A security engineer needs to establish a robust monitoring solution for cross-account administrative activities within an AWS Organization. The solution must ensure that all API calls made by IAM users and roles in every account are captured, immutable, and retained for 10 years for forensic analysis. Furthermore, any attempts to disable CloudTrail logging or delete logs must generate immediate alerts. Which combination of services should the engineer implement?
- AConfigure individual CloudTrail trails in each account, sending logs to an S3 bucket in the same account with S3 Object Lock, and CloudWatch Alarms for CloudTrail events.
- BUse Amazon EventBridge to capture CloudTrail events and forward them to a Lambda function for processing and storage in a custom database, with custom alerts.
- CDeploy an organization trail in the management account, configured to log to a central S3 bucket in a logging account with S3 Object Lock in Compliance mode, and configure CloudWatch Alarms on the central CloudTrail log group for specific events.
- DEnable AWS Config in all accounts to monitor for CloudTrail changes and send findings to Security Hub, with S3 lifecycle policies for log retention.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploy an organization trail in the management account, configured to log to a central S3 bucket in a logging account with S3 Object Lock in Compliance mode, and configure CloudWatch Alarms on the central CloudTrail log group for specific events.
An organization trail centralizes all API calls from all accounts. S3 Object Lock in Compliance mode ensures immutability and long-term retention, even against root user actions. CloudWatch Alarms on the central CloudTrail log group can detect tampering attempts (e.g., StopLogging, DeleteTrail events) and trigger immediate alerts, fulfilling all requirements.
Why the other options are wrong
- A. Individual trails are not centralized for an organization, making forensic analysis cumbersome. While S3 Object Lock helps, a centralized approach is better for cross-account monitoring.
- B. While possible, this custom solution introduces significant operational overhead, maintenance, and potential for misconfiguration, and doesn't inherently guarantee immutability as strongly as S3 Object Lock, nor does it provide a native 'disable CloudTrail' alert as easily as CloudWatch Alarms on CloudTrail events.
- D. AWS Config monitors resource configurations, not the API calls themselves, and relies on CloudTrail for its event source. It's not the primary mechanism for capturing all API calls or ensuring immutability of the logs themselves, and Security Hub aggregates, it doesn't log.
Cross-Account CloudTrail Monitoring
Centralized, immutable logging and alerting for all API activities across multiple AWS accounts in an organization.
- Organization trail for centralization
- S3 Object Lock for immutability and retention
- CloudWatch Alarms for tampering detection
Memory trick: One trail, one lock, one alarm, keeps the org safe from harm.