AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard

A global enterprise operates multiple AWS accounts across various regions and requires a centralized, immutable, and long-term archive for all security logs, including CloudTrail, VPC Flow Logs, and custom application logs. The solution must ensure that logs cannot be altered or deleted for seven years to meet regulatory compliance, and a dedicated security account should be used for storage. How should the security engineer design this logging architecture?

  1. AConfigure all log sources to publish to Amazon S3 buckets in the dedicated security account and enable S3 Versioning on the buckets.
  2. BUtilize AWS Organizations to consolidate all logs into a single S3 bucket in the dedicated security account, and enable S3 Object Lock in Compliance mode on the bucket.
  3. CSet up a centralized Amazon CloudWatch Logs account, ingest all logs into CloudWatch Logs, and configure retention policies for seven years.
  4. DStream all logs to Amazon Kinesis Data Firehose, which then delivers them to an S3 bucket in the dedicated security account with S3 Object Lock in Governance mode.
Show answer & explanation

Correct answer: B. Utilize AWS Organizations to consolidate all logs into a single S3 bucket in the dedicated security account, and enable S3 Object Lock in Compliance mode on the bucket.

AWS Organizations allows for centralized management of CloudTrail and other logs across accounts. S3 Object Lock in Compliance mode provides an unalterable and undeletable WORM (Write Once, Read Many) capability for the specified retention period, which is crucial for meeting strict regulatory compliance requirements for immutability over seven years. This combination ensures centralized, immutable, and long-term archival.

Why the other options are wrong

  • A. S3 Versioning protects against accidental deletion or overwrites but does not prevent malicious actors with appropriate permissions from intentionally deleting all versions of an object or the bucket itself, thus not meeting the immutability requirement for compliance.
  • C. CloudWatch Logs retention policies can handle the seven-year requirement, but CloudWatch Logs itself does not provide the strong immutability guarantees (WORM) that S3 Object Lock Compliance mode offers, which is often a specific requirement for regulatory compliance.
  • D. S3 Object Lock in Governance mode allows certain authorized users (with `s3:BypassGovernanceRetention` permission) to modify or delete objects even during the retention period, which does not fully satisfy the 'cannot be altered or deleted' requirement for strict regulatory compliance, where Compliance mode is often mandated.

S3 Object Lock (Compliance Mode)

A feature of Amazon S3 that prevents an object from being overwritten or deleted for a fixed amount of time or indefinitely, even by the root user. Compliance mode offers the strongest protection.

  • Ensures WORM (Write Once, Read Many) storage.
  • Prevents deletion or modification by any user, including root.
  • Critical for meeting strict regulatory compliance requirements for data immutability.

Memory trick: Object Lock's Compliance mode makes logs as solid as a rock.

More Domain 2: Logging and Monitoring questions