hands-on lab

Governing AWS accounts with AWS Config and AWS CloudTrail

Difficulty: Intermediate
Duration: Up to 1 hour
Students: 1,320
Rating: 4.4/5
Get guided in a real environmentPractice with a step-by-step scenario in a real, provisioned environment.
Learn and validateUse validations to check your solutions every step of the way.
See resultsTrack your knowledge and monitor your progress.

Description

As deployments become increasingly complex and businesses allow developers more freedom to work with the AWS Cloud, understanding what users are doing becomes even more important.

Governance on AWS is the practice of using AWS tools to ensure that the way AWS is used meets strategic goals for a company. More concretely, this usually refers to a set of practices and techniques to monitor the usage of AWS APIs and services. In this lab, we will review methods for monitoring how developers use AWS.

Learn about the basic techniques and technologies for the governance of enterprise AWS accounts. This lab covers how to use AWS Config Rules, IAM monitoring techniques, AWS CloudTrails, and core reporting tools.

You will set up AWS Config to monitor changes to resources within an AWS account, subscribe to updates on these resources via email, create an audit trail of AWS API calls using AWS CloudTrail, learn how to read an AWS Config Resource Change Timeline, and pull an AWS IAM report for an account.

Learning objectives

Upon completion of this lab, you will be able to:

  • Set up AWS Config to monitor changes to AWS resources in your account
  • Subscribe to resource updates via email
  • Create an audit trail of AWS API calls using AWS CloudTrail
  • Learn how to read an AWS Config Resource Change Timeline
  • Access an AWS IAM report for an AWS account

Intended audiences

  • Candidates for the AWS Certified Solutions Architect - Associate exam
  • Cloud Architects
  • System Administrators

Prerequisites

Familiarity with the following will be beneficial but is not required:

  • AWS Config
  • AWS IAM
  • AWS CloudTrail

Updates

March 21st, 2023 - Updated CloudTrail lab step instructions to match console UI experience

October 13th, 2022 - Resolved deployment issue

May 31st, 2022 - Updated lab format and lab step instructions to match console UI experience

July 20th, 2021 - Updated lab format and lab step instructions to match console UI experience

January 10th, 2019 - Added a validation Lab Step to check the work you perform in the Lab

September 12th, 2018 - Updated instructions, screenshots, and permissions to match the new service workflows.

Environment before

Environment after

Covered topics

Lab steps

Logging In to the Amazon Web Services Console
Setting up AWS Config
Sending email notifications with Amazon Simple Notification Service
Creating a trail with AWS CloudTrail
Reviewing AWS Config resource timelines
Inspecting AWS Config timeline changes
Accessing an AWS IAM credential report