312-39 SOC For Cloud Environments Practice Question
Which TWO settings should you prioritize when configuring AWS CloudTrail for a robust security audit trail?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable global service events
Enabling global service events and log file integrity ensure that all actions are captured and that logs remain tamper-proof.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable global service events
Why this is correct
Ensures events from all regions are captured.
- ✓
Enable Log File Integrity
Why this is correct
Ensures that log files have not been modified or deleted.
- ✗
Disable SNS notifications
Why it's wrong here
Notifications are critical for timely incident response.
- ✗
Limit logs to one region
Why it's wrong here
Limiting to one region ignores threats in other regions.
- ✗
Encrypt logs with a public key
Why it's wrong here
Logs should be encrypted with KMS, not a public key.
About these practice questions
This 312-39 question is part of Courseiva's 201-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This 312-39 practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 312-39 exam.