AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

Your company runs an API behind an Application Load Balancer that is protected by an AWS WAFv2 web ACL. Security engineers must audit every request that AWS WAF blocks, keep the detailed records for at least 30 days, and let analysts run ad-hoc SQL queries on this data with minimal operations effort and cost. Which solution meets these requirements?

  • Publish AWS WAF metrics to Amazon CloudWatch, retain the metrics for 30 days, and analyze them with CloudWatch Logs Insights.

  • Turn on Application Load Balancer access logging to S3 and have analysts use Amazon Athena to search for HTTP 403 responses.

  • Enable AWS WAF logging and configure a Kinesis Data Firehose delivery stream that sends the logs to an S3 bucket with a 30-day lifecycle policy; analysts query the data with Amazon Athena.

  • Enable AWS CloudTrail data events for the load balancer and stream the logs to Amazon OpenSearch Service for querying.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot