AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard

A company is migrating its on-premises applications to AWS. They use custom applications that generate security-relevant logs in various formats (JSON, plain text, syslog) on EC2 instances. The security team needs to centralize these logs into a single, queryable repository for threat hunting and compliance auditing. The solution must support real-time ingestion, flexible querying capabilities, and long-term archival. Which combination of AWS services would best meet these requirements?

  1. AAWS Systems Manager Agent for log collection, Amazon S3 for raw storage, and AWS Glue for ETL and Amazon Redshift for querying.
  2. BAWS CloudWatch Logs for ingestion, Amazon Kinesis Data Firehose for transformation, and Amazon OpenSearch Service for real-time querying and analysis.
  3. CAmazon Kinesis Data Firehose for ingestion, Amazon S3 for archival, and Amazon Athena for querying.
  4. DAWS CloudWatch Logs for ingestion and storage, with CloudWatch Logs Insights for querying.
Show answer & explanation

Correct answer: B. AWS CloudWatch Logs for ingestion, Amazon Kinesis Data Firehose for transformation, and Amazon OpenSearch Service for real-time querying and analysis.

This combination provides a robust, scalable, and flexible solution. CloudWatch Logs Agent (or Kinesis Agent) collects logs. Kinesis Data Firehose can transform logs before delivery. OpenSearch Service provides powerful real-time search, analysis, and visualization capabilities for diverse log formats, while CloudWatch Logs can also act as an ingestion point, and Firehose can deliver to OpenSearch.

Why the other options are wrong

  • A. Systems Manager Agent can collect logs, and S3/Glue/Redshift can work, but Redshift is more for structured data warehousing and less optimized for real-time, ad-hoc, semi-structured log analysis and visualization compared to OpenSearch Service.
  • C. Athena on S3 is excellent for ad-hoc querying of archived data but less suitable for real-time, interactive threat hunting and visualization that OpenSearch Service provides.
  • D. While CloudWatch Logs and Insights offer querying, they might not be as performant or flexible for diverse, high-volume real-time threat hunting across custom formats as OpenSearch Service.

Centralized Custom Log Management

Collecting diverse custom logs from EC2, centralizing them for real-time querying, analysis, and long-term archival.

  • Requires flexible ingestion for varied formats
  • Needs real-time search and analytics for threat hunting
  • Long-term, cost-effective archival is crucial

Memory trick: Gather, transform, then search and store.

More Domain 2: Logging and Monitoring questions