AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard

A security architect is designing a multi-account logging strategy for an organization with strict regulatory requirements. All CloudTrail logs from member accounts must be aggregated into a central logging account. Furthermore, these aggregated logs must be encrypted at rest, protected against accidental deletion, and retained for ten years. Which configuration ensures these requirements are met with minimal operational overhead?

  1. AUse AWS Organizations to enable CloudTrail organization trail, deliver logs to a central S3 bucket, enable S3 server-side encryption with S3-managed keys (SSE-S3), and set a bucket lifecycle policy for retention.
  2. BConfigure CloudTrail in each member account to deliver logs to an S3 bucket in the central account, enable S3 default encryption with KMS, and configure S3 Object Lock in compliance mode.
  3. CSet up a custom AWS Lambda function in each member account to collect CloudTrail events and push them to an Amazon Kinesis Data Firehose in the central account, which then delivers to an S3 bucket with versioning enabled.
  4. DEnable CloudTrail in each member account to send logs to CloudWatch Logs, then use CloudWatch Logs subscriptions to forward logs to a central S3 bucket with Glacier Deep Archive for long-term retention.
Show answer & explanation

Correct answer: B. Configure CloudTrail in each member account to deliver logs to an S3 bucket in the central account, enable S3 default encryption with KMS, and configure S3 Object Lock in compliance mode.

Configuring CloudTrail in each member account to deliver logs to a central S3 bucket, enabling S3 default encryption with KMS, and configuring S3 Object Lock in compliance mode directly addresses all requirements. S3 default encryption with KMS ensures encryption at rest. S3 Object Lock in compliance mode provides immutable retention for the specified duration, preventing deletion or modification, and meets the 10-year retention. This approach is standard and has relatively low operational overhead compared to custom solutions.

Why the other options are wrong

  • A. While an organization trail centralizes logs, SSE-S3 is less secure than KMS for sensitive data. A lifecycle policy for retention doesn't provide the immutability guarantee of S3 Object Lock, which is often required for strict regulatory compliance against accidental deletion or modification.
  • C. This is an overly complex custom solution (Lambda, Kinesis Firehose) for a task that CloudTrail and S3 can handle natively. S3 versioning helps with accidental deletion but doesn't guarantee immutability in the same way Object Lock does for compliance.
  • D. Sending logs from CloudWatch Logs to S3 via subscriptions can be done, but CloudWatch Logs itself has its own retention policies, and this path adds an extra hop. More importantly, it doesn't inherently provide the immutability guarantee of S3 Object Lock, and Glacier Deep Archive is for archival, not necessarily the active protection against deletion required by 'protected against accidental deletion' in a strong compliance context.

Multi-Account CloudTrail Log Aggregation & Compliance

Aggregating CloudTrail logs from multiple accounts into a central S3 bucket with KMS encryption and S3 Object Lock in compliance mode for immutable, long-term, and secure retention.

  • CloudTrail provides audit logs of AWS API calls.
  • Centralized S3 bucket acts as the log repository.
  • KMS encryption ensures data encryption at rest.
  • S3 Object Lock (Compliance Mode) guarantees WORM and immutability for regulatory needs.

Memory trick: CloudTrail to S3, KMS encrypts, Object Lock keeps history, for ten years and beyond.

More Domain 2: Logging and Monitoring questions