DOP-C02 exam dumps

DOP-C02 practice question 214 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 214

Single answer

Your organization has a multi-account setup in AWS and you are tasked with implementing a centralized logging solution for all accounts using Amazon OpenSearch Service. The logs must be ingested securely from multiple accounts, and access to the logs should be restricted based on IAM roles. Which approach should you take to meet these requirements?

  1. A

    Set up Amazon OpenSearch Service in a central logging account and configure Amazon S3 bucket policies in each source account to send logs to the central account.

  2. B

    Deploy OpenSearch Service in every account and configure cross-account access using VPC peering.

  3. C

    Set up Amazon OpenSearch Service in a central logging account and use AWS Kinesis Data Firehose in each source account to stream logs securely to the OpenSearch domain.

  4. D

    Use AWS CloudWatch Logs Insights in each account to analyze logs and centralize the results into the central OpenSearch Service domain.

Show answer and explanation

Correct answer: C

Explanation

The best approach for centralized logging in a multi-account setup is to use Amazon OpenSearch Service in a central logging account and AWS Kinesis Data Firehose in each source account. Kinesis Data Firehose provides secure, scalable data streaming from multiple accounts into a centralized OpenSearch Service domain. It supports fine-grained access control using IAM roles and policies, ensuring secure and compliant log ingestion.

  • A. Incorrect.

    This option does not directly address how logs from multiple accounts are securely ingested into a centralized OpenSearch Service instance, and it does not utilize Kinesis Data Firehose, which is a recommended service for such scenarios.

  • B. Incorrect.

    Deploying OpenSearch Service in every account would lead to unnecessary complexity and costs. Using VPC peering for cross-account access is not a scalable or recommended approach for centralized logging.

  • C. Correct.

    This is the correct approach. AWS Kinesis Data Firehose can securely stream logs from multiple accounts into a centralized OpenSearch Service domain. It supports transformations and ensures secure transmission of data using IAM roles and policies.

  • D. Incorrect.

    This is not a valid solution as CloudWatch Logs Insights is used for querying and analyzing logs but does not support direct centralization of logs across accounts into OpenSearch Service.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam