🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 7 hours remaining!

AWS Certified Data Engineer Associate DEA-C01 Practice Question

Your company has ten AWS accounts under AWS Organizations. For compliance, the data engineering team must: capture all API activity in every account, store the logs centrally in a dedicated log-archive account for 7 years using immutable storage, and allow auditors to run ad-hoc SQL queries on the logs without copying them to another system. Which solution meets these requirements with the least operational effort?

  • Enable CloudTrail in every account and stream the logs from Amazon CloudWatch Logs to a centralized Amazon OpenSearch Service cluster, giving auditors Kibana access for queries.

  • Turn on AWS Config aggregation across the organization, store configuration snapshots in an S3 bucket with Object Lock, and let auditors query the snapshots with AWS Config advanced queries.

  • Create a single organization CloudTrail that delivers logs to an S3 bucket in the log-archive account with S3 Object Lock enabled. Enable CloudTrail Lake in that account and grant auditors read-only access to a 7-year event data store.

  • Run an AWS Glue crawler in each account to crawl local CloudTrail S3 logs and load them into a shared Amazon Redshift cluster that auditors can query.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot