Medium1 markMultiple Choice
Domain 1.2: Security ControlsSecurityCloudTrailCompliance

AWS SAP-C02 · Question 07 · Domain 1.2: Security Controls

A healthcare company is migrating to AWS and must comply with HIPAA. They are setting up a multi-account structure. They need to ensure that AWS CloudTrail logs are immutable, encrypted, and centrally stored. Additionally, they must automatically detect if any CloudTrail logging is disabled across the organization. Which combination of steps should the Architect take? (Select THREE)

Answer options:

A.

Create an organization trail in AWS Organizations that logs to a central S3 bucket.

B.

Enable S3 Object Lock in compliance mode on the central CloudTrail S3 bucket.

C.

Deploy an AWS Config rule (cloudtrail-enabled) across all accounts using AWS CloudFormation StackSets.

D.

Use Amazon Macie to continuously monitor the CloudTrail S3 bucket for unauthorized modifications.

E.

Create a Service Control Policy (SCP) that denies the s3:DeleteObject action on all S3 buckets in the organization.

F.

Enable AWS Shield Advanced on the central CloudTrail S3 bucket to protect against DDoS attacks.

How to approach this question

Select the native AWS features for centralized logging, immutability, and configuration compliance monitoring.

Full Answer

For strict compliance, an Organization Trail ensures all accounts are logged centrally. S3 Object Lock (Compliance mode) provides WORM (Write Once Read Many) storage, ensuring immutability. AWS Config continuously monitors resource configurations, including CloudTrail status.

Common mistakes

Selecting Macie for log integrity, or applying overly broad SCPs.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 5

75 questions · hints · full answers · grading

More questions from this exam