CloudTrail Flashcards

1
Q

What AWS service do you use when you need to know who to blame?

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In what service can you monitor API Calls?

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS CloudTrail is a service that enables this 4 elements of your AWS account.

A
  • Governance
  • Compliance
  • Operational auditing
  • Risk auditing (rɪsk ˈɑdətɪŋ)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

With CloudTrail you can collect logs beyond 90 days by creating one of these

A

A Trail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In CloudTrail, Trail data is stored where?

A

S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What do you have to use to To analyze a Trail in CloudTrail?

A

Amazon Athena
ˈæməˌzɑn əˈθinə

Because There is no a trail GUI

Amazon Athena is an interactive query service that makes it easy to analyze data in Amazon S3 using standard SQL. Athena is serverless, so there is no infrastructure to manage, and you pay only for the queries that you run.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Trail option should you enable to ensure the logs are not tampered with?

A

Log File Validation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

With CloudTrail this AWS service handles the server side encryption of data

A

Key Management Service (SSE-KMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Sending CloudTrail to a CloudWatch log enables what functionality?

A

SNS notifications on specific activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where can you send events from CloudTrail?

A

CloudWatch Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which 2 AWS services can you track with CloudTrail Data Events?

A

Data events provide visibility into the resource operations performed on or within a resource. These are also known as data plane operations. Data events are often high-volume activities. The following data types are recorded:

  • Amazon S3 object-level API activity (for example, GetObject, DeleteObject, and PutObject API operations)
  • AWS Lambda function execution activity (the Invoke API)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The CloudTrail event type that is high volume and results in additional charges

A

Data Events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The 2 types of CloudTrail events

A

Management Events
Tracks management operations. (Eg. Attach role policies)
Turned on by default. Can’t be turned off.

Data Events
Tracks specific operations for specific AWS Services. Data events are high volume logging and will result in additional charges. Turned off by default.

The two services that can be tracked is S3 and Lambda. So it would track action such as: GetObject, DeleteObject, PutObject

They occur very frequently

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In CloudTrail that are 4 things you can do on Management Events?

A
  • Security
  • Registering devices
  • Configuring rules for routing data
  • Setting up logging
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is CloudTrail?

What are its 4 elements?

A
  • It’s a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account
  • Who to blame
  • It logs calls between AWS Service
  • Trails
  • Log file validation
  • Type of Events (Managed and data)
  • Athena
How well did you know this?
1
Not at all
2
3
4
5
Perfectly