exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 342 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 342
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A security team is working on a solution that will use Amazon EventBridge (Amazon CloudWatch Events) to monitor new Amazon S3 objects. The solution will monitor for public access and for changes to any S3 bucket policy or setting that result in public access. The security team configures EventBridge to watch for specific API calls that are logged from AWS CloudTrail. EventBridge has an action to send an email notification through Amazon Simple Notification Service (Amazon SNS) to the security team immediately with details of the API call.

Specifically, the security team wants EventBridge to watch for the s3:PutObjectAcl, s3:DeleteBucketPolicy, and s3:PutBucketPolicy API invocation logs from CloudTrail. While developing the solution in a single account, the security team discovers that the s3:PutObjectAcl API call does not invoke an EventBridge event. However, the s3:DeleteBucketPolicy API call and the s3:PutBucketPolicy API call do invoke an event.

The security team has enabled CloudTrail for AWS management events with a basic configuration in the AWS Region in which EventBridge is being tested. Verification of the EventBridge event pattern indicates that the pattern is set up correctly. The security team must implement a solution so that the s3:PutObjectAcl API call will invoke an EventBridge event. The solution must not generate false notifications.

Which solution will meet these requirements?

  • A. Modify the EventBridge event pattern by selecting Amazon S3. Select All Events as the event type.
  • B. Modify the EventBridge event pattern by selecting Amazon S3. Select Bucket Level Operations as the event type.
  • C. Enable CloudTrail Insights to identify unusual API activity.
  • D. Enable CloudTrail to monitor data events for read and write operations to S3 buckets.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AdamWest
Highly Voted 2 years, 5 months ago
Selected Answer: D
D - Is correct you must use Data Events https://docs.amazonaws.cn/en_us/eventbridge/latest/userguide/eb-log-s3-data-events.html
upvoted 10 times
...
Toptip
Most Recent 1 year, 11 months ago
Selected Answer: D
D... easy
upvoted 1 times
...
572f16d
1 year, 11 months ago
Selected Answer: D
D You can also get CloudTrail logs for object-level Amazon S3 actions. To do this, enable data events for your S3 bucket or all buckets in your account. When an object-level action occurs in your account, CloudTrail evaluates your trail settings. If the event matches the object that you specified in a trail, the event is logged. For more information, see Enabling CloudTrail event logging for S3 buckets and objects and Logging Data Events for Trails in the AWS CloudTrail User Guide. The following object-level API actions are logged as CloudTrail events: .... PutObjectAcl .....
upvoted 2 times
...
ITGURU51
1 year, 12 months ago
The solution that will meet the requirements is D. Enable CloudTrail to monitor data events for read and write operations to S3 buckets. This will allow the s3:PutObjectAcl API call to invoke an EventBridge event without generating false notifications.
upvoted 2 times
...
nairj
2 years ago
D : Enable Cloudtrail to monitor API call and set-up an EventBridge rule configuring the source and the target
upvoted 1 times
...
kujin
2 years, 1 month ago
A - s3:DeleteBucketPolicy, and s3:PutBucketPolicy -> Bucket level action s3:PutObjectAcl -> Object level action https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazons3.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago