DEA-C01 exam dumps

DEA-C01 practice question 523 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 523

Select 2

A data engineering team at your company wants to track and log access to AWS services in their account for compliance and auditing purposes. They aim to log all API requests made to AWS services and store the logs securely for at least 180 days. Which solution meets these requirements?

  1. A

    Enable AWS CloudTrail and configure it to log all management and data events for all AWS services.

  2. B

    Use AWS Config to log API requests and store configuration changes for at least 180 days.

  3. C

    Store CloudTrail logs in an S3 bucket with an appropriate lifecycle policy to retain logs for at least 180 days.

  4. D

    Enable Amazon GuardDuty to monitor and log access to AWS services.

  5. E

    Configure AWS Identity and Access Management (IAM) to log all API activity.

Show answer and explanation

Correct answers: A, C

Explanation

To log access to AWS services, AWS CloudTrail must be enabled to record management and data events for API activity. The logs can then be stored securely in an S3 bucket with a lifecycle policy to retain them for at least 180 days, meeting both the logging and retention requirements. AWS Config, GuardDuty, and IAM do not directly address the requirement to log API requests.

  • A. Correct.

    Enabling AWS CloudTrail to log all management and data events ensures that all API requests to AWS services are tracked and logged. This is the core service for logging access to AWS services.

  • B. Incorrect.

    AWS Config tracks configuration changes rather than logging API requests. While it is useful for compliance and auditing, it does not meet the requirement to log API requests to AWS services.

  • C. Correct.

    Storing CloudTrail logs in an S3 bucket with an appropriate lifecycle policy ensures the logs are securely stored and retained for the required duration of 180 days.

  • D. Incorrect.

    Amazon GuardDuty is used to detect threats and anomalies in your AWS environment, but it does not log API requests or access to AWS services.

  • E. Incorrect.

    IAM manages permissions and access controls, but it does not provide a mechanism to log API requests or access logs.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam