AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A compliance officer needs to ensure that all API calls made to AWS services across an entire multi-account organization are logged and centrally stored for audit purposes. The logs must be immutable and retained for 7 years. Which solution MOST effectively meets these requirements?

  1. AUse Amazon CloudWatch Logs to collect all API calls and set retention policies for 7 years.
  2. BImplement custom Lambda functions to capture API calls and store them in an encrypted Amazon RDS database.
  3. CEnable CloudTrail in each account and configure S3 bucket policies for immutability and lifecycle rules.
  4. DConfigure an AWS Organizations delegated administrator account for CloudTrail, enable an organization trail, and use S3 object lock.
Show answer & explanation

Correct answer: D. Configure an AWS Organizations delegated administrator account for CloudTrail, enable an organization trail, and use S3 object lock.

Configuring an organization trail in CloudTrail via a delegated administrator account ensures all API calls across the organization are logged. S3 Object Lock provides immutability (WORM model) for the logs, and S3 lifecycle policies can manage retention for 7 years, making this the most effective and managed solution.

Why the other options are wrong

  • A. While CloudWatch Logs can store logs, it's primarily for operational monitoring and doesn't inherently provide the immutability guarantees of S3 Object Lock or the audit-focused nature of CloudTrail for API calls across an organization.
  • B. Custom Lambda functions and an RDS database add significant operational overhead and complexity, are not a native AWS solution for this specific problem, and may not inherently provide the immutability and auditability required.
  • C. Enabling CloudTrail in each account is decentralized and prone to misconfiguration or accidental disabling. It lacks the central management and enforcement of an organization trail.

Centralized CloudTrail Logging

Consolidating AWS CloudTrail logs from multiple accounts into a single, secure location for centralized auditing and compliance.

  • AWS Organizations enables organization trails.
  • Delegated administrator account manages the organization trail.
  • S3 Object Lock provides WORM (Write Once, Read Many) for log immutability.
  • S3 lifecycle policies manage retention periods.

Memory trick: Org Trail with Object Lock Locks Logs.

More Design Secure Architectures questions