Management and Governance
CoreAWS CloudTrail
AWS API activity records for audit extraction and traceability.
Key points
- CloudTrail records AWS API identity and action history for audit and investigation.
- Account, Region, event type, retention, integrity, and delivery scope determine whether the evidence meets an audit requirement.
Best-known use cases
- Audit API activity against data stores, catalogs, and processing services.
- Deliver activity history to S3 for compliance analysis and investigation.
What candidates often confuse it with
- CloudTrail captures API activity; CloudWatch Logs stores general application and service logs, and CloudTrail Lake supports audit-event queries.
Key takeaway
Choose CloudTrail when the question is who called an AWS API, what they did, and when.
Relevant exam tasks
- D3.3 — Task 3.3: Maintain and monitor data pipelines
- 3.3.1 — Extract logs for audits.
- 3.3.5 — Use AWS CloudTrail to track API calls.
- D4.4 — Task 4.4: Prepare logs for audit
- 4.4.1 — Use AWS CloudTrail to track API calls.
- 4.4.3 — Use AWS CloudTrail Lake for centralized logging queries.
- D4.5 — Task 4.5: Understand data privacy and governance
- 4.5.4 — Viewing configuration changes that have occurred in an account (for example, AWS Config).