AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A security engineer has configured an AWS WAF Web ACL to protect a public-facing web application. The engineer needs to monitor WAF logs for specific attack patterns (e.g., SQL injection attempts, cross-site scripting) and receive real-time alerts when these patterns are detected. The logs should be stored centrally for auditing and forensics. Which solution provides the most effective way to meet these requirements?

  1. APublish WAF metrics to CloudWatch and create alarms on metric thresholds for attack types.
  2. BEnable WAF logging and configure it to send logs to a CloudWatch Logs log group. Create CloudWatch Logs subscription filters to send matching log events to a Lambda function for alerting and to an S3 bucket for archival.
  3. CConfigure WAF to send logs to an S3 bucket, then use CloudWatch Alarms on S3 object creation to trigger a Lambda function for pattern matching and alerting.
  4. DIntegrate WAF with AWS Config to monitor WAF rule changes and trigger alerts for non-compliant configurations.
Show answer & explanation

Correct answer: B. Enable WAF logging and configure it to send logs to a CloudWatch Logs log group. Create CloudWatch Logs subscription filters to send matching log events to a Lambda function for alerting and to an S3 bucket for archival.

AWS WAF can send its detailed logs directly to a CloudWatch Logs log group. From CloudWatch Logs, subscription filters can be configured to match specific attack patterns within the log events. These matching events can then be streamed in real-time to a Lambda function for custom alerting (e.g., sending to Slack, PagerDuty) and simultaneously to an S3 bucket for long-term archival and forensic analysis.

Why the other options are wrong

  • A. WAF metrics in CloudWatch provide aggregated counts (e.g., blocked requests), but they lack the detailed log event data needed to identify *specific attack patterns* (e.g., the exact SQL injection string) for granular alerting and forensic analysis.
  • C. While S3 can store logs, processing them in real-time for specific patterns using Lambda triggered by S3 object creation is less efficient and has higher latency than using CloudWatch Logs subscription filters for real-time event streaming.
  • D. AWS Config monitors WAF *rule changes* and configurations, not the actual *attack patterns* detected by WAF during runtime. This doesn't meet the requirement for monitoring attack patterns and real-time alerts.

AWS WAF Logging to CloudWatch Logs with Filters

A method to capture detailed AWS WAF traffic logs, send them to Amazon CloudWatch Logs, and use CloudWatch Logs subscription filters to stream specific log patterns for real-time analysis and alerting.

  • WAF provides detailed logs of requests it processes.
  • CloudWatch Logs offers centralized log storage and analysis.
  • Subscription filters enable real-time pattern matching and streaming.
  • Integrates with Lambda for custom alerting and S3 for archiving.

Memory trick: WAF logs to CloudWatch, filters trigger Lambda to shout for patterns.

More Domain 2: Logging and Monitoring questions