AWS Certified Data Engineer – AssociateData Governance and SecurityMedium
A compliance officer needs to ensure that all changes to S3 bucket policies, IAM roles, and encryption keys used for a data lake are logged and immutable for auditing purposes. This includes tracking who made the change, when, and the exact details of the change. Which AWS service configuration is essential for capturing this type of governance and security-related event data?
- AAmazon GuardDuty for continuous security monitoring
- BAWS CloudTrail configured with a multi-region trail and S3 bucket logging
- CAWS Config with resource change tracking and conformance packs
- DAmazon CloudWatch Events with custom rules
Show answer & explanationAnswer & explanation
Correct answer: B. AWS CloudTrail configured with a multi-region trail and S3 bucket logging
AWS CloudTrail records API calls and related events for AWS services, including changes to S3 bucket policies, IAM roles, and KMS keys. A multi-region trail ensures comprehensive coverage, and logging to an S3 bucket provides immutable storage for auditing and long-term retention.
Why the other options are wrong
- A. Amazon GuardDuty is a threat detection service, not a service for logging and auditing configuration changes.
- C. AWS Config tracks resource configuration changes and compliance against desired states, but CloudTrail provides the 'who, what, when, and how' of the change event itself.
- D. CloudWatch Events (now EventBridge) reacts to events but does not generate the detailed audit trail of configuration changes itself.
CloudTrail for Governance
AWS CloudTrail provides a record of actions taken by a user, role, or an AWS service, serving as a critical tool for governance, compliance, and auditing by logging API calls and changes to resources.
- Records API calls and events.
- Tracks changes to policies, roles, keys.
- Logs 'who, what, when, where' of changes.
- Essential for compliance and security audits.
Memory trick: CloudTrail Changes Tracked