AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementHard
A large enterprise with a complex AWS environment is migrating applications that require robust, centralized logging and auditing of all AWS API calls and related events across all accounts in their AWS Organization. They need to ensure that the audit logs are immutable, encrypted, and stored in a central, secure S3 bucket that cannot be tampered with, even by root users of individual member accounts. Which solution should the security architect recommend?
- AEnable AWS Config recorder in all accounts and aggregate findings to a central account.
- BConfigure individual CloudTrail trails in each member account, delivering logs to a dedicated S3 bucket in each account.
- CUse AWS Security Hub to aggregate security findings and CloudWatch Logs for event storage.
- DImplement a CloudTrail organization trail delivered to a central S3 bucket with S3 Object Lock enabled in compliance mode.
Show answer & explanationAnswer & explanation
Correct answer: D. Implement a CloudTrail organization trail delivered to a central S3 bucket with S3 Object Lock enabled in compliance mode.
A CloudTrail organization trail centralizes logging of all API activity from all member accounts to a single S3 bucket. Enabling S3 Object Lock in compliance mode on this central bucket ensures that logs are immutable and cannot be deleted or overwritten, even by the root user, addressing the immutability and tamper-proof requirements.
Why the other options are wrong
- A. AWS Config records resource configuration changes, not all API calls, and does not provide immutable storage against root user actions by default.
- B. Individual trails are cumbersome to manage across many accounts and don't provide central immutable storage that resists root user tampering without additional controls.
- C. Security Hub aggregates findings, and CloudWatch Logs stores logs, but neither inherently provides immutable storage against root user actions or comprehensive API call logging across an organization by itself.
CloudTrail Organization Trails with S3 Object Lock
A centralized logging solution for AWS Organizations that delivers immutable audit logs to a secure S3 bucket.
- CloudTrail organization trails capture all AWS API activity across all member accounts.
- S3 Object Lock in compliance mode prevents deletion or modification of objects for a specified retention period, even by the root user.
- Ensures audit trail integrity and non-repudiation for compliance.
Memory trick: Think of a 'master ledger' (CloudTrail) locked inside a 'vault' (S3 Object Lock) that no one, not even the owner, can alter.