AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard
A healthcare provider is storing patient records in an Amazon S3 bucket. Due to regulatory compliance, all access to these records must be logged, and the logs themselves must be protected from tampering. The logs should also be easily queryable for audit purposes. Which solution should the Solutions Architect recommend?
- AIntegrate S3 with AWS Config to track all object changes, and export data to Amazon Elasticsearch Service for querying.
- BEnable S3 server access logging to the same S3 bucket with bucket versioning enabled, and use S3 Select for querying.
- CEnable S3 server access logging to a separate S3 bucket with S3 Object Lock configured in compliance mode, and use Amazon Athena for querying.
- DUse AWS CloudTrail to log S3 data events to a separate S3 bucket with versioning enabled, and use Amazon CloudWatch Logs for querying.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable S3 server access logging to a separate S3 bucket with S3 Object Lock configured in compliance mode, and use Amazon Athena for querying.
S3 server access logging records all requests to an S3 bucket. Storing these logs in a separate S3 bucket with S3 Object Lock (compliance mode) ensures immutability and protection against tampering. Amazon Athena can then be used to perform SQL queries directly on these logs in S3, making them easily queryable for audit purposes, satisfying all requirements.
Why the other options are wrong
- A. AWS Config tracks configuration changes, not access logs. While Elasticsearch is good for log analytics, the primary mechanism for collecting immutable access logs and making them queryable from S3 is better handled by S3 access logs + Object Lock + Athena.
- B. Logging to the same S3 bucket is generally not recommended as it can lead to infinite loops or make log management difficult. S3 versioning helps with accidental deletions but doesn't provide the same tamper-proof guarantee as Object Lock. S3 Select is for querying within a single object, not across many log files.
- D. CloudTrail data events can log S3 object access, but S3 server access logging is generally more comprehensive for *all* requests to an S3 bucket. CloudWatch Logs is good for log monitoring, but Athena is often more powerful for direct SQL queries on large S3 log datasets. S3 versioning alone doesn't guarantee immutability against deletion in the same way Object Lock does.
S3 Access Log Auditing
S3 server access logs record all requests to an S3 bucket. When combined with S3 Object Lock and Amazon Athena, they provide immutable, auditable, and queryable access records.
- S3 server access logs capture all requests (who, what, when).
- S3 Object Lock (Compliance Mode) ensures log immutability.
- Logs should be stored in a separate S3 bucket.
- Amazon Athena allows SQL-based querying of logs in S3.
Memory trick: Logs: Lock, Query, Audit