DEA-C01 exam dumps

DEA-C01 practice question 507 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 507

Select 3

Your company requires all application logs stored in Amazon S3 to be prepared for audit purposes. The logs must be encrypted, organized by compliance year, and automatically archived after 90 days. Which combination of actions should you take to meet these requirements?

  1. A

    Enable server-side encryption (SSE) with AWS Key Management Service (KMS) for the S3 bucket storing the logs.

  2. B

    Organize the logs in S3 folders based on the compliance year, such as 'logs/2023/', 'logs/2024/', etc.

  3. C

    Set up an S3 Lifecycle policy to transition logs older than 90 days to Amazon Glacier Deep Archive.

  4. D

    Use AWS CloudTrail to track S3 bucket activity and automatically generate compliance reports.

  5. E

    Enable S3 Object Lock with Compliance mode to prevent logs from being deleted or modified.

Show answer and explanation

Correct answers: A, B, C

Explanation

To prepare logs for audit in this scenario, the logs need to be encrypted, organized by compliance year, and archived after 90 days. Enabling server-side encryption (SSE) with AWS KMS ensures data security. Organizing logs by compliance year makes them easy to access for audit purposes. Setting up an S3 Lifecycle policy to move older logs to Glacier Deep Archive meets the requirement for automatic archiving while optimizing costs. Other options, like CloudTrail and S3 Object Lock, address different compliance needs but do not directly solve the requirements stated in the scenario.

  • A. Correct.

    This is correct because enabling server-side encryption (SSE) with AWS KMS ensures that all logs stored in the S3 bucket are encrypted. This is a crucial step for meeting security and compliance requirements.

  • B. Correct.

    This is correct because organizing logs into folders by compliance year makes it easier to retrieve and audit logs for a specific time period, which aligns with audit preparation best practices.

  • C. Correct.

    This is correct because setting up an S3 Lifecycle policy to transition logs to Amazon Glacier Deep Archive after 90 days ensures cost-effective long-term storage and satisfies the archiving requirement.

  • D. Incorrect.

    This is incorrect because AWS CloudTrail monitors bucket activity and generates logs, but it does not help with preparing existing logs for audit purposes, such as encryption or lifecycle management.

  • E. Incorrect.

    This is incorrect because enabling S3 Object Lock in Compliance mode prevents deletion or modification of objects, which may be an additional compliance measure but is not directly related to preparing logs for audit as described in this scenario.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam