The company uses CloudTrail to record user activity and must protect those log files from being altered, removed, or forged to meet new security standards. Which approach fulfills this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable CloudTrail log file integrity validation..
Why this is the answer
Enabling CloudTrail log file integrity validation is the correct approach because it uses cryptographic hashing to determine if a log file has been modified or deleted after CloudTrail delivered it. This mechanism ensures the authenticity and integrity of your logs, which is crucial for security and compliance. While S3 MFA Delete adds an extra layer of security for deleting objects, it doesn't prevent modification of existing logs or detect if they've been tampered with. S3 Versioning preserves previous versions but doesn't validate the integrity of any specific version. Encrypting logs with KMS protects them at rest but doesn't detect unauthorized modifications once decrypted or accessed.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed