A healthcare provider is storing patient records in an Amazon S3 bucket. Due to HIPAA compliance requirements, all access to these records must be logged and monitored for suspicious activity. The SysOps administrator needs a solution that automatically detects unusual or potentially unauthorized access patterns to the S3 bucket and alerts the security team. Which AWS service is best suited for this task?
- AAmazon CloudWatch Logs with metric filters and alarms.
- BAWS Security Hub to aggregate S3 access logs.
- CAmazon GuardDuty with S3 Protection enabled.
- DAWS Config with a custom rule to monitor S3 bucket policies.
Show answer & explanationAnswer & explanation
Correct answer: C. Amazon GuardDuty with S3 Protection enabled.
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. With S3 Protection enabled, GuardDuty monitors S3 data events (via CloudTrail) and S3 access logs for suspicious activity like unusual data access patterns, attempts to delete logs, or access from known malicious IP addresses. It automatically generates findings and can alert the security team, making it ideal for detecting 'unusual or potentially unauthorized access patterns' to an S3 bucket.
Why the other options are wrong
- A. While CloudWatch Logs can collect S3 access logs, configuring metric filters and alarms to detect complex 'unusual or potentially unauthorized access patterns' would be highly complex to implement and maintain compared to the out-of-the-box intelligence provided by GuardDuty.
- B. Security Hub aggregates security findings from various AWS services, but it doesn't perform the actual detection of suspicious S3 access patterns itself. GuardDuty generates the findings that Security Hub would then aggregate.
- D. AWS Config monitors resource configurations and compliance, not real-time access patterns or suspicious activity. While it can check bucket policies, it won't detect unusual access attempts.
Amazon GuardDuty S3 Protection
Amazon GuardDuty's S3 Protection feature continuously monitors S3 data events and access logs for suspicious activity and generates security findings for potential threats.
- Detects unusual S3 access patterns.
- Monitors data events (CloudTrail) and access logs.
- Generates security findings and alerts.
- Fully managed threat detection service.
Memory trick: GuardDuty is the 'Guard' that 'Detects' the 'Duty' of watching S3.