AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy
A security auditor needs to regularly review all API calls made to an AWS account, including who made the call, when, from where, and what actions were taken. This data must be stored securely and be immutable for compliance purposes. Which AWS service should be configured?
- AAmazon CloudWatch Logs
- BAWS CloudTrail
- CAWS Config
- DAmazon GuardDuty
Show answer & explanationAnswer & explanation
Correct answer: B. AWS CloudTrail
AWS CloudTrail records all API calls and related events made within an AWS account, including who, what, when, and from where. It can deliver these logs to S3, where features like S3 Object Lock can ensure immutability for compliance.
Why the other options are wrong
- A. CloudWatch Logs collects and monitors logs from various AWS services and applications, but it doesn't inherently record all AWS API calls for auditing purposes as CloudTrail does.
- C. AWS Config continuously monitors and records AWS resource configurations and changes, which is different from recording API call history.
- D. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not a service for logging all API calls for auditing.
AWS CloudTrail
A service that enables governance, compliance, operational auditing, and risk auditing of your AWS account by logging actions taken by a user, role, or an AWS service.
- Records all AWS API calls and events.
- Logs who, what, when, and from where.
- Delivers logs to S3 for secure, immutable storage.
- Essential for auditing and compliance.
Memory trick: CloudTrail: Track All Actions