A company needs to retain audit logs for ten years and ensure the logs cannot be altered after they are stored. Which storage solution fulfills these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Store the logs in an Amazon S3 Glacier vault and apply a vault lock policy to enforce write-once, read-many (WORM) retention..
Why this is the answer
Storing logs in an Amazon S3 Glacier vault with a vault lock policy is the correct solution because Glacier is a cost-effective storage class for long-term archives, and a vault lock policy enforces a WORM (Write Once, Read Many) model. This WORM model ensures that once data is written, it cannot be altered or deleted for the specified retention period, meeting the requirement for immutable audit logs. Placing logs on an Amazon EBS volume and enabling AWS KMS encryption does not provide immutability; EBS volumes can be modified or deleted. Saving logs in Amazon S3 Standard-Infrequent Access with server-side encryption or requiring MFA for access also doesn't guarantee immutability. While these options offer data protection and access control, they do not prevent modification or deletion of the stored objects.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed