A DevOps team is managing an application that processes highly sensitive customer data. To meet compliance requirements, all access to this data must be logged, and any attempts at unauthorized access must trigger an immediate alert to the security team. The logs must be immutable and retained for seven years. Which combination of AWS services should the team use to meet these auditing and alerting requirements efficiently?
- AAmazon CloudWatch Logs and Amazon SNS
- BAWS CloudTrail, Amazon S3, and Amazon SNS
- CAWS GuardDuty and AWS Lambda
- DAWS Config and AWS Security Hub
Show answer & explanationAnswer & explanation
Correct answer: B. AWS CloudTrail, Amazon S3, and Amazon SNS
AWS CloudTrail records API calls and related events in your AWS account, providing a detailed log of all actions. These logs can be stored immutably in Amazon S3 with appropriate lifecycle policies for long-term retention. Amazon SNS can be configured to receive notifications from CloudTrail (via CloudWatch Alarms on specific CloudTrail events) for unauthorized access attempts, enabling immediate alerts.
Why the other options are wrong
- A. CloudWatch Logs stores logs, but CloudTrail specifically captures API activity for auditing. CloudWatch Alarms can trigger SNS, but CloudTrail is the source for API access events.
- C. GuardDuty detects threats but doesn't provide the comprehensive API access logs required for auditing, and Lambda would be a component for custom actions, not the primary logging and alerting mechanism itself.
- D. Config monitors resource configurations and Security Hub aggregates findings, but neither is designed for direct API access logging and immediate alerting on unauthorized attempts in the same way CloudTrail + SNS is.
AWS API Auditing
The process of recording, storing, and analyzing all API calls made to AWS services in an account to track activity, ensure accountability, and identify potential security incidents or compliance violations.
- Crucial for security and compliance.
- Provides a historical record of actions.
- Enables detection of unauthorized activity.
Memory trick: CloudTrail logs, S3 stores, SNS shouts - unauthorized access is caught!