New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 34 Topic 4 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 34 Topic 4 Discussion

SCS-C02 Exam Topic 4 Question 34 Discussion:
Question #: 34
Topic #: 4

An organization wants to log all IAM API calls made within all of its IAM accounts, and must have a central place to analyze these logs. What steps should be taken to meet these requirements in the MOST secure manner? (Select TWO)


A.

Turn on IAM CloudTrail in each IAM account


B.

Turn on CloudTrail in only the account that will be storing the logs


C.

Update the bucket ACL of the bucket in the account that will be storing the logs so that other accounts can log to it


D.

Create a service-based role for CloudTrail and associate it with CloudTrail in each account


E.

Update the bucket policy of the bucket in the account that will be storing the logs so that other accounts can log to it


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.