DEA-C01 exam dumps

DEA-C01 practice question 374 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 374

Select 2

You are a data engineer tasked with ensuring all access to your company's AWS services is logged for security and compliance purposes. Which of the following steps should you take to achieve this? (Select TWO.)

  1. A

    Enable AWS CloudTrail in all regions to log API and management console activity.

  2. B

    Set up AWS Config to monitor access patterns in real time.

  3. C

    Enable S3 Server Access Logging to capture object-level access requests in your S3 buckets.

  4. D

    Activate VPC Flow Logs to capture service-level access logs for all AWS services.

  5. E

    Ensure CloudTrail logs are stored in a secure and encrypted S3 bucket.

Show answer and explanation

Correct answers: A, E

Explanation

To log access to AWS services, enabling AWS CloudTrail is essential as it provides detailed logs of API and management console activity. Additionally, ensuring that these logs are securely stored in an encrypted S3 bucket helps maintain compliance and data security. Other options, such as AWS Config or VPC Flow Logs, serve different monitoring purposes and do not provide comprehensive service access logging.

  • A. Correct.

    Correct. AWS CloudTrail is the primary service used to log API and management console activity for all AWS services. Enabling it in all regions ensures comprehensive access logging.

  • B. Incorrect.

    Incorrect. AWS Config is used for resource configuration tracking and compliance auditing, not access logging.

  • C. Incorrect.

    Incorrect. S3 Server Access Logging is specific to S3 bucket access logs and doesn't cover all AWS services. It is not a comprehensive solution for logging access to AWS services.

  • D. Incorrect.

    Incorrect. VPC Flow Logs capture network traffic metadata, not service-level access logs. They are useful for network monitoring but do not log access to AWS services comprehensively.

  • E. Correct.

    Correct. Ensuring CloudTrail logs are securely stored in an encrypted S3 bucket is a best practice to safeguard the integrity and confidentiality of audit records.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam