exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 69 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 69
Topic #: 1
[All AWS Certified Security - Specialty Questions]

Which of the following is the most efficient way to automate the encryption of AWS CloudTrail logs using a Customer Master Key (CMK) in AWS KMS?

  • A. Use the KMS direct encrypt function on the log data every time a CloudTrail log is generated.
  • B. Use the default Amazon S3 server-side encryption with S3-managed keys to encrypt and decrypt the CloudTrail logs.
  • C. Configure CloudTrail to use server-side encryption using KMS-managed keys to encrypt and decrypt CloudTrail logs.
  • D. Use encrypted API endpoints so that all AWS API calls generate encrypted CloudTrail log entries using the TLS certificate from the encrypted API call.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/encrypting-cloudtrail-log-files-with-aws-kms.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sanjaym
Highly Voted 3 years, 6 months ago
Ans: C 100%
upvoted 9 times
...
ITGURU51
Most Recent 1 year, 11 months ago
This is because it provides the following benefits: It allows you to use your own CMKs to encrypt your CloudTrail logs. It provides an audit trail of all key usage. It allows you to control access to your keys. It provides automatic key rotation. C
upvoted 2 times
...
Isaias
2 years, 5 months ago
Selected Answer: C
C for sure
upvoted 2 times
...
ff12
3 years, 6 months ago
ANS --> C
upvoted 2 times
...
Larsson
3 years, 6 months ago
C. Think about it, that you might want to store the logs somewhere else than AWS and need to decrypt them somewhere else.
upvoted 4 times
...
kalzht00
3 years, 6 months ago
ANS - C
upvoted 2 times
...
devjava
3 years, 6 months ago
Ans > C https://docs.aws.amazon.com/awscloudtrail/latest/userguide/encrypting-cloudtrail-log-files-with-aws-kms.html
upvoted 3 times
...
AfricanCloudGuru
3 years, 6 months ago
Ans(C) SSE using KMS https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingKMSEncryption.html
upvoted 1 times
...
AfricanCloudGuru
3 years, 6 months ago
Ans(C)
upvoted 1 times
...
RoyWeiss
3 years, 6 months ago
ccccccc !!!
upvoted 1 times
...
RaySmith
3 years, 6 months ago
C is correct
upvoted 2 times
...
CloudyMcClouderson
3 years, 6 months ago
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/encrypting-cloudtrail-log-files-with-aws-kms.html
upvoted 1 times
...
ourking
3 years, 7 months ago
I all go with C. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/encrypting-cloudtrail-log-files-with-aws-kms.html
upvoted 1 times
...
RakeshTaninki
3 years, 7 months ago
C is correct
upvoted 1 times
...
AnNguyen
3 years, 7 months ago
Answer is C
upvoted 2 times
...
Osemk
3 years, 7 months ago
C is the answer
upvoted 2 times
...
exams
3 years, 7 months ago
yeah. C is right https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingKMSEncryption.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago