AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A large enterprise uses AWS Organizations with multiple accounts. They require a centralized and immutable log of all API calls and configuration changes across all accounts for compliance and auditing purposes. The logs must be encrypted at rest and in transit, and retained for seven years. Which logging solution should the security architect design to meet these requirements?

  1. AEnable AWS Config in all accounts, and aggregate findings to a central S3 bucket in a logging account.
  2. BConfigure individual CloudTrail trails in each account, sending logs to an S3 bucket in the same account with a lifecycle policy.
  3. CDeploy Amazon Kinesis Data Firehose in each account to stream API call data to Amazon OpenSearch Service in a central account for analysis and long-term storage.
  4. DCreate an organization-wide CloudTrail trail, configured to deliver logs to a central, encrypted S3 bucket in a dedicated logging account with a WORM policy, and enable S3 Server-Side Encryption with KMS (SSE-KMS) and S3 bucket policies.
Show answer & explanation

Correct answer: D. Create an organization-wide CloudTrail trail, configured to deliver logs to a central, encrypted S3 bucket in a dedicated logging account with a WORM policy, and enable S3 Server-Side Encryption with KMS (SSE-KMS) and S3 bucket policies.

An organization-wide CloudTrail trail aggregates logs from all member accounts to a single S3 bucket. Using SSE-KMS ensures encryption at rest, and a WORM (Write Once, Read Many) policy on the S3 bucket ensures immutability for compliance, meeting all specified requirements.

Why the other options are wrong

  • A. AWS Config tracks resource configurations, not all API calls, and aggregation to S3 doesn't inherently provide immutable storage without additional S3 features.
  • B. This approach is decentralized and would be difficult to manage for a large enterprise; it also doesn't explicitly ensure immutability or centralized encryption key management.
  • C. While Kinesis Firehose and OpenSearch can handle logging, this setup doesn't inherently provide immutability or explicitly cover all API calls across accounts as comprehensively as CloudTrail, and introduces more complexity for simple long-term archival.

Organization-wide CloudTrail

A single CloudTrail trail created in the management account that logs events from all AWS accounts in an organization.

  • Centralized logging for AWS Organizations
  • Captures API calls and configuration changes
  • Simplifies compliance and auditing across accounts

Memory trick: One trail for all, secure and never fall.

More Domain 2: Logging and Monitoring questions