AWS Certified DevOps Engineer – ProfessionalMonitoring and LoggingHard

A security team needs to monitor access to sensitive data stored in Amazon S3 buckets. They require real-time alerts for specific access patterns, such as an unusual number of 'GetObject' requests from an unapproved IP range, or a 'DeleteObject' operation on a critical bucket. The solution must be highly available and integrate with existing security operations tools.

  1. AEnable S3 server access logging, deliver logs to a separate S3 bucket, and use AWS Lambda functions to analyze logs and send alerts.
  2. BConfigure CloudTrail data events for S3, send logs to CloudWatch Logs, and create CloudWatch Alarms based on metric filters for specific events.
  3. CUse Amazon Macie to detect sensitive data and automatically generate alerts for unusual access patterns.
  4. DIntegrate S3 with AWS Security Hub to aggregate findings and trigger alerts for suspicious activities.
Show answer & explanation

Correct answer: B. Configure CloudTrail data events for S3, send logs to CloudWatch Logs, and create CloudWatch Alarms based on metric filters for specific events.

CloudTrail data events capture S3 object-level API actions (like GetObject, DeleteObject). Sending these to CloudWatch Logs allows for real-time analysis using metric filters to identify specific patterns (e.g., source IP, event name). CloudWatch Alarms can then trigger immediate notifications, fulfilling the real-time alerting requirement and integrating with existing tools via SNS.

Why the other options are wrong

  • A. S3 server access logs are eventually consistent and not suitable for real-time alerting. They also don't provide the same level of detail for API calls as CloudTrail.
  • C. Amazon Macie is primarily for discovering and protecting sensitive data, not for real-time monitoring of all S3 API access patterns and alerting based on custom rules.
  • D. Security Hub aggregates findings but doesn't perform the real-time log analysis and custom pattern detection needed for specific S3 access patterns. It relies on other services to generate those findings.

CloudTrail Data Events for S3 Monitoring

AWS CloudTrail can record S3 object-level API actions (data events), providing detailed audit trails for access to sensitive data within S3 buckets.

  • Captures 'GetObject', 'PutObject', 'DeleteObject', etc.
  • Provides source IP, user identity, timestamp, and bucket details.
  • Essential for security, compliance, and operational troubleshooting.
  • Can be integrated with CloudWatch Logs for real-time alerting.

Memory trick: CloudTrail's 'S3 Data Watch' with Alarms catches bad actors in real-time.

More Monitoring and Logging questions