DEA-C01 exam dumps

DEA-C01 practice question 522 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 522

Select 3

You are a data engineer working for an organization that heavily uses AWS services like Amazon S3, Amazon Redshift, and AWS Glue. The security team has requested that you enable logging for access to these services to monitor potential unauthorized access or anomalies. Which of the following actions should you take to meet this requirement?

  1. A

    Enable AWS CloudTrail and configure it to log management and data events.

  2. B

    Enable S3 access logs for all S3 buckets storing sensitive data.

  3. C

    Configure AWS Config to track API calls and resource changes.

  4. D

    Enable Amazon Redshift Audit Logging for tracking queries and connections.

  5. E

    Set up VPC Flow Logs to capture detailed access patterns for services.

Show answer and explanation

Correct answers: A, B, D

Explanation

To log access to AWS services effectively, multiple logging mechanisms should be used depending on the specific service. AWS CloudTrail provides a centralized way to log API calls for most AWS services, S3 access logs capture detailed access information for S3 buckets, and Redshift Audit Logging captures activity within Amazon Redshift. AWS Config and VPC Flow Logs serve different purposes and are not directly relevant to logging access to AWS services.

  • A. Correct.

    Correct. AWS CloudTrail is designed to log API calls for AWS services, including management and data events, making it an essential tool for monitoring access to AWS services.

  • B. Correct.

    Correct. S3 access logs specifically track requests made to S3 buckets, providing detailed information on who accessed the data and when.

  • C. Incorrect.

    Incorrect. AWS Config is used to track resource configurations and compliance, but it does not log API calls or access to AWS services directly.

  • D. Correct.

    Correct. Redshift Audit Logging is specifically designed for tracking user activity, queries, and connections within Amazon Redshift.

  • E. Incorrect.

    Incorrect. VPC Flow Logs monitor network traffic within a VPC and are not designed to capture detailed access patterns for services like S3 or Redshift.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam