Elasticsearch Service) domain with internet access and server-side encryption that uses the default AWS managed customer master key (CMK). Configure CloudFront to use the Amazon OpenSearch Service (Amazon Elasticsearch Service) domain as a log destination.
  • B. Create an Amazon OpenSearch Service (Amazon Elasticsearch Service) domain with VPC access and server-side encryption that uses AES-256. Configure CloudFront to use the Amazon OpenSearch Service (Amazon Elasticsearch Service) domain as a log destination.
  • C. Create an Amazon S3 bucket that is configured with default server-side encryption that uses AES-256. Configure CloudFront to use the S3 bucket as a log destination.
  • D. Create an Amazon S3 bucket that is configured with no default encryption. Enable encryption in the CloudFront distribution, and use the S3 bucket as a log destination.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Balliache520505
Highly Voted 2 years, 2 months ago
The answer is C. https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/AccessLogs.html
upvoted 6 times
jipark
1 year, 3 months ago
S3 contains Encrption of Data without addtional KMS solutions.
upvoted 1 times
...
...
gehadg
Most Recent 2 weeks, 1 day ago
Option C: Storing CloudFront logs in an Amazon S3 bucket with server-side encryption using AES-256 meets the requirement for central log storage and data encryption at rest. Amazon S3 provides server-side encryption, and configuring CloudFront to log directly to this bucket is a common and effective way to handle CloudFront logs securely.
upvoted 1 times
...
BietTuot
1 year, 11 months ago
Selected Answer: C
Answer is C
upvoted 3 times
...
michaldavid
1 year, 11 months ago
Selected Answer: C
cccccccc
upvoted 1 times
...
Surferbolt
2 years, 1 month ago
Selected Answer: C
C. CloudFront logs can be sent to an S3 bucket, and S3 buckets can be encrypted.
upvoted 2 times
...
kati2k22cz
2 years, 2 months ago
Selected Answer: C
C. here some references https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html https://stackoverflow.com/questions/52560188/are-my-s3-objects-encrypted-at-rest-or-not
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...