Question 1 · choose 1
An organization trail delivers CloudTrail logs for all accounts to a central S3 bucket. Auditors must be able to show whether any log file was modified or deleted after CloudTrail delivered it. What should a data engineer turn on?
- ACloudTrail Insights events for the trail
- BLog file integrity validation for the trail
- CS3 Versioning for the log bucket
- DDefault encryption with SSE-KMS on the log bucket
Show the answer and why
ACloudTrail Insights events for the trail
Incorrect
Insights events detect unusual API call or error rates. They say nothing about whether log files were changed.
BLog file integrity validation for the trail
Correct
Integrity validation uses SHA-256 hashing and RSA signing so you can determine whether a log file was modified, deleted or unchanged after delivery.
CS3 Versioning for the log bucket
Incorrect
Versioning keeps earlier versions of objects, but it does not prove whether a delivered file was changed.
DDefault encryption with SSE-KMS on the log bucket
Incorrect
Encryption protects the files at rest. It does not detect or prove modification.
Proof of integrity comes from digest files that CloudTrail signs; storage features such as versioning or encryption do not provide it.
AWS documentation