
Answer-first summary for fast verification
Answer: Use an isolated forensic account to store artifacts in an S3 bucket with S3 Object Lock enabled.
To protect and preserve forensic artifacts, it is crucial to use an isolated forensic account, which enhances security by isolating sensitive data. Storing these artifacts in an S3 bucket with S3 Object Lock ensures that the data cannot be altered or deleted, providing immutable storage for forensic evidence.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
No comments yet.
In the event of a compromised AWS environment, how would you protect and preserve forensic artifacts using AWS services? Provide a detailed plan involving S3, S3 Object Lock, and isolated forensic accounts.
A
Store artifacts in a standard S3 bucket with versioning enabled.
B
Use an isolated forensic account to store artifacts in an S3 bucket with S3 Object Lock enabled.
C
Replicate artifacts to another region using S3 replication and enable S3 Object Lock.
D
Archive artifacts in an S3 Glacier bucket within the same account.