A security engineer needs to change the Amazon S3 log file prefix for an existing AWS CloudTrail trail. When saving the change in the CloudTrail console, the engineer receives the error: "There is a problem with the bucket policy." What action will allow the change to be saved?
Choose an answer
Tap an option to check your answer.
Correct answer: Update the existing Amazon S3 bucket policy to include the new log file prefix required by CloudTrail, then update the prefix in the CloudTrail console..
Why this is the answer
When you change the S3 log file prefix for an existing CloudTrail trail, CloudTrail attempts to update the S3 bucket policy to reflect this change. If the bucket policy does not explicitly permit CloudTrail to write logs to the new prefix, the update will fail with a "There is a problem with the bucket policy" error. Therefore, you must first manually update the S3 bucket policy to include the new log file prefix in the resource ARN for the s3:PutObject and s3:GetBucketAcl actions. After the bucket policy is updated, CloudTrail will be able to successfully save the prefix change. Creating a new trail is unnecessary and inefficient. Updating permissions for PutBucketPolicy or GetBucketPolicy for the engineer's principal does not address the core issue of the bucket policy itself lacking the necessary permissions for CloudTrail.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed