AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard
A security engineer needs to monitor for any attempts to modify or delete a critical AWS CloudFormation stack that defines the network infrastructure. This monitoring solution must provide immediate alerts to the security team. Which approach should the engineer implement?
- ACreate an AWS Config rule to check for CloudFormation stack drift and send notifications via SNS.
- BConfigure AWS Systems Manager Change Manager to approve or reject CloudFormation stack changes.
- CEnable Amazon GuardDuty to monitor for unusual API calls related to CloudFormation and generate findings.
- DSet up a CloudWatch Events rule (now Amazon EventBridge) to detect specific CloudFormation API calls and trigger an SNS topic.
Show answer & explanationAnswer & explanation
Correct answer: D. Set up a CloudWatch Events rule (now Amazon EventBridge) to detect specific CloudFormation API calls and trigger an SNS topic.
Amazon EventBridge (formerly CloudWatch Events) can directly monitor CloudTrail events for specific API calls. By targeting CloudFormation API calls like `UpdateStack` or `DeleteStack`, an EventBridge rule can trigger an SNS topic for immediate alerts, providing real-time notification of critical infrastructure changes.
Why the other options are wrong
- A. AWS Config can detect CloudFormation stack drift (differences between template and deployed resources), but it's for auditing *state*, not for real-time alerts on *API calls* that initiate changes or deletions. The requirement is for immediate alerts on *attempts* to modify/delete.
- B. Systems Manager Change Manager is for managing and approving changes to operational items, not for real-time detection and alerting on API calls. It's a change control workflow, not a monitoring and alerting system for API activity.
- C. GuardDuty detects unusual or malicious API activity, but it's a threat detection service. While it might flag *suspicious* CloudFormation activity, it doesn't provide direct, guaranteed alerts for *any* modification or deletion attempt, which is a specific and critical operational security requirement.
EventBridge for CloudFormation API Monitoring
Using Amazon EventBridge to monitor AWS CloudTrail events for critical CloudFormation API calls (e.g., UpdateStack, DeleteStack) and trigger immediate alerts via SNS.
- EventBridge reacts to events from AWS services.
- CloudTrail events include all API calls to CloudFormation.
- Rules can filter for specific `eventName` patterns.
- SNS topics provide immediate, flexible notification options.
Memory trick: EventBridge watches CloudFormation's call, 'Update' or 'Delete' will warn us all.