AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A security auditor requires proof that all Amazon S3 buckets containing sensitive customer data are continuously monitored for unauthorized access and data exfiltration attempts. The solution must integrate with an existing security information and event management (SIEM) system for alerting and reporting. Which combination of AWS services should be implemented to meet this requirement effectively?

  1. AEnable S3 server access logging to an S3 bucket in a separate account, and configure CloudWatch Alarms on log patterns.
  2. BEnable S3 event notifications for 's3:ObjectCreated:*' and 's3:ObjectAccessed:*' events, send them to an SQS queue, and process with a Lambda function that forwards to the SIEM.
  3. CEnable S3 Data Events in AWS CloudTrail, send CloudTrail logs to CloudWatch Logs, and configure a CloudWatch Logs subscription filter to stream logs to the SIEM.
  4. DEnable S3 server access logging to an S3 bucket, configure Amazon EventBridge to trigger a Lambda function for log parsing, and send findings to the SIEM.
Show answer & explanation

Correct answer: C. Enable S3 Data Events in AWS CloudTrail, send CloudTrail logs to CloudWatch Logs, and configure a CloudWatch Logs subscription filter to stream logs to the SIEM.

S3 Data Events in CloudTrail capture API activity for S3 objects, including GetObject, PutObject, and DeleteObject. By sending these detailed logs to CloudWatch Logs and then using a subscription filter to stream them to a SIEM, you get comprehensive, near real-time monitoring of all object-level accesses for auditing and threat detection.

Why the other options are wrong

  • A. S3 server access logging is asynchronous and can have delivery delays, making it less suitable for continuous, near real-time monitoring and immediate alerting required for exfiltration attempts.
  • B. S3 event notifications are primarily for object creation/deletion/restore and can be configured for 'ObjectAccessed' but might not capture all granular API calls that CloudTrail Data Events provide, and managing many notifications can be complex.
  • D. While EventBridge and Lambda can process logs, S3 server access logs are not ideal for real-time due to delivery delays. CloudTrail provides more robust and immediate data events.

CloudTrail S3 Data Events

Records object-level API activity for Amazon S3 buckets, providing detailed logs of GetObject, PutObject, DeleteObject, and other object operations.

  • Captures detailed object-level API calls.
  • Essential for auditing data access and changes.
  • Can be integrated with CloudWatch Logs and SIEMs for real-time monitoring.

Memory trick: CloudTrail Data Events track every S3 object's journey.

More Domain 2: Logging and Monitoring questions