AWS Certified Data Engineer Associate DEA-C01 Practice Question
A data engineering team runs Amazon EC2-based Spark jobs in two AWS Regions. Compliance requires that application log files from /var/log/app.log on every instance be centralized in Amazon CloudWatch Logs and automatically deleted after 90 days. Which approach satisfies the requirements with minimal operational overhead?
Write the log files to an Amazon S3 bucket that has a lifecycle rule to expire objects after 90 days, and query the logs with Amazon Athena.
Configure VPC Flow Logs on the instances' subnets with 90-day retention and use CloudWatch Logs Insights to analyze the data.
Enable AWS CloudTrail in both Regions and set its retention to 90 days; CloudTrail will capture the application log entries automatically.
Create a CloudWatch Logs log group, set its retention to 90 days, and install the CloudWatch agent on each instance to monitor /var/log/app.log.
The CloudWatch agent can be installed on each EC2 instance and configured to monitor specific files such as /var/log/app.log. When the agent sends those files to a designated CloudWatch Logs log group, the team can set the log group's retention policy to 90 days so that CloudWatch automatically deletes older log events. This solution keeps the logs in CloudWatch Logs as required and requires no custom code or additional infrastructure.
The other choices do not meet the stated needs:
AWS CloudTrail records AWS API calls, not arbitrary application log files.
Storing logs directly in Amazon S3 with a lifecycle rule meets retention needs but does not place the data in CloudWatch Logs.
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of CloudWatch Logs retention policies?
Open an interactive chat with Bash
How does the CloudWatch agent monitor specific log files like /var/log/app.log?
Open an interactive chat with Bash
Why are VPC Flow Logs unsuitable for monitoring application logs?
Open an interactive chat with Bash
What role does the CloudWatch agent play in this solution?
Open an interactive chat with Bash
Why is CloudTrail not suitable for collecting application logs?
Open an interactive chat with Bash
How does the CloudWatch Logs retention policy work?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .