AWS CloudTrail Flashcards

1
Q

I need to be able to capture changes from all regions, what is the best way to do this?

A

Use cloud trail and select option ‘Apply to all regions’

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

I need to be able to capture changes from all accounts in my organization, what is the best way to do this?

A

Create a cloud trail and select to use ‘Apply trail to my organization’, this will capture all changes from all accounts and if you select ‘apply to all regions’ you also get trails across all regions in all accounts in the orgnization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

I need to collect AWS resource API event information for S3 and lambs, what options do I have?

A

You can enable data collection when creating a cloud trail, you can select individual objects or turn option on for every object.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

I need to create a CloudTrail, do I pay for just one?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Where can I store cloud trails logs to?

A

You can store the cloud trail logs to an S3 bucket.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

I have an organization with many accounts, is it possible to capture all changes across all accounts to a CloudTrail log?

A

Yes, you sent the option to have cloud trail consolidate across all account, this means the trails will aggregate into one single bucket.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

As part of regulatory, I have to ensure all my data is stored encrypted at rest, what options do I have for cloud trail?

A

When creating a CloudTrail, I can in advance options select encryption of log files using KMS SSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

As part of regulatory, I need to capture all changes in AWS and also ensure the data can not be seen if the log data file was taken by hackers, I also need to ensure the log data files not tampered with, what are my best options?

A
  • Use CloudTrail to capture all changes in AWS
  • Use the advanced option of a CloudTrail to encrypt the files with a KMS SSK
  • Use the advanced option to also sign the files
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

I have created a CloudTrail and I need to be able to know when files are delivered to the S3 bucket, what options do I have?

A

You can use the CloudTrail advance option of notification and select an SNS topic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How long will cloud trail retain logs?

A

You can search back 90 days of hoistory, but if you have a CloudTrail pushing logs to s3, data is retained indefently, you can use life cycle policies to delete the logs files form s3 as needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How many trails can I create in a single region?

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What makes storing CloudTrail logs in S3 secure?

A
  • ## By default CloudTrail encrypts the log files before placing in a S3 buckket.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do I get charged for CloudTrail?

A

AWS CloudTrail allows you to view and download the last 90 days of your account activity for create, modify, and delete operations of supported services free of charge. There is no charge from AWS CloudTrail for creating a CloudTrail trail and the first copy of management events within each region is delivered to the S3 bucket specified in your trail free of charge.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

If I have only one trail with management Events, and apply it to all regions, will I incur charges?

A

No. The first copy of management events is delivered free of charge in each region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

I nneed to process CloudTrail logs using an Java application I am creating, what are my options?

A

AWS CloudTrail Processing Library is a Java librar

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is CloudTrail log file integrity validation?

A

CloudTrail log file integrity validation feature allows you to determine whether a CloudTrail log file was unchanged, deleted, or modified since CloudTrail delivered it to the specified Amazon S3 bucket.

17
Q

What is the benefit of CloudTrail log file integrity validation?

A

ensure the logs delivered to S3 are not tampered after delivery.

18
Q

I shose to use KMS SSE with cloudtrail will I be charged?

A

Yes you will pay for KMS

19
Q

How often will CloudTrail deliver log files to my Amazon S3 bucket?

A

CloudTrail delivers log files to your S3 bucket approximately every 5 minutes.

20
Q

How long does it take CloudTrail to deliver an event for an API call?

A

Typically, CloudTrail delivers an event within 15 minutes of the API call.

21
Q

What will CloudTrail log for you?

A

All api calls to your accounts. but not calls inside each sevice or resource, you can enable this capture for S3 and Lambds.

22
Q

I need to keep my audit logs from AWS for two years, how cna |I do this?

A

You need to set up a CloudTrail-trail export and have cloud trail logs send to s3.

23
Q

I need to have my cloud trail logs send to lambda, is this possible and if so how?

A

You can set up a CloudTrail-trail and have the log stream call a lambda function.

24
Q

If I have CloudTrail apply to all regions and AWS adds a new region, what will happen by default?

A

CloudWatch will be added to the new region.

25
Q

I wnat to collect all CloudTrail logs into a single bucket, how cna I do this?

A

ClouTrail has an option to collect all logs into a single bucket.

26
Q

I am setting up an account structure in AWS with AWS Organizations, I wnat to have CloudTrail automatically added to any new account added to my organization, how can I do this?

A

There is an option in CloudTrail to have CloudTrail added to any new accounts added to an organization.

27
Q

What are management events in CloudTrail?

A

They are a set of control plain events like someone logged in to your account, you can opt to have these added to your CloudTrail stream.

28
Q

My org has the policy to encrypt all data at rest, how can I deal with this in CloudTrail or do I need to implement a third-party tool or service?

A

In CloudTrail you have the option when creating a trail to select to encrypt the sat in the s3 bucket. You cna select to encrypt using SSE-KMS

29
Q

I am implementing a government sAWS solution and one of the requirements is to ensure that the logs have not been tampered with form CloudTrail, what is my best method to architect for this?

A

CloudTrail has an option when creating a TRAIL to have log validation, this is where AWS also delivers a hash.

30
Q

I am setting up a CloudTrail trail and I wnat to be notified with log is delivered into S3, is this possible?

A

Yes, when creating a trail, it is an option to have an SNS invoked.

31
Q

Is CloudTrail free?

A

Yes for the first TRAIL.

32
Q

I wnat t could the number of CloudTrail logs arriving, how can I architect this?

A

You can have CloudTrail logs delivered to CloudWatch, this is an option when setting up a CloudTrail-trail.

33
Q

What is the function of AWS CloudTrail?

A

AWS Cloudtrail records all of the AWS API calls to a region or all regions or when using orgnization you can have it record all regions in all accounts belong to the orgnization?

34
Q

At 1 PM today we saw an s3 bucket get deleted, we want to know who delete the s3 bucket, how can we find this out?

A

Using AWS Cloudtrail we can search for this event/API call as Cloudtrail records all events/API calls.

35
Q

What are the two endpoints thet Cloudtrail can deliver events to?

A
  • S3

- Lambda

36
Q

Describe the Cloudtrail event you need to look for when a user logs in to AWS account?

A

The ‘eventName = ConsoleLogin’ event and in this event is the username= ‘Roger’