AWS Certified Data Engineer – AssociateData Governance and SecurityMedium

A pharmaceutical company is auditing its data governance practices. They need to ensure that all data access events, including who accessed which data, when, and from where, are logged and immutable for seven years to comply with regulatory requirements. The data is stored across S3, Redshift, and DynamoDB. Which AWS service is primarily responsible for capturing these audit logs?

  1. AAmazon CloudWatch Logs
  2. BAWS CloudTrail
  3. CAWS Config
  4. DAmazon GuardDuty
Show answer & explanation

Correct answer: B. AWS CloudTrail

AWS CloudTrail records API calls and related events made by or on behalf of an AWS account, providing an audit trail of actions taken across AWS services, including data access events for S3, Redshift, and DynamoDB. This data can be stored for long periods in S3 for compliance.

Why the other options are wrong

  • A. CloudWatch Logs aggregates and monitors logs from various sources but doesn't primarily generate the audit logs of API calls.
  • C. AWS Config records configuration changes of AWS resources, not individual data access events.
  • D. Amazon GuardDuty is a threat detection service, not an audit logging service for compliance.

AWS CloudTrail

AWS CloudTrail is an AWS service that helps you enable governance, compliance, and operational and risk auditing of your AWS account. It records API calls and related events for most AWS services.

  • Records AWS API calls and events.
  • Provides audit trail for actions.
  • Integrates with S3 for long-term storage.
  • Essential for compliance and security forensics.

Memory trick: CloudTrail Tracks Every Action

More Data Governance and Security questions