AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard

A global enterprise uses AWS Organizations with multiple accounts and requires a centralized, immutable audit trail of all management events across all accounts and regions. The audit trail must be encrypted at rest and in transit, and accessible only by a dedicated security team in a separate logging account. What is the most secure and compliant way to achieve this?

  1. AManually create individual CloudTrail trails in each account, sending logs to an S3 bucket in the logging account, using S3 Object Lock in Governance mode.
  2. BUse AWS Config to record all resource changes and aggregate them to a central S3 bucket in the logging account, with client-side encryption.
  3. CEnable CloudTrail organization trail in the management account, configuring it to log to an S3 bucket in the logging account with KMS encryption.
  4. DConfigure CloudTrail in each account to log to a central S3 bucket in the logging account, with SSE-S3 encryption and bucket policies.
Show answer & explanation

Correct answer: C. Enable CloudTrail organization trail in the management account, configuring it to log to an S3 bucket in the logging account with KMS encryption.

An organization trail in AWS CloudTrail, created from the management account, automatically applies to all member accounts and all regions, ensuring comprehensive coverage. Logging to a central S3 bucket in a separate logging account provides centralization and isolation. Using AWS Key Management Service (KMS) for S3 bucket encryption ensures encryption at rest with strong key management. CloudTrail logs are encrypted in transit by default using TLS. This setup is the most secure and compliant for centralized, immutable audit trails.

Why the other options are wrong

  • A. Manually creating trails is inefficient and error-prone for a large organization. While S3 Object Lock in Governance mode can help with immutability, the primary focus is on centralized and comprehensive logging of management events, which an organization trail handles best, and KMS encryption is preferred for at-rest encryption over just SSE-S3 which is implied by Object Lock without explicit KMS.
  • B. AWS Config tracks resource configuration changes, not management events (API calls) which are critical for an audit trail. Client-side encryption is less robust for this scenario than server-side KMS encryption managed by AWS.
  • D. This approach is manual and prone to misconfiguration. While SSE-S3 encrypts at rest, KMS provides stronger key management and separation of duties. It also misses the organization trail's automatic deployment feature.

CloudTrail Organization Trail

A single CloudTrail trail created in the AWS Organizations management account that records events for all member accounts in the organization.

  • Automatically applies to all existing and future member accounts.
  • Logs to a central S3 bucket.
  • Ensures consistent logging across the organization.

Memory trick: The Organization Trail is the 'master logger' for the entire AWS family, sending all secrets securely to the central vault.

More Domain 2: Logging and Monitoring questions