A new regulation requires that all data access events for sensitive data stored in Amazon S3 buckets must be logged, and these logs must be centrally stored in a separate, immutable S3 bucket in another AWS account for at least 10 years. The SysOps administrator needs to implement this solution with minimal cost and operational overhead. Which solution meets these requirements?
- AImplement custom Lambda functions to capture S3 object access events, push logs to Amazon Kinesis Firehose, and then store them in the central S3 bucket with S3 Object Lock.
- BConfigure S3 Event Notifications to trigger a Lambda function that writes access details to Amazon DynamoDB, then use DynamoDB Streams to replicate to the central S3 bucket with S3 Object Lock.
- CEnable AWS CloudTrail data events for S3 for all sensitive data buckets, configure CloudTrail to deliver logs to the central S3 bucket in the other account, and enable S3 Object Lock on the central bucket.
- DEnable S3 server access logging for all sensitive data buckets, configure logs to be delivered to the central S3 bucket in the other account, and enable S3 Object Lock on the central bucket.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable AWS CloudTrail data events for S3 for all sensitive data buckets, configure CloudTrail to deliver logs to the central S3 bucket in the other account, and enable S3 Object Lock on the central bucket.
AWS CloudTrail data events for S3 specifically capture object-level API activity (e.g., `GetObject`, `PutObject`, `DeleteObject`), which is exactly what's needed for 'all data access events'. CloudTrail can be configured to deliver logs to an S3 bucket in a different account, fulfilling the central storage requirement. Enabling S3 Object Lock on the destination S3 bucket ensures immutability and long-term retention (10 years) for compliance, while CloudTrail and S3 are cost-effective and have minimal operational overhead for this purpose.
Why the other options are wrong
- A. Using custom Lambda functions adds significant operational overhead, complexity, and cost compared to the native integration of CloudTrail, which is designed for this audit logging purpose.
- B. This solution is overly complex and expensive for simple logging and archiving. DynamoDB is a NoSQL database, not primarily for long-term audit log storage, and the replication process adds unnecessary layers.
- D. S3 server access logging captures basic access logs, but CloudTrail data events provide a more detailed, auditable, and compliance-focused record of API calls, which is generally preferred for regulatory requirements for 'data access events'.
S3 Data Event Auditing
Use AWS CloudTrail data events for S3 to capture object-level API activity, delivering logs to a cross-account immutable S3 bucket with Object Lock for compliance.
- CloudTrail data events log S3 object operations.
- Logs can be delivered to S3 in another account.
- S3 Object Lock ensures log immutability.
- Cost-effective and low operational overhead.
Memory trick: CloudTrail tracks every 'Click', S3 Object Lock makes logs 'Stuck'.