AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
An auditor reviewing CloudTrail wants to see individual S3 GetObject and PutObject API calls made against a specific bucket, which are not captured by default in a standard trail. Which type of CloudTrail event must be enabled to capture this activity?
- AManagement events
- BConfig events
- CInsight events
- DData events
Show answer & explanationAnswer & explanation
Correct answer: D. Data events
CloudTrail management events (enabled by default) record control plane operations like creating or deleting resources. Data events capture object-level operations such as S3 GetObject/PutObject or Lambda invocations, and must be explicitly enabled because of their high volume. Insight events detect unusual API call rate patterns, and 'Config events' is not a CloudTrail event type.
Why the other options are wrong
- A. Management events cover control plane actions like bucket creation, not object-level reads/writes.
- B. There is no CloudTrail event type called 'Config events'.
- C. Insight events detect anomalous API activity patterns, not specific object operations.
CloudTrail Data Events
CloudTrail events that record object-level operations (e.g., S3 GetObject/PutObject, Lambda Invoke) which are not logged by default.
- Must be explicitly enabled per resource
- Higher volume/cost than management events
- Management events are enabled by default and cover control plane actions
Memory trick: Data events = the 'data plane' details, off by default