A company needs to build a code-signing solution using an AWS KMS asymmetric key and must store immutable evidence of key creation and usage for compliance and audit purposes.
Which solution meets these requirements?
AWS CloudTrail provides authoritative records of KMS key creation, origin, and usage. Enabling log file validation ensures tamper detection. S3 Object Lock in compliance mode enforces immutability, which is a core audit requirement cited in AWS Certified Security -- Specialty materials.
CloudWatch and DynamoDB do not provide immutable storage guarantees suitable for compliance evidence.
Referenced AWS Specialty Documents:
AWS Certified Security -- Specialty Official Study Guide
AWS CloudTrail Log File Validation
Amazon S3 Object Lock
Annamae
1 month agoDestiny
1 month agoMarge
1 month agoCheryl
2 months agoSalina
2 months agoAshlyn
2 months agoMiss
2 months agoGlendora
2 months agoLillian
3 months agoStephania
3 months agoSerita
3 months agoMarta
3 months agoMarylou
4 months agoTammara
4 months agoBelen
4 months agoHaydee
4 months agoAnglea
4 months agoRosamond
5 months agoBerry
5 months ago