AWS Certified Data Engineer – AssociateData Governance and SecurityMedium

A financial institution uses Amazon DynamoDB to store transaction data. Due to strict audit requirements, every access attempt to the DynamoDB tables, including successful reads, writes, and administrative actions, must be logged and immutable. These logs must be available for forensic analysis for at least five years. Which AWS service should be integrated with DynamoDB to meet these logging and immutability requirements?

  1. AAmazon CloudWatch Logs
  2. BDynamoDB Streams
  3. CAWS CloudTrail
  4. DAWS Config
Show answer & explanation

Correct answer: C. AWS CloudTrail

AWS CloudTrail records API calls made to DynamoDB (including both data plane and control plane operations) as events, providing an immutable log suitable for auditing and forensic analysis with configurable retention.

Why the other options are wrong

  • A. CloudWatch Logs aggregates logs but doesn't inherently provide immutable API call logs for DynamoDB; CloudTrail is the source for this.
  • B. DynamoDB Streams capture item-level changes (inserts, updates, deletes) within a table, but not all access attempts or administrative actions as API calls.
  • D. AWS Config tracks resource configuration changes, not individual data access attempts or API calls.

CloudTrail for DynamoDB

AWS CloudTrail records API activity for Amazon DynamoDB, capturing all control plane and data plane operations as events, providing an audit trail for security and compliance.

  • Logs API calls, including item-level data plane operations.
  • Logs are immutable and stored in S3.
  • Supports long-term retention for compliance.

Memory trick: CloudTrail Captures All DynamoDB Deeds.

More Data Governance and Security questions