ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization runs a multi-tenant SaaS platform on AWS. Regulators require that every administrative API call be preserved for seven years and that you can provide auditors with cryptographic proof the records were never altered. Management wants the least possible ongoing maintenance effort while meeting these mandates. Which design choice BEST satisfies the requirement?

  • Configure application servers to write JSON audit events locally, then replicate those files to a second S3 bucket each night.

  • Enable AWS CloudTrail in all regions with log file integrity validation and send the trails to an S3 bucket that has Object Lock set to Compliance mode for seven years.

  • Stream CloudTrail events into a self-managed Elasticsearch cluster and create weekly encrypted snapshots to S3.

  • Enable Amazon VPC Flow Logs and archive them directly to Glacier Deep Archive with a seven-year retention lifecycle policy.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot