AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company has associated a Route 53 Resolver DNS Firewall rule group with several production VPCs to block known malware domains. An auditor requires proof that the blocking rules are enforced and insists that the DNS log records be retained for at least 5 years at the lowest possible cost. Which solution meets these requirements with the least operational overhead?
Turn on Route 53 Resolver query logging to CloudWatch Logs and create a subscription filter that forwards the logs to an S3 bucket.
Enable AWS CloudTrail Lake and periodically join CloudTrail management events with VPC Flow Logs to infer blocked DNS requests.
Enable Route 53 Resolver query logging for the production VPCs and write the logs directly to an Amazon S3 bucket that has a lifecycle policy to transition objects to the S3 Glacier Flexible Retrieval storage class after 30 days.
Configure Amazon GuardDuty DNS Malware Protection and export its findings to AWS Security Hub for long-term retention.
Route 53 Resolver query logging can stream logs directly to an Amazon S3 bucket. Each entry includes the query_name plus DNS Firewall fields such as firewall_rule_group_id and firewall_rule_action, demonstrating that the rule evaluated the request. Applying an S3 lifecycle policy moves older objects to S3 Glacier Flexible Retrieval, providing inexpensive five-year retention with no additional infrastructure. Sending logs first to CloudWatch or relying on CloudTrail, VPC Flow Logs, or GuardDuty adds cost or lacks per-query evidence.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Route 53 Resolver DNS Firewall?
Open an interactive chat with Bash
How does an S3 lifecycle policy work?
Open an interactive chat with Bash
What data does Route 53 Resolver query logging capture?
Open an interactive chat with Bash
What is Route 53 Resolver DNS Firewall?
Open an interactive chat with Bash
What is an S3 lifecycle policy and how does it help with cost optimization?
Open an interactive chat with Bash
Why is Route 53 Resolver query logging sent directly to S3 preferred over CloudWatch Logs for this scenario?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .