AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationMedium

A company requires a robust solution for auditing all AWS account activity, including API calls, resource changes, and security events, across multiple AWS accounts. The audit logs must be stored securely, centrally, and encrypted, with integrity validation enabled. Which combination of AWS services should be used to meet these requirements?

  1. ADeploy AWS Config in each account, configure rules for resource changes, send notifications to Amazon SNS, and archive SNS messages to a central S3 bucket.
  2. BUtilize Amazon CloudWatch Logs for all log collection, create custom metric filters for activity, and export logs to a central S3 bucket via CloudWatch Logs subscriptions.
  3. CConfigure Amazon GuardDuty to monitor all accounts, aggregate findings to AWS Security Hub, and enable Security Hub's export to S3.
  4. DEnable AWS CloudTrail in each account, configure a trail to send logs to a central Amazon S3 bucket, and enable S3 default encryption and CloudTrail log file integrity validation.
Show answer & explanation

Correct answer: D. Enable AWS CloudTrail in each account, configure a trail to send logs to a central Amazon S3 bucket, and enable S3 default encryption and CloudTrail log file integrity validation.

AWS CloudTrail is the primary service for auditing AWS account activity, recording API calls and resource changes. Configuring a multi-region, multi-account trail to a central S3 bucket with default encryption and CloudTrail log file integrity validation ensures secure, centralized, and verifiable audit logs.

Why the other options are wrong

  • A. AWS Config focuses on resource configuration changes and compliance. While it records changes, it doesn't provide the full API call history or security event details that CloudTrail offers for auditing purposes.
  • B. CloudWatch Logs can collect logs, but CloudTrail is specifically designed for account activity auditing. While logs can be exported to S3 from CloudWatch Logs, CloudTrail provides built-in integrity validation and a more direct audit focus.
  • C. GuardDuty is for threat detection, and Security Hub aggregates findings. While important for security, they don't provide the comprehensive audit trail of all API calls and resource changes that CloudTrail does.

Centralized CloudTrail Logging

Centralized CloudTrail logging involves configuring AWS CloudTrail to record all account activity across multiple AWS accounts and deliver these logs to a single, secure Amazon S3 bucket, with encryption and integrity validation enabled.

  • CloudTrail records all API calls and events.
  • Multi-account, multi-region trails are recommended.
  • Logs delivered to a central S3 bucket.
  • S3 encryption and CloudTrail integrity validation ensure security and verifiability.

Memory trick: CloudTrail leaves a secure 'trail' of all account actions in S3.

More Monitoring, Logging, and Remediation questions