AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium

A security engineer is investigating a potential compromise of an Amazon S3 bucket where sensitive data might have been exfiltrated. The engineer needs to identify the exact objects that were accessed, the IAM principal that accessed them, and the time of access to reconstruct the attack timeline. The S3 bucket has S3 server access logging enabled, delivering logs to another S3 bucket. Which AWS service should the engineer use to efficiently query these S3 access logs to build a timeline of accessed objects?

  1. AAmazon CloudWatch Logs Insights.
  2. BAmazon Athena.
  3. CAWS CloudTrail Event History.
  4. DAmazon Macie.
Show answer & explanation

Correct answer: B. Amazon Athena.

Amazon Athena is a serverless interactive query service that makes it easy to analyze data directly in Amazon S3 using standard SQL. S3 server access logs are stored in S3, making Athena the ideal tool for efficiently querying these logs to identify accessed objects, principals, and timestamps for timeline reconstruction.

Why the other options are wrong

  • A. CloudWatch Logs Insights queries logs in CloudWatch Logs, but S3 server access logs are typically delivered to S3, not CloudWatch Logs by default.
  • C. CloudTrail Event History provides API call logs (management events), but S3 server access logs provide object-level access details (data events) which are more granular for exfiltration analysis.
  • D. Amazon Macie focuses on sensitive data discovery and classification within S3, not on querying raw access logs for forensic timeline reconstruction.

S3 Access Log Analysis with Athena

S3 server access logs record detailed requests made to an S3 bucket. Amazon Athena provides a powerful, serverless SQL query engine to efficiently analyze these logs directly in S3, crucial for forensic investigations of data access and exfiltration.

  • S3 server access logs record every request to a bucket.
  • Logs are stored in S3.
  • Athena enables SQL queries for fast analysis of S3 data.

Memory trick: Athena is your SQL-powered librarian for S3 access logs.

More Domain 1: Incident Response questions