AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard

A security engineer is tasked with monitoring for unauthorized modifications to critical AWS CloudFormation stacks that define the core infrastructure of a production environment. Any attempt to modify or delete these stacks must trigger an immediate alert to the security team. The solution needs to be robust, real-time, and target specific CloudFormation stack operations. Which AWS service combination provides the most effective and granular monitoring solution?

  1. AConfigure CloudWatch Alarms to monitor CloudFormation metrics for stack update/delete operations.
  2. BEnable AWS Config rules to detect changes in CloudFormation stacks and send notifications via SNS.
  3. CDeploy a Lambda function that periodically lists CloudFormation stacks and compares their current state to a baseline, then sends alerts if changes are detected.
  4. DCreate an Amazon EventBridge rule that captures CloudTrail events for `CloudFormation:UpdateStack` and `CloudFormation:DeleteStack` API calls, and targets an SNS topic.
Show answer & explanation

Correct answer: D. Create an Amazon EventBridge rule that captures CloudTrail events for `CloudFormation:UpdateStack` and `CloudFormation:DeleteStack` API calls, and targets an SNS topic.

AWS CloudTrail records all API calls, including `CloudFormation:UpdateStack` and `CloudFormation:DeleteStack`. Amazon EventBridge can be configured with rules to specifically capture these CloudTrail events in near real-time. By targeting an SNS topic with these EventBridge rules, an immediate alert can be sent to the security team for any unauthorized modifications or deletions of critical CloudFormation stacks.

Why the other options are wrong

  • A. CloudFormation metrics in CloudWatch are generally aggregate counts of operations, not granular enough to identify specific stack names or the initiating user for immediate, targeted alerts on critical stacks.
  • B. AWS Config tracks configuration changes, but its evaluations might not be real-time enough for 'immediate' alerts on critical operations. EventBridge directly processing CloudTrail events offers lower latency.
  • C. Periodically listing stacks and comparing baselines is reactive, not real-time. It would introduce significant latency between an unauthorized modification and the detection/alert, failing the 'immediate alert' requirement.

EventBridge for CloudFormation API Monitoring

Using Amazon EventBridge to capture specific AWS CloudTrail events related to CloudFormation stack operations (e.g., UpdateStack, DeleteStack) and trigger real-time alerts or automated actions.

  • CloudTrail records all API calls, including CloudFormation operations.
  • EventBridge provides near real-time filtering and routing of CloudTrail events.
  • Enables immediate alerts for critical infrastructure changes.
  • Provides granular control over which events trigger actions.

Memory trick: CloudTrail sees the stack change, EventBridge alerts the team.

More Domain 2: Logging and Monitoring questions