AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationEasy

A company is deploying a new service that processes sensitive customer data. They need to ensure that all API calls made to AWS services within their account are logged, immutable, and retained for seven years for compliance purposes. Which solution best meets these requirements?

  1. ASet up AWS Config rules to monitor API calls and store remediation actions in an S3 bucket with versioning enabled.
  2. BUse Amazon Macie to discover and protect sensitive data in S3 buckets and enable versioning on those buckets.
  3. CConfigure S3 server access logging for all buckets storing sensitive data.
  4. DEnable AWS CloudTrail in all regions, configure it to log to an S3 bucket with S3 Object Lock in compliance mode, and set a retention period of seven years.
Show answer & explanation

Correct answer: D. Enable AWS CloudTrail in all regions, configure it to log to an S3 bucket with S3 Object Lock in compliance mode, and set a retention period of seven years.

AWS CloudTrail records all API calls made to AWS services. By configuring it to log to an S3 bucket with S3 Object Lock in compliance mode, the logs become immutable and cannot be deleted or overwritten for the specified retention period, meeting the compliance requirements.

Why the other options are wrong

  • A. AWS Config monitors resource configurations and changes, but it doesn't log all API calls or provide the immutability required by S3 Object Lock for compliance.
  • B. Amazon Macie is for data discovery and protection, not for logging all API calls or ensuring their immutability for compliance.
  • C. S3 server access logging tracks requests to S3 buckets, not all AWS API calls, and does not inherently provide immutability for compliance.

CloudTrail with S3 Object Lock

AWS CloudTrail records all API calls and events in your AWS account. When integrated with S3 Object Lock, it ensures that these logs are immutable and protected against deletion or modification for compliance.

  • CloudTrail captures API activity
  • S3 Object Lock provides WORM (Write Once, Read Many) protection
  • Compliance mode prevents root user deletion

Memory trick: CloudTrail's logs locked tight in S3, for compliance to see.

More Monitoring, Logging, and Remediation questions