A security team requires a way to prove that AWS CloudTrail log files have not been modified after delivery. The organization already uses IAM to restrict who can access particular trails. What is the MOST operationally efficient method to guarantee and validate the integrity of each delivered CloudTrail file?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable CloudTrail’s built-in file integrity validation on the trail. Use the digest file that CloudTrail produces to allow the security team to confirm each delivered file’s integrity..
Why this is the answer
The most operationally efficient method is to enable CloudTrail's built-in file integrity validation. CloudTrail automatically creates digest files that contain a hash of the log files delivered to your S3 bucket. These digest files are signed by AWS, providing cryptographic proof that the log files have not been tampered with. The security team can then use these digest files to validate the integrity of each delivered CloudTrail file. This is a native, fully managed feature requiring minimal configuration and maintenance. The other options involve custom solutions (Lambda functions, DynamoDB, S3 object tags) which are less efficient because they require developing, deploying, and maintaining custom code and infrastructure. While technically possible, they introduce unnecessary operational overhead compared to CloudTrail's native functionality.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed