AWS Certified Data Engineer Associate DEA-C01 Practice Question
A company has 10 AWS accounts in AWS Organizations and must comply with an audit requirement to retain all API activity logs centrally for 7 years. Data engineers need to run ad-hoc SQL queries across this history with minimal operational overhead. Which solution meets the requirement MOST effectively?
Enable Amazon EventBridge Archive in every account to export all events to individual S3 buckets, then schedule Athena queries that join the buckets.
Configure CloudWatch Logs subscription filters in each account to send logs to a cross-account Kinesis Data Firehose that writes to Amazon OpenSearch Service for search.
Schedule an AWS Lambda function in the audit account to call CloudTrail LookupEvents for each member account and store the output in DynamoDB tables for analysis.
Create an organization-wide CloudTrail trail that stores logs in an S3 bucket in a dedicated audit account and automatically copy events into a CloudTrail Lake event data store for SQL querying.
An organization-wide CloudTrail trail writes a single, immutable copy of every member account's events to a central Amazon S3 bucket. CloudTrail can automatically copy those trail files into a CloudTrail Lake event data store, where auditors and engineers can run SQL-compatible queries across multiple Regions and accounts without building additional pipelines. The other approaches either collect logs per account, depend on custom export code, or store data in services (OpenSearch, DynamoDB) that are not optimized for long-term audit retention and SQL analysis, increasing cost and operational burden.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS CloudTrail and its purpose?
Open an interactive chat with Bash
How does CloudTrail Lake simplify SQL querying for audit purposes?
Open an interactive chat with Bash
What are the key differences between CloudTrail logs stored in S3 and a CloudTrail Lake event data store?
Open an interactive chat with Bash
What is AWS CloudTrail Lake?
Open an interactive chat with Bash
Why use CloudTrail for auditing API activity?
Open an interactive chat with Bash
How does CloudTrail Lake differ from Amazon Athena?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .