Examtopics

AWS Certified Security - Specialty
  • Topic 1 Question 147

    A security engineer needs to build a solution to turn AWS CloudTrail back on in multiple AWS Regions in case it is ever turned off.

    What is the MOST efficient way to implement this solution?

    • Use AWS Config with a managed rule to initiate the AWS-EnableCloudTrail remediation.

    • Create an Amazon EventBridge event with a cloudtrail.amazonaws.com event source and a StartLogging event name to invoke an AWS Lambda function to call the StartLogging API.

    • Create an Amazon CloudWatch alarm with a cloudtrail.amazonaws.com event source and a StopLoggmg event name to invoke an AWS Lambda function to call the StartLogging API.

    • Monitor AWS Trusted Advisor to ensure CloudTrail logging is enabled.


    シャッフルモード