AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A single AWS account has a trail that records write-only management events and delivers logs to an S3 bucket. During an investigation, the security team must review AWS Management Console sign-in attempts, but no such entries appear in the recent log files. The team must collect this information without enabling any data events. What should a CloudOps engineer do to meet the requirement?
Modify the trail to log read-only management events in addition to write-only events.
Convert the trail to an organization trail and query the Organization Activity tab.
Create a new trail that captures data events for IAM and AWS STS only.
Enable CloudTrail Insights on the existing trail to automatically record console login anomalies.
Console sign-in attempts are logged by CloudTrail as read-only management events (eventSource signin.amazonaws.com, eventName ConsoleLogin). Because the existing trail captures only write-type management events, those sign-in records are being excluded. Updating the trail to include read-only (or all) management events causes CloudTrail to capture the required console login activity. Data events, CloudTrail Insights, organization trails, or CloudTrail Lake do not add the missing records when they are not being logged in the first place, and turning them on would either have no effect or add unnecessary cost.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are read-only management events in CloudTrail?
Open an interactive chat with Bash
What is the difference between management events and data events in CloudTrail?
Open an interactive chat with Bash
Why is enabling CloudTrail Insights insufficient for identifying sign-in attempts?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .