AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium
A security analyst needs to create a custom CloudWatch alarm that triggers when an AWS Identity and Access Management (IAM) root user performs any API activity. This alarm should notify the security team immediately via email. Which of the following combinations of AWS services and configurations will achieve this goal?
- AEnable AWS Config rules to detect root user activity and integrate with CloudWatch Events for SNS notifications.
- BConfigure a CloudWatch Logs Metric Filter for CloudTrail events with 'userIdentity.type': 'Root' and create a CloudWatch Alarm publishing to an SNS topic.
- CSet up an Amazon EventBridge rule that filters CloudTrail events for root user activity and targets an SQS queue which triggers a Lambda function for email.
- DCreate an AWS CloudTrail trail with `isRootUser` set to true, and configure a custom metric in CloudWatch based on this trail, then set an alarm.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure a CloudWatch Logs Metric Filter for CloudTrail events with 'userIdentity.type': 'Root' and create a CloudWatch Alarm publishing to an SNS topic.
To detect root user activity, CloudTrail logs are essential. These logs can be sent to CloudWatch Logs, where a Metric Filter can be applied to specifically count events where 'userIdentity.type' is 'Root'. A CloudWatch Alarm can then be configured on this metric, publishing notifications to an SNS topic for email alerts.
Why the other options are wrong
- A. AWS Config is for resource configuration changes and compliance, not directly for monitoring real-time API call events from CloudTrail for specific user types. While it can detect some root activity, a direct metric filter on CloudTrail logs is more precise for API calls.
- C. While EventBridge can filter CloudTrail events, sending to SQS then Lambda for email is an overly complex and less direct path compared to a CloudWatch Alarm directly to SNS for a simple metric trigger.
- D. CloudTrail does not have a configurable `isRootUser` setting for a trail itself. Root user activity is an attribute within the CloudTrail event. You need a metric filter to extract this information from the logs.
CloudWatch Alarm for Root Activity
A configuration using CloudTrail, CloudWatch Logs, Metric Filters, and SNS to alert on IAM root user API activity.
- CloudTrail records root user API calls.
- CloudWatch Logs ingests CloudTrail events.
- Metric Filter extracts specific patterns (e.g., 'userIdentity.type': 'Root').
- CloudWatch Alarm triggers based on the metric, sending notifications via SNS.
Memory trick: Root's API calls, through CloudTrail's sight, become CloudWatch metrics, sparking SNS light.