A company stores sensitive data in an Amazon S3 bucket. The security team must log all object-level activity for that bucket and retain the logs for 5 years. The security team also must receive an email notification whenever there is an attempt to delete data in the bucket. Which combination of steps meets these requirements most cost-effectively? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Configure AWS CloudTrail to log S3 data events for the bucket., Configure S3 to send object deletion events to Amazon EventBridge and have EventBridge publish to an Amazon SNS topic to notify the security team by email., Create a separate S3 bucket to store the logs and apply an S3 Lifecycle policy to manage 5-year retention and lower-cost storage tiers..
Why this is the answer
Configuring AWS CloudTrail to log S3 data events is essential for capturing all object-level activity, including deletions, which fulfills the logging requirement. Creating a separate S3 bucket for logs and applying an S3 Lifecycle policy ensures cost-effective 5-year retention by transitioning logs to lower-cost storage tiers like S3 Glacier. Configuring S3 to send object deletion events to Amazon EventBridge, which then publishes to an Amazon SNS topic, allows for email notifications to the security team upon deletion attempts. S3 server access logging provides access logs but not detailed object-level activity like CloudTrail data events. Sending events directly to Amazon SES is not a native S3 event notification option. Storing logs in Amazon Timestream is not the most cost-effective or standard solution for S3 access logs; S3 is preferred for this purpose.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed