AWS Certified Data Engineer – AssociateData Governance and SecurityMedium
A healthcare organization stores patient health information (PHI) in an Amazon S3 data lake. Due to HIPAA compliance, all access to this data must be logged, and these logs must be retained for seven years. The organization also needs to ensure that access attempts, both successful and failed, are captured. Which AWS service should the data engineer configure to meet these logging and retention requirements for S3 data access?
- AAWS CloudTrail
- BAmazon CloudWatch Logs
- CS3 Access Logs
- DAmazon Macie
Show answer & explanationAnswer & explanation
Correct answer: C. S3 Access Logs
S3 Access Logs capture detailed records of requests made to an S3 bucket, including successful and failed access attempts, and can be configured for long-term retention, making it suitable for HIPAA compliance for data access logging.
Why the other options are wrong
- A. CloudTrail logs API calls for governance and auditing, but S3 Access Logs provide more granular object-level access details for compliance.
- B. CloudWatch Logs aggregates logs from various AWS services but doesn't directly generate S3 object access logs at the detailed level required.
- D. Amazon Macie is for data discovery and classification, not for logging access attempts.
S3 Access Logs
S3 Access Logs provide detailed records for requests made to an S3 bucket, capturing information about who accessed what, when, and how, including successful and failed attempts.
- Deliver log files to a specified S3 bucket.
- Capture object-level operations.
- Essential for auditing and compliance requirements.
Memory trick: Access Logs: Always Capture All S3 Stuff.