AWS Certified DevOps Engineer – ProfessionalMonitoring and LoggingEasy
A security team requires that all API calls made to AWS services within their accounts are logged and immutable for auditing purposes. They need to analyze these logs to detect unusual activity, such as unauthorized API calls or changes to critical resources. The solution must ensure log integrity and long-term retention. Which AWS service is primarily responsible for fulfilling these requirements?
- AAmazon CloudWatch Logs
- BAWS CloudTrail
- CAWS Security Hub
- DAWS Config
Show answer & explanationAnswer & explanation
Correct answer: B. AWS CloudTrail
AWS CloudTrail is specifically designed to record all API calls and related events made to AWS services within an account. It provides event history, log file integrity validation, and integration with S3 for long-term storage, making it ideal for security auditing and compliance.
Why the other options are wrong
- A. CloudWatch Logs is for application and system logs, not primarily for AWS API call logging for auditing purposes, although CloudTrail can deliver logs to CloudWatch Logs.
- C. Security Hub aggregates security findings from various AWS services and third-party products, but it doesn't generate the API call logs itself.
- D. AWS Config tracks configuration changes of AWS resources, not individual API calls made to modify those resources.
AWS CloudTrail
A service that enables governance, compliance, operational auditing, and risk auditing of your AWS account by logging actions taken by a user, role, or an AWS service.
- Records API calls and other events.
- Logs are stored in S3 for long-term retention.
- Supports log file integrity validation.
Memory trick: CloudTrail Tracks All API Calls for Audit.