Open cardosec

Case A8D1C7 · Cloud · L2 Practitioner

Cloud Audit Logging

Practise as: Explain it · Interview

Interview questionWhat cloud logs do you need on day one to investigate an incident later?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Control-plane logs (CloudTrail, Azure Activity Log, GCP Audit Logs) record who called which API and from where
  2. Data events (S3 object reads, Lambda invokes) are often off by default and must be enabled for sensitive data
  3. Also: VPC flow logs, DNS query logs, load balancer and WAF logs, identity provider sign-in logs
  4. Ship to a separate, locked-down log account so an attacker with admin cannot delete the evidence
  5. Alert on StopLogging/DeleteTrail, root account use, and new access keys on privileged users

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.