Question 1 · choose 1
Auditors require a record of which IAM principal read each object in a sensitive S3 bucket. The records must appear in the company's existing CloudTrail trail, which logs management events only. What should a data engineer do?
- AAdd data events for the bucket's objects to the trail
- BTurn on CloudTrail Insights events for the trail
- CTurn on S3 Versioning for the sensitive bucket
- DAdd an AWS Config rule that checks the bucket's logging settings
Show the answer and why
AAdd data events for the bucket's objects to the trail
Correct
Trails do not log data events by default. S3 object-level activity such as GetObject is a data event, and logging it costs extra.
BTurn on CloudTrail Insights events for the trail
Incorrect
Insights events flag unusual API call rates or error rates against a baseline. They do not record each object read.
CTurn on S3 Versioning for the sensitive bucket
Incorrect
Versioning keeps every version of an object. It records nothing about who read them.
DAdd an AWS Config rule that checks the bucket's logging settings
Incorrect
Config rules evaluate resource configurations. They do not record requests made against the bucket.
CloudTrail splits activity into management events (logged by default) and data events such as S3 object reads (opt-in, per resource).
AWS documentation