AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationMedium

A SysOps team manages several AWS accounts. They need to establish a centralized logging solution for all AWS API calls across these accounts to meet compliance requirements and simplify security auditing. The solution must ensure that logs are immutable and can be stored for seven years. What is the most robust and cost-effective solution?

  1. AEnable VPC Flow Logs in each account and configure them to send logs to a central CloudWatch Logs group, then export these logs to an S3 bucket with a seven-year lifecycle policy.
  2. BUse Amazon Kinesis Firehose to stream all API call events from each account to a central Amazon Redshift cluster for long-term storage and querying.
  3. CImplement AWS Config rules in each account to record configuration changes, then aggregate these changes into a central account for auditing purposes.
  4. DConfigure CloudTrail in each account to deliver logs to a central Amazon S3 bucket, enable S3 Object Lock in compliance mode for immutability, and set a lifecycle policy for retention.
Show answer & explanation

Correct answer: D. Configure CloudTrail in each account to deliver logs to a central Amazon S3 bucket, enable S3 Object Lock in compliance mode for immutability, and set a lifecycle policy for retention.

CloudTrail is specifically designed for logging AWS API calls. Delivering these logs to a central S3 bucket with Object Lock in compliance mode ensures immutability, and S3 lifecycle policies manage the seven-year retention requirement cost-effectively.

Why the other options are wrong

  • A. VPC Flow Logs record network traffic, not AWS API calls, and exporting from CloudWatch Logs to S3 adds unnecessary complexity and cost for this requirement.
  • B. Redshift is a data warehouse, which is overkill and more expensive for simple log storage and auditing compared to S3 for this use case.
  • C. AWS Config records configuration changes, not all API calls, and is not designed as the primary service for comprehensive API call logging and auditing.

Centralized CloudTrail Logging with S3 Object Lock

CloudTrail records AWS API calls, which can be delivered to a centralized S3 bucket. S3 Object Lock in compliance mode ensures logs are immutable, meeting strict compliance requirements for data integrity.

  • CloudTrail logs all AWS API calls.
  • Logs can be delivered to an S3 bucket in a central logging account.
  • S3 Object Lock (Compliance mode) prevents deletion or modification of logs.
  • S3 lifecycle policies manage long-term retention efficiently.

Memory trick: CloudTrail records, S3 locks it tight, compliance is right.

More Monitoring, Logging, and Remediation questions