ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your organization is drafting an AWS-specific log management policy. Compliance rules mandate that security logs must be retained for at least two years, remain immutable even to administrators, and be stored as cost-effectively as possible after the first 90 days. Which control BEST satisfies all three requirements if CloudTrail and application logs are delivered to an Amazon S3 bucket?
Store logs on Amazon EFS and protect them with AWS Backup vault policies set to a two-year retention window.
Enable S3 Object Lock in compliance mode on the log bucket and add a lifecycle rule that transitions objects to Glacier Deep Archive after 90 days.
Keep logs in CloudWatch Log Groups with a 730-day retention period and rely on CloudWatch built-in integrity checks.
Turn on bucket versioning, replicate logs to a second region, and use a bucket policy that denies DeleteObject for two years.
Amazon S3 Object Lock in compliance mode enforces write-once-read-many (WORM) protection so that no user, including the root account, can alter or delete objects during the retention period. Adding a lifecycle rule that transitions objects to the Glacier Deep Archive storage class after 90 days keeps the data for the full two years at the lowest per-GB cost AWS offers for long-term, infrequently accessed data. The other options either allow privileged deletion, lack true immutability, or retain data in more expensive storage tiers.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Amazon S3 Object Lock in Compliance Mode?
Open an interactive chat with Bash
What is Glacier Deep Archive in AWS, and how does it minimize costs?
Open an interactive chat with Bash
Why are the other suggested options for AWS log management incorrect?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .