Monitoring, Auditing, and Logging Users and Resource Usage in AWS IAM

30 minutes
  • 3 Learning Objectives

About this Hands-on Lab

In this hands-on lab scenario, you are a security engineer working for a new startup that’s launching an online bookstore for rare and antique books. The founder, Kia, needs your help with monitoring and auditing the activities in her account. In order to provide access and ensure the proper security measures are in place, you will use AWS Identity & Access Management (IAM) and AWS CloudTrail. You will provide Kia with the credential report, the details from the Access Advisor tab, and you will create a trail using CloudTrail.

Learning Objectives

Successfully complete this lab by achieving the following learning objectives:

Generate a Credential Report
  1. Log in to the AWS Management Console.
  2. Access Identity & Access Management (IAM).
  3. Click Credential Report.
  4. Download the report and open it.
Utilize the Access Advisor Tab
  1. Log in to the AWS Management Console.
  2. Access Identity & Access Management (IAM).
  3. Access the developer-1 user.
  4. Review the details of the Access Advisor tab.
Create a Trail using CloudTrail
  1. Log in to the AWS Management Console.
  2. Access CloudTrail.
  3. Review the event history for the account.
  4. Create a trail that logs to an Amazon S3 bucket.

Additional Resources

Please log in to the lab environment with the cloud_user credentials provided. Make sure you are using us-east-1 region throughout the lab.

What are Hands-on Labs

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?