0PricingLogin
AWS Security Academy · Lesson

Auditing and Logging Admin Sessions

Record every command an operator runs for accountability.

Accountability for Admins

Granting administrative access is only half the job; you must also record what administrators do. Session Manager provides rich logging so every command and session is accountable. The SCS-C02 exam stresses this auditability as a core advantage over SSH, where command-level logging is hard to centralize.

Two Layers of Logging

Session Manager logging has two layers: API-level logging of who started and stopped sessions, captured by CloudTrail, and session-content logging of the actual keystrokes and output, sent to CloudWatch Logs or S3. Together they answer both "who connected" and "what did they do."

All lessons in this course

  1. Why Bastion Hosts Add Risk
  2. Session Manager Without Open Ports
  3. Auditing and Logging Admin Sessions
  4. Hardening Endpoints and Patch Manager
← Back to AWS Security Academy