CloudTrail is enabled and delivers log files to an Amazon S3 bucket. The operations team is worried that delivered log files might be altered after arrival in the bucket. Going forward, how can the administrator verify that individual CloudTrail log files were not modified after delivery?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable CloudTrail log-file integrity validation and use the digest files to validate each log file’s hash..
Why this is the answer
CloudTrail log file integrity validation is the correct solution because it specifically addresses the concern of log file alteration. When enabled, CloudTrail delivers digest files to your S3 bucket every hour, which contain hashes of the log files delivered during that period. You can then use these digest files to cryptographically verify that individual log files have not been tampered with after delivery. Streaming CloudTrail events to CloudWatch Logs provides a second copy but doesn't inherently validate the integrity of the original S3-stored logs against post-delivery modification. Replicating the S3 bucket and encrypting logs enhances durability and security but doesn't provide a mechanism to verify the integrity of individual files against alteration. S3 server access logging records requests made to the bucket, which is useful for auditing access, but it does not validate the content integrity of the objects themselves.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed