The company requires that all AWS account activity be logged with CloudTrail and that an administrator be alerted when CloudTrail log files are altered or removed. How should the SysOps administrator meet both requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Turn on CloudTrail log file integrity validation. Use the AWS CLI tools to verify the integrity of the log files..
Why this is the answer
The correct answer is to turn on CloudTrail log file integrity validation and use the AWS CLI tools to verify the integrity. CloudTrail log file integrity validation uses cryptographic hashing and digital signatures to determine if a log file has been modified or deleted after CloudTrail delivered it. The AWS CLI provides commands to validate these files. Using the AWS CloudTrail Processing Library is not the primary or most direct method for verifying integrity in an operational context; it's more for processing and analyzing logs. CloudTrail Insights focuses on detecting unusual activity, not specifically log file alteration. Sending logs to CloudWatch Logs allows for monitoring, but CloudWatch itself doesn't inherently validate the integrity of the CloudTrail log files against tampering; it only processes the events it receives.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed