AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

An auditor needs to verify that CloudTrail log files stored in an S3 bucket have not been tampered with or deleted since they were delivered. Which CloudTrail feature should be enabled to support this verification?

  1. ALog file integrity validation
  2. BData event logging
  3. CCloudTrail Insights
  4. DMulti-Region trail configuration
Show answer & explanation

Correct answer: A. Log file integrity validation

CloudTrail log file integrity validation uses SHA-256 hashing and digitally signs digest files, allowing an auditor to determine whether a log file has been modified, deleted, or unchanged after CloudTrail delivered it to the S3 bucket.

Why the other options are wrong

  • B. Data event logging records object/function-level activity, unrelated to tamper detection.
  • C. CloudTrail Insights identifies unusual API activity patterns, not tampering detection.
  • D. Multi-Region trails capture events across regions but do not validate file integrity.

CloudTrail Log File Integrity Validation

A CloudTrail feature that uses SHA-256 hashing and digital signatures to create digest files, enabling detection of whether log files were altered or deleted after delivery.

  • Uses SHA-256 hashing and digest files
  • Digest files are digitally signed
  • Helps prove log files are unaltered for audits/forensics

Memory trick: Digest files are the tamper-evident seal on your logs.

More Security and Compliance questions