Use a CloudTrail trail with log file validation and S3 data events for object-level logging

Answer Correct answer: A — a CloudTrail trail with log file validation enabled and S3 data events logs object-level activity with a digital signature.

A company needs to log object-level activity in its Amazon S3 buckets. The company also needs to validate the integrity of the log file by using a digital signature. Which solution will meet these requirements?

  1. Create an AWS CloudTrail trail with log file validation enabled. Enable data events. Specify Amazon S3 as the data event type. Correct Answer
  2. Create a new S3 bucket for S3 server access logs. Configure the existing S3 buckets to send their S3 server access logs to the new S3 bucket.
  3. Create an Amazon CloudWatch Logs log group. Configure the existing S3 buckets to send their S3 server access logs to the log group.
  4. Create a new S3 bucket for S3 server access logs with log file validation enabled. Enable data events. Specify Amazon S3 as the data event type.

Community Votes

A
80%
D
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Only CloudTrail provides log file validation with a digital signature, and its S3 data events capture object-level activity (A). S3 server access logs (B/C/D) record requests but have no digital-signature integrity validation, and option D's 'log file validation' does not apply to server access logs. A is the only option meeting both requirements.

To log object-level S3 activity and cryptographically validate log integrity, create a CloudTrail trail, enable data events and specify Amazon S3 as the data-event type (capturing object-level GET/PUT/DELETE), and enable log file validation—which uses a digital signature (SHA-256 hash chain) so you can verify the logs were not tampered with. S3 server access logs (B/D) do not provide digital-signature validation.

Using S3 server access logs (B/C/D)—they log object requests but lack CloudTrail's digital-signature log file validation, so integrity cannot be cryptographically verified. Assuming server access logs support 'log file validation' (D)—that capability is specific to CloudTrail, not S3 access logs. A is the correct service.

Community Discussion (3 comments)

IPLogic 👍 2 Selected: A
Object-Level Logging: By enabling data events in AWS CloudTrail and specifying Amazon S3 as the data event type, you can log object-level activities such as GET, PUT, DELETE, and other operations on your S3 objects. Log File Validation: AWS CloudTrail provides the option to enable log file integrity validation. When this feature is enabled, CloudTrail creates a hash for each log file and delivers it alongside the log file. This ensures that you can verify the integrity and authenticity of your log files, confirming they haven't been tampered with.
HappyG 👍 2 Selected: A
Only CloudTrail provides the digital signature validation feature.
jdx000 👍 1 Selected: D
answer is D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A CloudTrail trail with S3 data events enabled records object-level API activity (GetObject, PutObject, DeleteObject, etc.) in the buckets. Enabling CloudTrail log file validation adds a digital signature (a SHA-256 hash chain) to the delivered logs, letting you verify they have not been modified—meeting both the object-level logging and integrity-validation requirements.

Why the Other Options Are Wrong

B and C use S3 server access logs, which record requests but provide no digital-signature validation of log integrity. D also references server access logs with 'log file validation,' but that feature belongs to CloudTrail, not S3 access logs. Only A delivers both object-level logging and signed log-file validation.

Community Comment Notes

Community voted A (80), with D a 20 minority. Commenters noted only CloudTrail provides the digital-signature log file validation feature, and S3 data events capture object-level activity. A confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide