AWS Certified Data Engineer – AssociateData Governance and SecurityHard

A data engineering team is building a new application that will process sensitive customer data. To meet compliance requirements, all access attempts to the data must be logged, including successful and failed attempts, and these logs must be immutable for seven years. Which AWS service should the team use to capture and ensure the integrity of these access logs?

  1. AAmazon CloudWatch Logs
  2. BAWS CloudTrail with S3 Object Lock
  3. CAmazon S3 server access logging
  4. DAWS Config
Show answer & explanation

Correct answer: B. AWS CloudTrail with S3 Object Lock

AWS CloudTrail records API calls and related events, capturing both successful and failed access attempts. Delivering these logs to an S3 bucket configured with Object Lock in WORM (Write Once Read Many) mode ensures that the logs are immutable and protected for the required seven-year retention period, satisfying both logging and integrity requirements.

Why the other options are wrong

  • A. CloudWatch Logs stores logs but does not inherently provide immutability guarantees like S3 Object Lock.
  • C. S3 server access logging logs requests to an S3 bucket, but it doesn't provide the comprehensive API call logging of CloudTrail, nor does it inherently offer immutability without additional S3 features like Object Lock.
  • D. AWS Config tracks resource configuration changes and compliance, not individual data access attempts or their immutability.

CloudTrail with S3 Object Lock

AWS CloudTrail logs API activity and events across AWS services. When combined with Amazon S3 Object Lock in WORM mode, it ensures that these audit logs are immutable and cannot be deleted or overwritten for a specified retention period.

  • CloudTrail records API calls and events.
  • S3 Object Lock provides WORM protection for data.
  • Together, they ensure immutable audit trails for compliance.

Memory trick: CloudTrail Charts Logs, S3 Locks 'em Tight.

More Data Governance and Security questions