Question 1
A global logistics firm uses a multi-cloud strategy with applications deployed across AWS and Azure. To standardize security monitoring, they are forwarding all logs to a central SIEM. An analyst observes that Azure Activity Logs are being ingested successfully, but AWS CloudTrail logs are not appearing. The AWS environment uses multiple accounts under AWS Organizations, and logs are centrally collected in an S3 bucket in the management account. What is the MOST likely cause of this issue?
Answer and explanation
Correct answer: A
The most probable cause is a permissions issue. When using a central S3 bucket for AWS Organizations' CloudTrail logs, the IAM role or user credentials used by the SIEM's data connector must have the necessary s3:GetObject and s3:ListBucket permissions on that specific bucket. Network ACLs are stateless and less likely to be the root cause for a service-level integration. CloudTrail is enabled by default for management events, so it's unlikely to be disabled. A misconfigured trail would affect log generation, not ingestion by an external system if logs are present in S3.