AWS Certified Data Engineer Associate DEA-C01 Practice Question
Your company has an organization-wide trail that already sends all management events to CloudTrail Lake. An auditor now needs to record every DeleteObject API call made against the S3 bucket prod-data-lake, but logging other buckets must not increase CloudTrail charges. What is the MOST cost-effective way to meet this requirement?
Enable CloudTrail Insights for object-level activity on the current event data store.
Turn on Amazon S3 server access logging for the prod-data-lake bucket and query the logs in Athena.
Create a new multi-Region trail that logs S3 data events for all buckets in the organization.
Update the existing organization trail with an advanced event selector that logs Write data events for the prod-data-lake bucket only.
CloudTrail management events are logged automatically, but object-level S3 actions such as DeleteObject are data events that are not captured unless explicitly enabled. Updating the existing organization trail with an advanced event selector that logs only Write data events (which includes DeleteObject) for the specific prod-data-lake bucket records the required API calls. Because data-event billing is $0.10 per 100,000 events, scoping the selector to a single bucket avoids charges from other buckets. S3 server access logging produces access logs outside of CloudTrail and does not provide the same level of IAM identity detail needed for audits. Creating a new trail for every bucket would meet the requirement but would incur unnecessary data-event costs. CloudTrail Insights analyzes anomalies in management-event patterns and does not capture individual DeleteObject operations. Therefore, refining the current trail with a bucket-specific advanced event selector is the most economical and compliant solution.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are CloudTrail data events and management events?
Open an interactive chat with Bash
How do advanced event selectors in CloudTrail work?
Open an interactive chat with Bash
Why is it more cost-effective to refine an existing trail than to create a new trail?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .