DEA-C01 exam dumps

DEA-C01 practice question 372 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 372

Select 2

A data engineering team needs to log all access requests made to their AWS S3 buckets for compliance purposes. They want to capture detailed information about who accessed the buckets, the actions performed, and the request sources. Which of the following steps should they take to enable comprehensive logging of access to their S3 buckets?

  1. A

    Enable S3 server access logging on the bucket and specify a target bucket to store the logs.

  2. B

    Enable AWS CloudTrail logging for S3 data events and configure an S3 bucket as the destination for the logs.

  3. C

    Enable VPC Flow Logs for the VPC where the S3 bucket resides to capture access logs.

  4. D

    Use AWS Config to track changes to the S3 bucket's resource configuration.

  5. E

    Enable CloudWatch Logs for the S3 bucket to capture detailed access logs.

Show answer and explanation

Correct answers: A, B

Explanation

To comprehensively log access to S3 buckets, you need to enable S3 server access logging for bucket-level request tracking and AWS CloudTrail logging for detailed API-level data events. These two mechanisms together provide the necessary granularity and compliance data to monitor and audit S3 access effectively. VPC Flow Logs, AWS Config, and CloudWatch Logs do not meet the specific requirements for logging S3 access requests.

  • A. Correct.

    S3 server access logging provides detailed records of the requests made to a bucket, including bucket-level actions. However, it does not capture information such as user identity or API calls, which is why it should be combined with other logging mechanisms.

  • B. Correct.

    AWS CloudTrail can be configured to log S3 data events, which include API-level actions performed on objects within a bucket. This is essential for capturing detailed access information, such as who made the request and what actions were taken.

  • C. Incorrect.

    VPC Flow Logs capture network flow information for a VPC, such as IP traffic. They do not provide specific details about S3 bucket access or API calls, so this option is not relevant for logging S3 access.

  • D. Incorrect.

    AWS Config tracks configuration changes to AWS resources, not access events. This does not fulfill the requirement to log access requests to S3 buckets.

  • E. Incorrect.

    CloudWatch Logs cannot directly log S3 access requests. It is used for collecting and monitoring application or system logs, but not for tracking S3 access events.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam