AWS Certified Data Engineer Associate DEA-C01 Practice Question
Your company runs a multi-account AWS environment with AWS Organizations. The data engineering team must audit every read or write operation on a data-lake Amazon S3 bucket and all administrative actions performed on Amazon Redshift clusters. Logs must be stored automatically in a log-archive account with minimal ongoing maintenance. Which solution meets these requirements?
Create an organization-level AWS CloudTrail trail that records management events for all regions and adds S3 data events for the data-lake bucket, directing the trail to an S3 bucket in the log-archive account.
Turn on AWS Config in every account to record all resources and aggregate configuration snapshots into an S3 bucket in the log-archive account.
Deploy Lambda@Edge functions in front of the S3 bucket and Redshift endpoint that record request information and send it through Kinesis Data Firehose to the log-archive account.
Enable S3 server access logging on the bucket and activate Redshift database audit logging to CloudWatch Logs; use a CloudWatch Logs subscription filter to forward logs to the log-archive account.
An AWS Organizations-level CloudTrail trail can be configured once and automatically applies to every current and future member account. Management events recorded by CloudTrail capture all control-plane API calls, which include administrative actions on Amazon Redshift. S3 data events record object-level read and write operations on the specified bucket. When the trail's destination is an S3 bucket in the log-archive account, all accounts deliver their CloudTrail logs centrally without additional setup or custom code. The other options either fail to capture all required actions, rely on service-specific features that do not cover both services, or introduce unnecessary operational overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS CloudTrail?
Open an interactive chat with Bash
What are S3 Data Events?
Open an interactive chat with Bash
How does AWS Organizations improve multi-account logging?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .