Log inputs and outputs for troubleshooting.
They may contain personal data or secrets.
Choose two designs.
Mask or tokenize sensitive values before logging and manage access, retention, export, deletion, and audit as a separate data lifecycle.
Detailed explanation
Log confidentiality is improved.
Log confidentiality is improved.
Logs have their own lifecycle.
Logs have their own lifecycle.
Exposure and over-retention increase.
Exposure and over-retention increase.
Insider misuse and compromise remain possible.
Insider misuse and compromise remain possible.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 5.1のログ保護、データ最小化、アクセス管理を確認する。Expected result
調査用ログの有用性と個人情報・秘密の保護を両立できる。Key points
- Log protection
- Minimization
- Retention
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.