CloudTrail Flashcards

This deck aims to help retain concepts related to the AWS CloudTrail service.

1
Q

What is the default data retention period for the CloudTrail service?

A

90 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which CloudTrail component allows logs to be delivered to S3, CloudWatch Logs, or CloudWatch Events?

A

Trail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Is CloudTrail a real-time solution?

A

No, logs usually take up to 15 minutes to deliver

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In which region are CloudTrail log events recorded for global services such as IAM, SNS, and CloudFront?

A

These events are logged in the us-east-1 region; only global trails can catch these logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which types of events does CloudTrail log?

A

Management events, data events, and insight events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which type of CloudTrail events provides information known as control plane operations (e.g., resource creation, policy attachment)?

A

Management events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which type of events does CloudTrail log by default?

A

Management events only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which type of CloudTrail events provides information known as data plane operations (e.g., object deletion from an S3 bucket, SNS publish)?

A

Data events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which type of CloudTrail events provides information on UNUSUAL API call rates or error rate activity (e.g., an account typically logs 20 deleteBucket API calls, but starts to log an average of 100 deleteBucket API calls)?

A

Insight events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly