AWS Certified Data Engineer – AssociateData Ingestion and TransformationHard
A financial institution needs to audit all access to sensitive customer data stored in an Amazon S3 bucket. All read and write operations on this S3 bucket must be captured, and these audit logs need to be delivered to an Amazon Redshift data warehouse for long-term retention and compliance analysis. The solution must be automated, reliable, and ensure that no audit events are missed. Which combination of AWS services should be used to achieve this?
- AS3 Event Notifications with AWS Lambda to Redshift
- BAmazon Kinesis Data Streams with a custom producer and consumer to Redshift
- CAWS CloudTrail with S3 Data Events enabled, integrated with Amazon Kinesis Data Firehose to Redshift
- DAWS Config with S3 rules and AWS Glue ETL to Redshift
Show answer & explanationAnswer & explanation
Correct answer: C. AWS CloudTrail with S3 Data Events enabled, integrated with Amazon Kinesis Data Firehose to Redshift
AWS CloudTrail, with S3 Data Events enabled, captures all S3 bucket-level API activity (read/write). Integrating CloudTrail logs with Amazon Kinesis Data Firehose reliably streams these events to Amazon Redshift, ensuring full auditability, automated delivery, and long-term retention for compliance.
Why the other options are wrong
- A. S3 Event Notifications are for object-level events (PUT, DELETE) and might not capture all API calls, especially LIST or GET operations from other services, and require custom Lambda code for delivery to Redshift.
- B. Amazon Kinesis Data Streams would require custom development for logging S3 events and delivering them to Redshift, which is less managed and reliable than CloudTrail integration.
- D. AWS Config tracks resource configuration changes and compliance, not individual API access events. AWS Glue ETL is for batch transformation, not real-time audit log streaming.
CloudTrail S3 Data Events + Kinesis Firehose
A robust solution for capturing and delivering all Amazon S3 object-level API activity (read/write) for auditing and compliance to analytics destinations like Amazon Redshift.
- CloudTrail captures S3 Data Events (GetObject, PutObject, etc.)
- CloudTrail logs are delivered to an S3 bucket
- Kinesis Data Firehose can ingest these logs from S3 or direct stream
- Firehose reliably delivers logs to Redshift for analysis
Memory trick: CloudTrail watches S3 like a detective, and Firehose delivers the evidence to Redshift.