A company centrally stores all AWS CloudTrail logs in an Amazon S3 bucket managed by the security team. The team must prevent unauthorized access and detect or prevent any tampering of the logs. Which combination of actions should be implemented? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable server-side encryption with AWS KMS managed encryption keys (SSE-KMS) on the S3 bucket., Enforce least-privilege access to the S3 bucket by using a bucket policy., Enable CloudTrail log file integrity validation..
Why this is the answer
Enabling SSE-KMS encrypts the logs at rest, protecting them from unauthorized access even if the underlying storage is compromised. Enforcing least-privilege access via a bucket policy ensures only authorized personnel or services can read or modify the logs, preventing tampering. CloudTrail log file integrity validation uses cryptographic hashing to detect any changes, deletions, or additions to the log files after they are delivered to S3, providing proof of non-tampering. Compressing logs saves storage but doesn't enhance security. An EventBridge rule could alert to modifications but doesn't prevent them or validate integrity. Access Analyzer for S3 helps identify unintended access but doesn't directly prevent tampering or encrypt data.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed