AWS Certified Data Engineer Associate DEA-C01 Practice Question

An enterprise has 30 AWS accounts in an AWS Organization. Compliance mandates that all API activity logs be retained for 7 years in immutable storage and that auditors can run ad-hoc SQL queries across the aggregated logs without building or managing ETL jobs. Which approach most effectively meets these requirements with minimal operational effort?

  • Create an organization-level CloudTrail Lake event data store with a 7-year retention period and grant auditors read-only Lake query permissions.

  • Enable AWS Config in all accounts, aggregate configuration snapshots to a central S3 bucket, and query the data with Athena.

  • Stream all CloudTrail events to CloudWatch Logs, forward them with Kinesis Data Firehose to Amazon OpenSearch Service, and allow auditors to run searches from Kibana.

  • In each account, configure CloudTrail to deliver logs to an S3 bucket protected by S3 Object Lock, then catalog the buckets with AWS Glue and query them using Amazon Athena.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot