AWS Certified Data Engineer Associate DEA-C01 Practice Question

A security team needs to audit API activity across 50 AWS accounts that belong to a single AWS Organization. They must aggregate all CloudTrail management events in near-real time, keep the logs immutable for 365 days, and let analysts run ad-hoc SQL queries without exporting the data to another service. Which solution requires the LEAST ongoing operational effort?

  • In each member account, stream CloudTrail events to CloudWatch Logs and subscribe the log groups to an Amazon OpenSearch Service domain for search and analysis.

  • Configure an organization CloudTrail trail that delivers logs to an S3 bucket protected with S3 Object Lock, catalog the logs with AWS Glue, and query them using Amazon Athena.

  • Create an organization event data store in AWS CloudTrail Lake from the delegated administrator account, set one-year extendable retention, and grant analysts permission to run Lake SQL queries.

  • Enable Amazon Security Lake across the organization to collect CloudTrail management events and query the Parquet files in the Security Lake S3 buckets with Athena.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot