Audit logs contain sensitive input summaries.
Only auditors need necessary portions.
Choose two practices.
Limit access by role, purpose, period, and fields, review it regularly, and record viewing, export, sharing, and deletion with alerts for suspicious use.
Detailed explanation
Only necessary access remains.
Only necessary access remains.
Log use is itself auditable.
Log use is itself auditable.
Sensitive content is broadly exposed.
Sensitive content is broadly exposed.
Stale permissions remain.
Stale permissions remain.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 5.2の監査ログ、最小権限、アクセスレビューを確認する。Expected result
監査ログ自身の機密性と閲覧証跡を管理できる。Key points
- Access review
- Least privilege
- Audit
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.