CloudTrail Flashcards
CloudTrail
How do you turn on CloudTrail?
On (enabled) by default, except for CloudFront and other global things
CloudTrail
How long stored?
Last 90 days for free
CloudTrail
Where are CloudTrail things stored?
In CloudTrail
CloudTrail
What if you want more than the CloudTrail limit on past events?
Create a Trail
CloudTrail
Attributes of a Trail you create?
S3 bucket to store events in, keys to encrypt, target CloudWatch Log Group
CloudTrail
Three types of events captured in CloudTrail?
Management Events (control plane), Data Events (data plane), Insight Events
CloudTrail
What is captured by default?
Management Events. Data Events are not 100% captured; have to turn on separately
CloudTrail
What about global services like CloudFront?
Off by default, can be turned on for any Trail, always log to us-east-1
CloudTrail
Two types of Trails you can create?
One Region trail, All Regions trail
CloudTrail
How does a One Region Trail work?
Everything lives in a single region
CloudTrail
How does an All Regions Trail work?
Collects data in every region, but managed as a single Trail
CloudTrail
Major product for aggregating CloudTrail across accounts?
Organizations: set up a Trail in management account to aggregate across all OU accounts.
CloudTrail
Is CloudTrail real-time?
No, has around 15 minute delay
CloudTrail
Cost structure of CloudTrail?
Default trail of 90 days and copy to S3 is free. Data Events and additional Trails have a cost.
CloudTrail
Are Security Group changes logged by default?
Yes