CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security architect is designing a new logging solution for a highly regulated environment. All logs must be immutable and tamper-proof to meet compliance requirements. Additionally, access to these logs must be restricted to specific audit teams and retained for a minimum of seven years. Which combination of cloud storage features and access controls best meets these requirements?

  1. ABlock storage with snapshots and an access control list (ACL) restricting write access.
  2. BFile storage with versioning and security groups controlling network access.
  3. CStandard object storage with bucket policies enforcing read-only access for audit teams.
  4. DObject storage with Write Once Read Many (WORM) enabled and an IAM policy granting read-only access to a specific group.
Show answer & explanation

Correct answer: D. Object storage with Write Once Read Many (WORM) enabled and an IAM policy granting read-only access to a specific group.

WORM (Write Once Read Many) or object lock features ensure immutability and tamper-proofing, making logs unalterable for the retention period. IAM policies are the standard and most granular way to grant read-only access to specific user groups in cloud object storage, satisfying both compliance and access control needs.

Why the other options are wrong

  • A. Block storage is typically used for disks attached to VMs, not for highly scalable, immutable log storage. Snapshots provide point-in-time recovery but not immutability, and ACLs are less granular than IAM policies.
  • B. File storage is generally not designed for WORM compliance for logs. Versioning helps with accidental deletions but doesn't guarantee immutability against malicious tampering, and security groups control network access, not data access permissions.
  • C. Standard object storage alone does not guarantee immutability; bucket policies only control permissions, not data alteration.

WORM Storage for Logs

Cloud object storage configured with Write Once Read Many (WORM) or Object Lock to ensure data immutability for compliance.

  • Prevents alteration or deletion for a set period.
  • Crucial for regulatory compliance (e.g., financial, healthcare).
  • Often combined with IAM for granular access control.

Memory trick: WORM locks logs, IAM lets auditors look.

More Security questions