Case A8D1C7 · Cloud · L2 Practitioner
Cloud Audit Logging
Practise as: Explain it · Interview
Interview questionWhat cloud logs do you need on day one to investigate an incident later?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Control-plane logs (CloudTrail, Azure Activity Log, GCP Audit Logs) record who called which API and from where
- Data events (S3 object reads, Lambda invokes) are often off by default and must be enabled for sensitive data
- Also: VPC flow logs, DNS query logs, load balancer and WAF logs, identity provider sign-in logs
- Ship to a separate, locked-down log account so an attacker with admin cannot delete the evidence
- Alert on StopLogging/DeleteTrail, root account use, and new access keys on privileged users
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.