DEA-C01 exam dumps

DEA-C01 practice question 509 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 509

Select 3

An organization wants to prepare its application logs for audit purposes. They use Amazon S3 to store logs generated by multiple AWS services. The audit team requires logs to be retained for 7 years, encrypted at rest, and easily queried using SQL for audit reviews. Which of the following steps should you take to meet these requirements?

  1. A

    Enable S3 Versioning and configure a lifecycle rule to transition logs to S3 Glacier after 7 years.

  2. B

    Use AWS Glue to catalog the logs stored in S3 and query them using Amazon Athena.

  3. C

    Enable S3 Server-Side Encryption (SSE) with an AWS Key Management Service (KMS) key for encryption at rest.

  4. D

    Configure S3 Object Lock to enforce a compliance retention period of 7 years.

  5. E

    Set up an Amazon CloudWatch Log Group to directly query logs stored in CloudWatch using SQL.

Show answer and explanation

Correct answers: B, C, D

Explanation

To prepare logs for audit, the solution must address retention, encryption, and query requirements. AWS Glue and Amazon Athena enable SQL-based querying of logs stored in S3. SSE with a KMS key ensures encryption at rest. S3 Object Lock ensures compliance with the 7-year retention requirement. Transitioning logs to Glacier or using CloudWatch Logs are not suitable for this use case due to the constraints of querying and retention policies.

  • A. Incorrect.

    This option is incorrect because transitioning logs to S3 Glacier after 7 years conflicts with the requirement of retaining logs for 7 years. Glacier is suitable for long-term archival, but the requirement here is for querying logs within the 7-year duration.

  • B. Correct.

    This option is correct because using AWS Glue to catalog the logs allows the audit team to easily query logs using SQL through Amazon Athena, fulfilling the querying requirement.

  • C. Correct.

    This option is correct because enabling SSE with an AWS KMS key ensures logs are encrypted at rest, meeting the encryption requirement.

  • D. Correct.

    This option is correct because S3 Object Lock in compliance mode can enforce the 7-year retention period, ensuring logs cannot be altered or deleted during the required time frame.

  • E. Incorrect.

    This option is incorrect because CloudWatch Log Groups are not designed for SQL-based querying of logs stored in S3. Amazon Athena is the correct tool for querying S3 logs.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam