ExamQuestions.com

Register
Login
AWS Certified Security Specialty Exam Questions

Amazon

AWS Certified Security Specialty

206 / 310

Question 206:

Your CTO thinks your AWS account was hacked. As CloudTrail has been enabled in the AWS account, you want to analyze the API activities from the logs. How would you ensure that the CloudTrail log files were not modified or deleted after CloudTrail delivered them?

Answer options:

A.Use CloudTrail Log File Integrity Validation.
B.Use AWS Config SNS Subscriptions and process events in real-time.
C.Use CloudTrail backed up to AWS S3 and Glacier.
D.Use AWS Config Timeline forensics.