AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A company is storing highly sensitive financial transaction records in an Amazon S3 bucket. A new regulation requires that all data access events for this bucket must be logged, including who accessed what, when, and from where. These logs must be retained for 10 years and be auditable for compliance purposes. Which AWS service should be enabled and configured specifically for this S3 bucket to meet these requirements?

  1. AAWS CloudTrail with S3 data events logging enabled.
  2. BAmazon S3 server access logging.
  3. CAWS Config with a custom rule for S3 bucket access.
  4. DAmazon Macie with S3 data classification.
Show answer & explanation

Correct answer: A. AWS CloudTrail with S3 data events logging enabled.

AWS CloudTrail, when configured with S3 data events logging, captures all S3 object-level API activity (e.g., GetObject, PutObject, DeleteObject), providing details on who, what, when, and from where. CloudTrail logs can be delivered to an S3 bucket for long-term retention and are immutable for auditing purposes.

Why the other options are wrong

  • B. S3 server access logging records requests made to an S3 bucket, but the logs are less detailed than CloudTrail data events and are delivered as best-effort, potentially with delays, making them less suitable for strict compliance audits.
  • C. AWS Config monitors resource configurations for compliance, not individual data access events.
  • D. Macie focuses on discovering and classifying sensitive data, not on logging individual data access events for auditing.

S3 Data Event Auditing

S3 data event auditing involves logging all object-level API activities within an Amazon S3 bucket to meet compliance, security, and operational requirements.

  • Enabled via AWS CloudTrail data events.
  • Captures GetObject, PutObject, DeleteObject, etc.
  • Records caller identity, timestamp, IP address, and resource.
  • Logs are stored in an S3 bucket for long-term retention.

Memory trick: CloudTrail Data Events: Who, What, When, Where for S3 Objects.

More Security and Compliance questions