A company needs to build a code-signing solution using an AWS KMS asymmetric key and must store immutable evidence of key creation and usage for compliance and audit purposes.
Which solution meets these requirements?
AWS CloudTrail provides authoritative records of KMS key creation, origin, and usage. Enabling log file validation ensures tamper detection. S3 Object Lock in compliance mode enforces immutability, which is a core audit requirement cited in AWS Certified Security -- Specialty materials.
CloudWatch and DynamoDB do not provide immutable storage guarantees suitable for compliance evidence.
Referenced AWS Specialty Documents:
AWS Certified Security -- Specialty Official Study Guide
AWS CloudTrail Log File Validation
Amazon S3 Object Lock
Ashlyn
4 days agoMiss
10 days agoGlendora
15 days agoLillian
20 days agoStephania
25 days agoSerita
1 month agoMarta
1 month agoMarylou
2 months agoTammara
2 months agoBelen
2 months agoHaydee
2 months agoAnglea
3 months agoRosamond
3 months agoBerry
3 months ago