AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy
A security engineer is tasked with establishing a centralized logging solution for an organization's AWS environment. The solution must collect logs from various AWS services, including CloudTrail, VPC Flow Logs, and S3 access logs, and then send them to a security information and event management (SIEM) system for analysis. The engineer needs to ensure that the log data is securely transported and that the solution is scalable and cost-effective. Which AWS service is most appropriate for aggregating and delivering these diverse log sources to the SIEM?
- AAmazon Kinesis Data Firehose
- BAmazon SQS
- CAWS CloudWatch Logs
- DAWS Lambda
Show answer & explanationAnswer & explanation
Correct answer: A. Amazon Kinesis Data Firehose
Amazon Kinesis Data Firehose is specifically designed for delivering real-time streaming data to destinations like S3, Redshift, Splunk, and other custom HTTP endpoints, making it ideal for aggregating diverse log sources and delivering them to a SIEM. It handles scaling and data transformation, simplifying the process.
Why the other options are wrong
- B. Amazon SQS is a message queuing service, not designed for direct, continuous streaming data delivery to a SIEM system.
- C. CloudWatch Logs is primarily for collecting and monitoring logs from EC2 instances, Lambda, and other AWS services, but Firehose is better suited for direct delivery to external SIEMs at scale.
- D. AWS Lambda can be used for custom log processing, but Firehose provides a managed service for direct delivery without needing to write and maintain custom code for aggregation and transport.
Amazon Kinesis Data Firehose
A fully managed service for delivering real-time streaming data to destinations like S3, Redshift, Splunk, and other HTTP endpoints.
- Automatically scales to match data throughput.
- Supports data transformation via AWS Lambda.
- Integrates with various AWS services as sources and destinations.
Memory trick: Firehose funnels logs, fast and full, to your SIEM system's pool.