AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard
A security auditor requires proof that all Amazon S3 buckets containing sensitive customer data have server access logging enabled and that these access logs are stored in a separate, secure S3 bucket in a different AWS account. The auditor also needs to continuously monitor for any S3 buckets that do not meet this logging standard. Which set of AWS services can address these requirements efficiently?
- AAWS CloudTrail logging S3 API calls, filtered by CloudWatch Logs metric filters for audit.
- BAWS Config with a custom rule, coupled with S3 bucket policies for cross-account access.
- CAmazon Macie for data discovery, with S3 Event Notifications to trigger Lambda functions.
- DAWS Organizations Service Control Policies (SCPs) to enforce logging, and S3 inventory reports for auditing.
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Config with a custom rule, coupled with S3 bucket policies for cross-account access.
AWS Config is designed for evaluating AWS resource configurations against desired states. A custom Config rule can be written to check if S3 server access logging is enabled and configured to store logs in the specified cross-account S3 bucket. S3 bucket policies are essential to allow cross-account log delivery. This provides continuous monitoring and compliance checking.
Why the other options are wrong
- A. CloudTrail logs *who* made *API calls* to S3, not whether server access logging is enabled for a bucket or where those logs are delivered. It doesn't check the *configuration state* of the bucket itself.
- C. Amazon Macie is for discovering and protecting sensitive data within S3, not for monitoring the configuration status of S3 server access logging. S3 Event Notifications are for actions on objects, not for auditing bucket configuration compliance.
- D. While SCPs can prevent certain actions (like disabling logging), they cannot proactively *ensure* that logging is enabled and configured correctly for all buckets. S3 inventory reports list objects, but not the detailed configuration state of server access logging for each bucket in a continuous manner.
S3 Access Logging Compliance
Ensuring S3 server access logging is enabled for sensitive buckets and logs are sent to a separate, secure cross-account S3 bucket, continuously monitored by AWS Config.
- S3 server access logging records requests to a bucket.
- Logs should be stored in a separate, secure bucket, ideally cross-account.
- AWS Config custom rules can continuously check this configuration.
- S3 bucket policies enable cross-account log delivery.
Memory trick: Config checks S3 logs are flowing right, cross-account, secure, and always bright.