An organization is investigating a potential insider threat where an IAM user is suspected of unauthorized access to sensitive S3 buckets. The security team needs to analyze the user's historical access patterns to S3, including successful and failed attempts, to determine the extent of the unauthorized activity. They also need to identify any unusual access locations or times. Which AWS service combination is most effective for this detailed behavioral analysis?
- AAmazon Inspector and Amazon Detective.
- BAmazon Macie and AWS Config.
- CAmazon GuardDuty and AWS Security Hub.
- DAWS CloudTrail S3 data events and Amazon Athena.
Show answer & explanationAnswer & explanation
Correct answer: D. AWS CloudTrail S3 data events and Amazon Athena.
AWS CloudTrail with S3 data events enabled logs all object-level API activity (e.g., GetObject, PutObject) for S3 buckets. When these logs are stored in S3, Amazon Athena can be used to query them efficiently, allowing for detailed analysis of access patterns, including specific users, actions, times, and source IPs, which is crucial for behavioral analysis.
Why the other options are wrong
- A. Inspector assesses vulnerabilities and compliance on EC2 instances, and Detective helps analyze and visualize security data, but it primarily uses GuardDuty, VPC Flow Logs, and CloudTrail management events, not raw S3 data events for deep behavioral analysis of S3 access patterns.
- B. Macie focuses on sensitive data discovery and classification within S3, while Config tracks resource configuration changes. Neither is designed for detailed, historical access pattern analysis.
- C. GuardDuty detects anomalies and threats, and Security Hub aggregates findings, but neither provides the raw, detailed S3 object-level access logs needed for historical behavioral analysis.
S3 Access Behavioral Analysis
Analyzing an IAM user's S3 access patterns requires capturing object-level API activity via CloudTrail data events. Amazon Athena can then query these logs in S3 for deep behavioral insights into successful, failed, and unusual access attempts.
- CloudTrail data events record object-level S3 actions.
- Logs are stored in S3 for long-term retention.
- Athena enables SQL queries over S3 data for analysis.
Memory trick: CloudTrail records the story, and Athena helps you read between the lines of S3 access.