A company has a CloudTrail trail that logs management events for all regions. The security team notices that some S3 data events are not being logged. How should the team enable logging for all S3 data events?
CloudTrail trails can be updated at any time to include data events for specific S3 buckets or all buckets, capturing object-level operations such as GetObject, PutObject, and DeleteObject in addition to the existing management events. This consolidates all API activity into a single audit stream, avoids the operational overhead of managing multiple trails, and is the direct, recommended way to meet the requirement for S3 access logging within CloudTrail.
Why this answer
CloudTrail trails can be configured to log data events for S3 in addition to management events. By updating the existing trail to include S3 data events (e.g., GetObject, PutObject), the security team can capture all object-level API activity without creating a separate trail. This ensures comprehensive logging while maintaining the existing management event logging for all regions.
Exam trap
The trap here is that candidates may think S3 server access logging (Option D) is equivalent to CloudTrail data events, but server access logs are separate, bucket-specific logs that lack the centralized management, API-level detail, and integration with CloudTrail Insights or other monitoring services.
How to eliminate wrong answers
Option B is wrong because creating a new CloudTrail trail that logs only data events would duplicate logging infrastructure and incur additional costs, but the existing trail already logs management events; the correct approach is to modify the existing trail to include data events. Option C is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity using CloudTrail logs, VPC Flow Logs, and DNS logs, but it does not enable or configure CloudTrail data event logging itself. Option D is wrong because S3 server access logs are bucket-level logs that record requests made to the bucket, but they are not integrated with CloudTrail and do not provide the centralized, API-level data event logging that CloudTrail offers; they also require enabling on each bucket individually and do not support the same filtering or integration with other AWS services.