A security architect is designing a logging solution for a highly regulated financial application hosted on AWS. The application generates sensitive audit logs that must be immutable and retained for seven years to meet compliance requirements. The solution must prevent any deletion or modification of these logs, even by root users, for the entire retention period. Which AWS service and configuration combination should the architect choose?
- AAmazon S3 with versioning enabled and a lifecycle policy to transition to Glacier.
- BAWS CloudWatch Logs with a retention policy and an IAM policy denying 'logs:DeleteLogGroup'.
- CAmazon Kinesis Data Firehose delivering logs to an S3 bucket with a bucket policy denying 's3:DeleteObject'.
- DAmazon S3 with S3 Object Lock configured in Compliance mode for the required retention period.
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon S3 with S3 Object Lock configured in Compliance mode for the required retention period.
S3 Object Lock in Compliance mode ensures that an object version cannot be overwritten or deleted by any user, including the root user, during a defined retention period. This immutability and protection against deletion, even by root, directly addresses the strict compliance requirement for sensitive audit logs.
Why the other options are wrong
- A. S3 versioning protects against accidental overwrites/deletions but does not prevent a root user from explicitly deleting object versions. Lifecycle policies manage transitions, not immutability.
- B. While CloudWatch Logs retention policies exist, an IAM policy denying 'logs:DeleteLogGroup' can still be overridden or modified by the root user, and it doesn't guarantee immutability of individual log events.
- C. A bucket policy denying 's3:DeleteObject' can be modified or removed by the root user, thus not providing the immutable, root-proof protection required by the compliance mandate.
S3 Object Lock (Compliance Mode)
An Amazon S3 feature that prevents an object version from being overwritten or deleted for a fixed amount of time or indefinitely. In Compliance mode, no user, including the root user, can delete the object version or alter its lock settings during the retention period.
- Provides WORM (Write Once, Read Many) storage.
- Essential for meeting strict regulatory compliance (e.g., FINRA, HIPAA).
- Retention period is set at object creation or later, cannot be shortened in Compliance mode.
Memory trick: Compliance Lock: S3's unchangeable promise.