AWS Certified Data Engineer – AssociateData Ingestion and TransformationHard

A financial services company needs to audit all access to sensitive customer data stored in Amazon S3. They need to capture every S3 object access event (read, write, delete) and send these events to a centralized logging system for compliance and security analysis. The solution must be highly available and scalable to handle millions of events per hour. Which AWS service should be enabled to capture these events, and which service should be used to deliver them for analysis?

  1. AAmazon CloudWatch Logs + AWS Lambda
  2. BAmazon EventBridge + Amazon SQS
  3. CAWS CloudTrail + Amazon Kinesis Data Firehose
  4. DS3 Access Logs + Amazon Kinesis Data Streams
Show answer & explanation

Correct answer: C. AWS CloudTrail + Amazon Kinesis Data Firehose

AWS CloudTrail records all API calls and S3 data events (read, write, delete) for auditing. Kinesis Data Firehose can then reliably deliver these high-volume CloudTrail events to a centralized logging system (e.g., S3, Splunk-compatible endpoint) for analysis.

Why the other options are wrong

  • A. Amazon CloudWatch Logs captures logs from various AWS services, but CloudTrail is specifically designed for API activity and S3 data events. AWS Lambda can process events, but Firehose is better for high-volume, continuous delivery to logging destinations.
  • B. Amazon EventBridge delivers real-time event streams from AWS services, but CloudTrail is the specific service for auditing API calls and S3 data events. Amazon SQS is a message queue, suitable for decoupling, but Kinesis Data Firehose is better for direct, continuous delivery of logs to analytical destinations.
  • D. S3 Access Logs track requests made to an S3 bucket, but they are eventually consistent and delivered as log files, not real-time streams of individual events. Kinesis Data Streams could process them if converted, but CloudTrail is more direct for auditing API calls.

CloudTrail + Kinesis Data Firehose for S3 Auditing

AWS CloudTrail captures S3 data events (object-level API activity) for auditing, and Amazon Kinesis Data Firehose reliably delivers these audit logs to a centralized logging system.

  • CloudTrail tracks API calls and S3 data events.
  • S3 data events capture object-level reads/writes.
  • Firehose delivers high-volume streaming data to destinations.

Memory trick: CloudTrail watches S3, Firehose delivers the evidence fast.

More Data Ingestion and Transformation questions