exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 175 discussion

A company monitors its account activity using AWS CloudTrail, and is concerned that some log files are being tampered with after the logs have been delivered to the account’s Amazon S3 bucket.

Moving forward, how can the SysOps administrator confirm that the log files have not been modified after being delivered to the S3 bucket?

  • A. Stream the CloudTrail logs to Amazon CloudWatch Logs to store logs at a secondary location.
  • B. Enable log file integrity validation and use digest files to verify the hash value of the log file.
  • C. Replicate the S3 log bucket across regions, and encrypt log files with S3 managed keys.
  • D. Enable S3 server access logging to track requests made to the log bucket for security audits.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JamesF92
Highly Voted 1 year, 2 months ago
Selected Answer: B
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-log-file-validation-intro.html
upvoted 5 times
jipark
1 year, 2 months ago
"integrity validation" is keyword
upvoted 1 times
...
...
Liongeek
Highly Voted 1 year, 11 months ago
Ans: B
upvoted 5 times
...
r2c3po
Most Recent 10 months ago
Selected Answer: B
Option B is the correct choice: To confirm that CloudTrail log files have not been modified after being delivered to an S3 bucket, you can enable log file integrity validation. When log file integrity validation is enabled, AWS CloudTrail generates digest files that contain the hash values of the delivered log files. These hash values are then used to verify the integrity of the log files. # B. Enable log file integrity validation and use digest files to verify the hash value of the log file: Log file integrity validation helps ensure that log files stored in the S3 bucket have not been tampered with. It adds an additional layer of security by providing a way to verify the integrity of the log files using hash values stored in digest files.
upvoted 2 times
...
Christina666
1 year, 3 months ago
Selected Answer: B
B..........log file integrity validation
upvoted 2 times
...
michaldavid
1 year, 10 months ago
Selected Answer: B
bbbbbbb
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago