YouTube2Text

AWS Monitoring & Governance Explained | CloudWatch vs CloudTrail vs Config | CLF-C02 Day 17 — Transcript

by Pawan Joshi · 3,798 words · 606 segments · language en · Watch on YouTube

Full transcript

  1. 0:00Hey everyone, welcome to day 17. We are
  2. 0:03officially deep into week three now and
  3. 0:04today's topic is one that I genuinely
  4. 0:06believe separates people who just
  5. 0:08memorize AWS services from people who
  6. 0:10actually understand how AWS works in the
  7. 0:12real world. Today's theme is see
  8. 0:14everything, prove everything, fix
  9. 0:16everything. Think about it like running
  10. 0:18a big office building. As a building
  11. 0:21manager, you need three completely
  12. 0:22different things. You need to see how
  13. 0:24the building is performing right now. Is
  14. 0:26the AC working? Is the elevator
  15. 0:28overloaded? Are there enough visitors
  16. 0:30coming in? That's monitoring.
  17. 0:33You need to be able to prove if anyone
  18. 0:35ever asked exactly who entered which
  19. 0:37room at what time and what uh they did
  20. 0:40there. That's called auditing.
  21. 0:43And the third one, you need a way to
  22. 0:45make sure every room in the building
  23. 0:47follows the rules. Fire exist unlocked,
  24. 0:50no unauthorized wiring changes, and to
  25. 0:52fix it the moment something drifts out
  26. 0:53of compliance. That's called governance
  27. 0:56and compliance. AWS has dedicated
  28. 0:58services for each of these three jobs
  29. 1:00and today we are covering all of them.
  30. 1:03We will cover cloudatch,
  31. 1:07cloud trail
  32. 1:10and AWS config
  33. 1:13plus some very important supporting
  34. 1:15services like uh audit manager, artifact
  35. 1:18system managers and trusted advisor as
  36. 1:20well. Now I have to warn you about
  37. 1:21something important right away.
  38. 1:23Cloudatch versus cloud trail versus
  39. 1:25config. This is officially one of the
  40. 1:27exams favorite gotcha comparisons. Their
  41. 1:29names sound similar. They all are
  42. 1:31watching something in your as account
  43. 1:33and countless student confuse them on
  44. 1:34exam day. But don't worry, by the end of
  45. 1:37this today's video, you will have such a
  46. 1:39crystal clear mental separation between
  47. 1:41these three that you will never mix them
  48. 1:43up again. Today's topic spans two
  49. 1:45domains at once. Domain two, security
  50. 1:48and compliance and domain three, cloud
  51. 1:50technology and services. By the end of
  52. 1:53today, you will be able to explain
  53. 1:54exactly what Cloudatch does and when to
  54. 1:56reach for it. We will also discuss what
  55. 1:58Cloud Trail does and how it's completely
  56. 2:00different from Cloudatch. We will
  57. 2:02understand how AWS config track
  58. 2:04configuration drift and compliance. We
  59. 2:06will also understand the difference
  60. 2:07between AWS artifact and AWS audit
  61. 2:10manager. We will also understand what
  62. 2:12systems manager and trusted advisor do
  63. 2:13for daily operations. and then we will
  64. 2:15do a hands-on lab where you will create
  65. 2:17a real cloud watch alarm and turn on
  66. 2:18real AWS config rule connecting theory
  67. 2:21directly to the practice. So let's get
  68. 2:23started. Before we deep dive into each
  69. 2:25service, let's quickly preview
  70. 2:26everything we are covering today so you
  71. 2:28have a mental map to follow along with.
  72. 2:30The first one, Amazon Cloudatch. This
  73. 2:33handles metrics, alarms, logs, and
  74. 2:35operational dashboards. Basically, this
  75. 2:37is your how is everything performing
  76. 2:38right now tool. The second one we have
  77. 2:41AWS cloud trail. This is the complete
  78. 2:43API activity audit log. This answers who
  79. 2:46did what and when. The third one is AWS
  80. 2:50config. This tracks configuration
  81. 2:52history, enforces compliance rule and
  82. 2:54detects drift. Meaning when a resource
  83. 2:57setting quietly change away from what
  84. 2:59they are supposed to be. The fourth one
  85. 3:02AWS audit manager and AWS artifact. Two
  86. 3:05compliance related services that are
  87. 3:06very easy to confuse but have a clean
  88. 3:08and simple distinction we will nail down
  89. 3:10today. The fifth one, AWS Systems
  90. 3:13Manager, a toolkit that lets you manage
  91. 3:15a whole fleet of servers without ever
  92. 3:17opening an SSH connection. Next is AWS
  93. 3:20Trusted Adviser, an automated service
  94. 3:22that checks your entire AWS account
  95. 3:24against AWS own best practice
  96. 3:26recommendations.
  97. 3:27The seventh one, we have our hands-on
  98. 3:30lab where we will create a cloud watch
  99. 3:32alarm and enable an AWS config rule
  100. 3:34together. That's the full road map.
  101. 3:36Let's start with most commonly tested
  102. 3:39service of the day that is cloudatch.
  103. 3:42So Amazon cloudatch. If I had to
  104. 3:45describe cloudatch in one sentence for a
  105. 3:47total beginner, I would say cloudatch is
  106. 3:49the health monitor of your entire AWS
  107. 3:51environment. It watches how your
  108. 3:53resources are performing and tells you
  109. 3:55the moment something looks off.
  110. 3:57Cloudatch is built around four main
  111. 3:59building blocks. Let's go through each
  112. 4:01one carefully. The first one we have is
  113. 4:04metrics. Cloudatch automatically collect
  114. 4:07metrics for nearly every AWS resource
  115. 4:10you use. No setup needed for the basics.
  116. 4:12Think of metrics as numbers measured
  117. 4:15over time. Things like CPU utilization
  118. 4:18on an EC2 instance. Network IO that is
  119. 4:21how much data is flowing in and out and
  120. 4:23disk throughput that means how fast data
  121. 4:26is being read and written. Request count
  122. 4:29how many requests your application
  123. 4:30received. lambda duration that is how
  124. 4:33long your serverless functions take to
  125. 4:35run. These are all just numeric data
  126. 4:37points tracked continuously so you can
  127. 4:39see trends over time like watching a
  128. 4:41heart rate monitor. Now what's the point
  129. 4:43of collecting all these numbers if
  130. 4:45nobody is watching them 24 by7 that's
  131. 4:48where alarms come in and alarm let you
  132. 4:51set the threshold and cloudatch
  133. 4:53automatically watches for that threshold
  134. 4:55being crossed let us take a real example
  135. 4:58if CPU utilization goes above 80% for
  136. 5:01five consecutive minutes notify the team
  137. 5:03via SNS and automatically trigger
  138. 5:06autoscaling to add more servers this
  139. 5:08means you don't need a human staring at
  140. 5:10a graph all day cloudatch does that
  141. 5:13watching for you and takes action
  142. 5:15automatically when something needs
  143. 5:16attention. Now let's see what Cloudatch
  144. 5:20logs mean. It is a centralized place to
  145. 5:22collect, search and analyze log data.
  146. 5:24Think of logs as detailed text record of
  147. 5:27events rather than simple numbers.
  148. 5:29Cloudatch logs can pull in logs from
  149. 5:31many different sources. EC2 application
  150. 5:33logs, Lambda function logs, VPC flow
  151. 5:35logs that is network traffic records, uh
  152. 5:38root 53 DNS query logs that is record of
  153. 5:40domain lookups. Instead of manually
  154. 5:42sshing into 10 different servers to
  155. 5:44check the individual log files, you can
  156. 5:46search across all of them in one central
  157. 5:48place. Finally, dashboards let you build
  158. 5:50custom real-time visual panels that pull
  159. 5:52together metrics and data from across
  160. 5:54many different services, giving your
  161. 5:57operations team one clear visual
  162. 5:58overview, like a single mission control
  163. 6:00screen showing everything at a glance.
  164. 6:03One more important detail, by default,
  165. 6:05Cloudatch only collects certain basic
  166. 6:07metrics automatically, but some data
  167. 6:09like memory usage or disk space on the
  168. 6:11EC2 instance actually requires
  169. 6:13installing something called the
  170. 6:15Cloudatch agent. And on that server we
  171. 6:18need to install that. This ascent is a
  172. 6:20small piece of software you install
  173. 6:22yourself and it collects extra OS level
  174. 6:24metrics and custom application logs that
  175. 6:26AWS can't see by default. So when do we
  176. 6:29use cloudatch? Here's the golden rule.
  177. 6:32Use cloudatch whenever the question is
  178. 6:34about monitoring resource performance or
  179. 6:37creating operational alerts. If a
  180. 6:39scenario talks about CPU usage, memory,
  181. 6:42network traffic, or setting up an alert
  182. 6:44when something crosses a threshold,
  183. 6:46that's Cloudatch every single time. So,
  184. 6:50here's a subtle but important trap.
  185. 6:52Cloudatch logs is not the same thing as
  186. 6:54Cloudatch metrics. Logs are the text
  187. 6:57record of events, detailed messages
  188. 7:00describing what happened. And metrics
  189. 7:03are numeric time series data, that is
  190. 7:05just numbers tracked over time. They
  191. 7:08live under the same overall cloudatch
  192. 7:09service but they are fundamentally
  193. 7:11different types of data. So don't
  194. 7:14confuse the two when a question
  195. 7:15specifically mentions one or the other.
  196. 7:19Now here comes the service that gets
  197. 7:20confused with cloudatch constantly. So I
  198. 7:22want you to lock in a very clear mental
  199. 7:24separation right now. Cloudatch is
  200. 7:28completely different from cloud trail.
  201. 7:30Here's the simplest way to understand
  202. 7:32cloud trail. It's your account security
  203. 7:35camera and a visitor log book combined.
  204. 7:38Every single time someone like a human
  205. 7:40user or an even automated AWS service
  206. 7:43makes an API call in your AWS account,
  207. 7:46cloud trail writes it down and it
  208. 7:48captures four critical pieces of
  209. 7:50information every time. What are these
  210. 7:53four critical pieces? Who made the call?
  211. 7:56Like which I am user or role. what
  212. 7:59action they performed like the specific
  213. 8:01API action name and when it happened
  214. 8:04means the exact timestamp where it came
  215. 8:07from that is a source IP address and by
  216. 8:11default AWS gives you 90 days of event
  217. 8:14history we will for free directly in the
  218. 8:16console but if you want to keep records
  219. 8:18independently for long-term audit
  220. 8:20purposes you need to create something
  221. 8:22called a trail this stores all your
  222. 8:25events permanently in an S3 bucket where
  223. 8:28they will stay as long as you want them
  224. 8:30to. Let us take an example where cloud
  225. 8:33trail becomes really powerful in the
  226. 8:34real world. Who deleted this S3 bucket?
  227. 8:38Who modified this IM policy and exactly
  228. 8:40when did they do it? Which IP addresses
  229. 8:43make those suspicious API calls at 3:00
  230. 8:45a.m.? We can see all that in Cloud
  231. 8:47Trail. If you ever need to investigate
  232. 8:50something that happened in your AWS
  233. 8:51account, a security incident or an
  234. 8:53accidental delete or just general
  235. 8:54accountability, cloud trail is where you
  236. 8:57go and find your answer. There's also a
  237. 9:00feature called cloud trail insights
  238. 9:02which can automatically detect unusual
  239. 9:04API activity. For example, a sudden
  240. 9:06unexpected spike in failed login
  241. 9:08attempts. This adds a bit of uh
  242. 9:10intelligent anomaly detection on the top
  243. 9:12of raw audit log. Here's the single most
  244. 9:15important sentence from the entire
  245. 9:17slide. So let's say it slowly. Cloudatch
  246. 9:21is equal to monitor performance metrics
  247. 9:25and cloud trail equal to audit API call
  248. 9:27history. So cloudatch cares about how
  249. 9:31well things are running. CPU, memory,
  250. 9:33request per second and cloud trail cares
  251. 9:36about who did what like identities and
  252. 9:40timestamps. Cloud trail is for editing
  253. 9:43users and service actions, not for
  254. 9:45measuring resource performance. Keep
  255. 9:47repeating this distinction until it
  256. 9:49becomes automatic in your brain. This
  257. 9:51single rule alone will save you on
  258. 9:53multiple exam questions. Now let's bring
  259. 9:56in the third member of this famous trio
  260. 9:57AWS config. If cloudatch is about
  261. 10:00performance and cloud trail is about who
  262. 10:02did what, then config is about what did
  263. 10:05this resource actually look like and
  264. 10:07does it follow our rules. So what config
  265. 10:10actually does it continuously records
  266. 10:12the configuration of your AWS resources
  267. 10:14over time. Think of it like a very
  268. 10:16detailed history book that captures a
  269. 10:18snapshot of every resource setting again
  270. 10:20and again. So you can look back and see
  271. 10:22exactly what a resource look like at any
  272. 10:24point in the past. Config also lets you
  273. 10:27define config rules. These automatically
  274. 10:29check your resource configuration
  275. 10:30against desired standard you defined.
  276. 10:32For example, a very common rule is no
  277. 10:35security group should allow unrestricted
  278. 10:37SSH access from the entire internet.
  279. 10:40Every resource that a rule applies to
  280. 10:42gets marked as either compliant or
  281. 10:44non-compliant. And this isn't a one-time
  282. 10:47check. It's a live continuously updating
  283. 10:49compliance dashboard. The moment
  284. 10:51something drifts out of the line with
  285. 10:52your rules, config flex it immediately.
  286. 10:55If you have many config rules that
  287. 10:56together represent an entire compliance
  288. 10:58framework, say a whole set of rules
  289. 11:01required for a specific industry
  290. 11:02standard, you can bundle them all
  291. 11:04together into something called a
  292. 11:06confirance pack, which lets you deploy
  293. 11:08the entire collection of rules as a
  294. 11:10single template instead of configuring
  295. 11:11each rule one by one. So, what question
  296. 11:14does config answer? Config answers what
  297. 11:17changed and did it drift away from the
  298. 11:19approved state. But here's something
  299. 11:21really important. Config tells you what
  300. 11:23changed but it does not tell you who
  301. 11:25made that change. For that you need to
  302. 11:27appear config together with cloud trail.
  303. 11:30This is a favorite exam trick so pay
  304. 11:32close attention. Which security group
  305. 11:34rule changed and who changed it. This
  306. 11:37security question actually requires both
  307. 11:40services working together. Config tells
  308. 11:42you what changed the specific
  309. 11:44configuration difference and the cloud
  310. 11:46trail tells you who changed it. the
  311. 11:49specific IM identity and time stamp.
  312. 11:51Cloudatch does neither of these jobs.
  313. 11:53It's not the part of this picture at
  314. 11:55all. So, here's your three-way mental
  315. 11:57map logged in for good. Cloudatch
  316. 12:00performance and health monitoring. Cloud
  317. 12:02trail is who did what and when. That is
  318. 12:05identity plus action. And we have
  319. 12:06config. Config is what changed and is it
  320. 12:09compliant. That is configuration plus
  321. 12:11drift.
  322. 12:13Now, let's cover two more services that
  323. 12:15sound similar and get mixed up
  324. 12:16constantly. AWS artifact and AWS audit
  325. 12:20manager. Fortunately, there is a
  326. 12:22beautifully simple way to tell them
  327. 12:23apart which I will give you in just a
  328. 12:25moment. But first, let's understand each
  329. 12:28one individually. AWS artifact. Artifact
  330. 12:31gives you ondemand self-service access
  331. 12:33to AWS own compliance reports and
  332. 12:35certifications. Things like ISO 27001,
  333. 12:39SOC1, SOC2, SOC3 and PCIDSS report. You
  334. 12:44might have heard about them. These are
  335. 12:46official documents providing that AWS
  336. 12:48own infrastructure meets these rigorous
  337. 12:50industry security and compliance
  338. 12:52standards. Artifact is also where you go
  339. 12:54to review and accept AWS agreements. For
  340. 12:57example, if you are running healthcare
  341. 12:58workloads in the US and need to sign a
  342. 13:01BAA that is a business associate
  343. 13:03agreement
  344. 13:05required for HIPAA compliance that's
  345. 13:08done through artifact. Then we have AWS
  346. 13:11audit manager. Audit manager works
  347. 13:13completely differently. It continuously
  348. 13:16collects evidence about your account's
  349. 13:18own activity and automatically maps that
  350. 13:20evidence against pre-built compliance
  351. 13:22frameworks like GDPR, PCIDSS and HIPA.
  352. 13:26This is designed to help you prepare for
  353. 13:28an actual audit of your own uh usage of
  354. 13:30uh AWS by automatically gathering the
  355. 13:32proof you will need to sow an auditor.
  356. 13:34Here's the single sentence that will
  357. 13:36lock this in forever. Artifact is equal
  358. 13:39to paperwork about AWS and audit manager
  359. 13:43is equal to evidence about your uses of
  360. 13:45AWS. Both of these tools reinforce
  361. 13:48something called the shared
  362. 13:49responsibility model. A concept you have
  363. 13:51already likely come across in this
  364. 13:53course where AWS is responsible for the
  365. 13:55security of the cloud that is their own
  366. 13:58infrastructure and you the customer are
  367. 14:00responsible for security in the cloud
  368. 14:03that is how you configure and use it.
  369. 14:05Artifact proves what AWS has already
  370. 14:08secured and audit manager helps you
  371. 14:10prove what you and the customer have
  372. 14:13properly secured.
  373. 14:15So there is an favorite exam trap that
  374. 14:18is where do I download AWS SOC2 report.
  375. 14:21If it's asked like that you will answer
  376. 14:24it as AWS artifact.
  377. 14:27And if asked where do I gather evidence
  378. 14:29that my workload is PCI compliant? See
  379. 14:32it's your workload and you need to find
  380. 14:34if that is PCI compliant or not. You can
  381. 14:37check that in AWS audit manager. You can
  382. 14:39get the evidence there. Let's move into
  383. 14:42our final two services for today. These
  384. 14:45are both about making day-to-day
  385. 14:47operations easier and safer. First is
  386. 14:50AWS Systems Manager. AWS Systems Manager
  387. 14:53is a unified operations hub for managing
  388. 14:56a whole fleet of servers without needing
  389. 14:58to individually log into each one. So
  390. 15:01what this does is it bundles together
  391. 15:03several useful sub features.
  392. 15:06So what sub features include? Sub
  393. 15:08features can include run command, patch
  394. 15:10manager, parameter store, sessions
  395. 15:13manager. Let us understand what do these
  396. 15:16features actually mean. Run commands
  397. 15:18means remotely executing scripts or
  398. 15:20commands across many servers at once
  399. 15:22without manually connecting to each one.
  400. 15:25We have patch manager that automates the
  401. 15:27process of applying operating system
  402. 15:28patches and security updates across your
  403. 15:30fleet. We also have parameter store that
  404. 15:33is a secure place to store configuration
  405. 15:36values and secrets encrypted so that
  406. 15:38your application can pull them at
  407. 15:40runtime instead of hard coding them. We
  408. 15:42have another that is session manager.
  409. 15:44This is the big one to remember. It
  410. 15:46gives you the browserbased cell
  411. 15:48connection directly to an EC2 instance
  412. 15:50without needing to open the traditional
  413. 15:52SSH port 22 at all. We also have another
  414. 15:55service that is AWS trusted advisor.
  415. 15:58Trusted adviser is like having an
  416. 16:00automated consultant constantly
  417. 16:02reviewing your AWS account and telling
  418. 16:04you where you are not following best
  419. 16:05practices. It performs automated and
  420. 16:08real-time checks across five categories.
  421. 16:10So understand these five categories. We
  422. 16:13have cost optimization that is finding
  423. 16:15ways to reduce your AWS spending.
  424. 16:18Performance. Performance means finding
  425. 16:20ways to improve how your resources
  426. 16:21perform. We have another that is
  427. 16:24security finding security gaps like uh
  428. 16:27overly open security groups. We have
  429. 16:30another that is fault tolerance that
  430. 16:31means finding weak spots in your
  431. 16:33resilience and backup setup. The fifth
  432. 16:35one is service limits that is warning
  433. 16:37you before you hit an AWS account limit
  434. 16:40that could disrupt your operations.
  435. 16:43So trusted advisor scale with your
  436. 16:45support plan. This is an important
  437. 16:47detail. The number of checks you get
  438. 16:50access to depends on AWS support plan.
  439. 16:53If you are on the basic or developer
  440. 16:54support plan, you only get seven core
  441. 16:56checks and those are limited to just
  442. 16:58security and service limit. But if you
  443. 17:00upgrade to business support or higher,
  444. 17:02you unlock the full set of over 150
  445. 17:04checks spanning all the five categories.
  446. 17:08And the next thing we have AWS health
  447. 17:12dashboard. Quickly worth mentioning the
  448. 17:14AWS health dashboard gives you an
  449. 17:16account specific reason aware view of
  450. 17:19event that specifically affect your
  451. 17:20resources like a schedule maintenance
  452. 17:22window for any CC2 instance you actually
  453. 17:24own or this that is this is different
  454. 17:26from the public service health dashboard
  455. 17:29which shows the overall global operation
  456. 17:31status of AWS services for everyone
  457. 17:33regardless of what you personally use.
  458. 17:36Here is an exam trap for you all to
  459. 17:37remember. Session manager lets you
  460. 17:40manage an EC2 instance without opening
  461. 17:41inbound port 22. What's that? This is
  462. 17:45the recurring best security practice
  463. 17:47answer that shows up repeatedly across
  464. 17:49different exam scenarios. Whenever a
  465. 17:51question emphasizes reducing your attack
  466. 17:53surface by avoiding open SS ports,
  467. 17:56session manager is likely the correct
  468. 17:58answer.
  469. 18:00All right, time to put these all the
  470. 18:03three core services into action
  471. 18:04together. In this lab, we are going to
  472. 18:06build a small but complete workflow that
  473. 18:08touches cloudatch, AWS config and cloud
  474. 18:11trail. I will show you exactly how these
  475. 18:14three services work together in a real
  476. 18:15world scenario.
  477. 18:18So first of all go to AWS console and
  478. 18:21search for cloudatch
  479. 18:23and you can see cloudatch is over here.
  480. 18:25Open the service and in the left
  481. 18:26navigation uh find alarms
  482. 18:30and click on create alarm. Select the
  483. 18:33metric you want to monitor. For this
  484. 18:34lab, we will monitor ECU CPU utilization
  485. 18:37uh on one of our existing EC2 instances.
  486. 18:41Uh let's say if my uh instance is not
  487. 18:44running, I will go and create one
  488. 18:46instance. Okay. Now, yes.
  489. 18:50So, under the action section, configure
  490. 18:52the alarm to trigger an SNS
  491. 18:54notification.
  492. 18:56This means when the threshold is
  493. 18:58crossed, an email will automatically be
  494. 19:00sent after you. Give your alarm a clear
  495. 19:02descriptive name like high CP all and
  496. 19:06click on create alarm. Once your alarm
  497. 19:09is created, check the email inbox you
  498. 19:11used for the SNS topic. You should
  499. 19:14receive a confirmation email from the
  500. 19:15AWS. You must click the confirmation
  501. 19:18link inside that email. And if you skip
  502. 19:21this step, the alert notification will
  503. 19:23never actually reach you even if the
  504. 19:26alarm triggers correctly on the back
  505. 19:27end.
  506. 19:29Now head over to the AWS config service
  507. 19:31in the console. If this is your first
  508. 19:34time using config in this in AWS
  509. 19:36account, then you need to enable it. Um,
  510. 19:40okay.
  511. 19:43Once navigated, navigate to rules and
  512. 19:46add a new rule. For this lab, look for
  513. 19:49AWS manage rule called restricted SSH.
  514. 19:53This is a pre-built rule that
  515. 19:54automatically checks whether any of your
  516. 19:56security groups allow unrestricted
  517. 19:58accesses access from the entire internet
  518. 20:00which is a well-known security risk.
  519. 20:04So add this rule and let config begin
  520. 20:06evaluating your resources against it.
  521. 20:10After giving config a few minutes to
  522. 20:12evaluate your account, go to your config
  523. 20:13dashboard and look at the rules section.
