AWS Certified Data Engineer – AssociateData Governance and SecurityHard
A large enterprise uses multiple AWS accounts and needs to centralize the auditing of all S3 bucket policy changes, IAM role modifications, and network access control list (NACL) updates across its entire AWS environment. The audit logs must be immutable and retained for 7 years for compliance. The security team also requires the ability to quickly search and analyze these logs. Which AWS service combination should be used to meet these requirements?
- AAWS CloudWatch Logs for log aggregation and S3 for storage.
- BAWS Config for resource configuration history and AWS CloudWatch Events for notifications.
- CS3 Access Logs for bucket activity and Amazon Macie for sensitive data discovery.
- DAWS CloudTrail with S3 for storage, integrated with S3 Object Lock and Amazon Athena.
Show answer & explanationAnswer & explanation
Correct answer: D. AWS CloudTrail with S3 for storage, integrated with S3 Object Lock and Amazon Athena.
AWS CloudTrail centrally logs all API calls (including S3 policy, IAM, and NACL changes) as immutable events to an S3 bucket. S3 Object Lock ensures log immutability, and Amazon Athena can be used to query and analyze these logs quickly, meeting all requirements for auditing, retention, and analysis.
Why the other options are wrong
- A. CloudWatch Logs aggregates logs but CloudTrail is the primary service for auditing API calls, and it doesn't inherently provide log immutability or a direct query service like Athena for CloudTrail logs.
- B. AWS Config tracks configuration changes but doesn't provide the detailed API call logs needed for auditing all S3 policy or IAM role modifications, nor log immutability.
- C. S3 Access Logs track object access, not management plane API calls like policy changes. Macie is for sensitive data discovery, not API call auditing or immutability.
CloudTrail with S3 Object Lock & Athena
AWS CloudTrail records API calls to AWS services, delivering immutable logs to S3. S3 Object Lock enforces WORM compliance on these logs, and Amazon Athena provides a serverless query engine to analyze them efficiently.
- CloudTrail logs management and data events.
- S3 Object Lock ensures log immutability for compliance.
- Athena allows SQL queries directly on S3-stored logs.
Memory trick: CloudTrail Locks Logs for Long-term Lookup with Athena.