Question 1
Q1A financial institution is implementing a centralized logging architecture to comply with strict regulatory requirements. They need to aggregate security logs from Amazon GuardDuty, AWS Security Hub, and Amazon Route 53 Resolver DNS Firewall across 50 AWS accounts into a central security account. The solution must support the Open Cybersecurity Schema Framework (OCSF) to facilitate integration with a third-party SIEM. The security team prioritizes a solution that minimizes custom transformation logic and operational overhead.
Which solution should the security architect implement?
Show answer & explanation
Correct answer: A
Amazon Security Lake automatically centralizes security data from AWS environments, SaaS providers, and on-premises sources into a purpose-built data lake stored in your account. It automatically converts incoming log data to the Open Cybersecurity Schema Framework (OCSF) standard, which meets the requirement for minimized transformation logic and SIEM integration.