  524. 20:17You will see each applicable resources
  525. 20:20marked as either compliant or
  526. 20:22non-compliant against the restricted SSH
  527. 20:24rule.
  528. 20:25If any of security group shows up as
  529. 20:27non-compliant, that config is doing
  530. 20:30exactly stop and flagging a real
  531. 20:31configuration risk in the AWS account.
  532. 20:34Finally, let's choose the loop. Head
  533. 20:37over to CloudFront and open event
  534. 20:39history.
  535. 20:41Search for related events related to
  536. 20:42security group modification. Especially
  537. 20:44look for API actions like authorized
  538. 20:48security group ingress which is the
  539. 20:49action AWS logs whenever an inbound role
  540. 20:52is added to a security group. Find the
  541. 20:54exact event that caused the flag change
  542. 20:56and look at the event details. You will
  543. 20:58be able to see exactly which IM user or
  544. 21:00role made that change and the precise
  545. 21:03time stamp it happened. Putting it all
  546. 21:07together, look at what we just did. This
  547. 21:10single lab worked through the entire uh
  548. 21:12real world workflow that is AWS config
  549. 21:14told us what changed and whether it's
  550. 21:16compliant or not. Cloudfare told us who
  551. 21:19made that change and when and cloudatch
  552. 21:21is standing by in the background ready
  553. 21:23to alert us at the any moment any
  554. 21:26resource performance crosses a dangerous
  555. 21:28threshold. This is precisely how real
  556. 21:31cloud security and operations teams work
  557. 21:33dayto-day. These three services aren't
  558. 21:35isolated tools. They are connected
  559. 21:37system that give you complete
  560. 21:39visibility, complete accountability and
  561. 21:41complete control over your AWS
  562. 21:43environment.
  563. 21:44Fantastic work today. Let's lock in this
  564. 21:47crucial trio with the clean final recap.
  565. 21:49We have cloudatch that is uh equal to
  566. 21:52monitor resource performance that is
  567. 21:54metrics, alarms, logs and dashboards. We
  568. 21:57have cloud trail cloud trail audit who
  569. 21:59did what and when and from where
  570. 22:02complete API activity history. We have
  571. 22:05config that is to use to track what
  572. 22:07changed and monitor compliance drift
  573. 22:09over time. Artifact AWS own compliance
  574. 22:13reports and audit manager means evidence
  575. 22:16of your compliance. System manager equal
  576. 22:19to SSH free fleet operations. Trusted
  577. 22:21advisor equal to automated best practice
  578. 22:24checks across five categories scaling
  579. 22:27with your support plan. So for homework
  580. 22:30tonight complete 10 practice question
  581. 22:31from the portal and this trial that is
  582. 22:34cloudatch cloud trail and config. This
  583. 22:37is a guaranteed exam topic meaning you
  584. 22:40can expect it to see tested in multiple
  585. 22:43different question formats. Make sure
  586. 22:45that the three-way distinction is
  587. 22:46absolutely rock solid before moving on
  588. 22:49and a look ahead to tomorrow. Day 18
  589. 22:52takes us into infrastructure escort that
  590. 22:54is elasticity identity federation and
  591. 22:57multi-account governance. We are going
  592. 22:59to be building on today's governance
  593. 23:01foundation and expanding into how large
  594. 23:03organization manage AWS accounts at
  595. 23:05scale. That's a wrap for day 17. You now
  596. 23:09have complete clarity on one of the most
  597. 23:12confused topic in the AWS entire exam.
  598. 23:15You know exactly when to reach for cloud
  599. 23:17watch, when to reach for cloud trail and
  600. 23:19when to reach for config. And you have
  601. 23:21seen with your own hands how all three
  602. 23:23work together in a real workflow. Great
  603. 23:26job today. Go ahead and complete the
  604. 23:28practice questions. I will see you
  605. 23:30tomorrow for day 18. Keep that momentum
  606. 23:33going. Thank you.

About this transcript

This page contains the full transcript of AWS Monitoring & Governance Explained | CloudWatch vs CloudTrail vs Config | CLF-C02 Day 17 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 3,798 words across 606 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.