To access material, start machines and answer questions login.
access logging is one of the most frequently missed security controls in deployments. It is not enabled by default on new buckets, and does not log S3 data events by default.
This leaves a blind spot for any S3 activity, but by the end of this room, you will be able to shed some light on it.
Learning Objectives
- Explain the difference between S3 server access logs and CloudTrail S3 data events
- Identify S3 buckets with no access logging configured
- Enable CloudTrail S3 data events for specific buckets
- Enable S3 server access logging as a complementary record
- Query CloudTrail logs through Logs Insights to identify suspicious data access patterns
Prerequisites
- Being able to set up your environment (First Steps Into AWS room)
- Basic commands (Linux Fundamentals room)
- Recommended to first complete the The Leaky Bucket room in this module
- Have a basic understanding of the S3 service (Introduction to Cloud Storage room)
Answer the questions below
I am blind, not deaf.
Ready to learn Cyber Security?
The The Blind Bucket room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

