exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 506 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 506
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company wants to analyze Amazon EC2 performance and utilization data in near real time for anomalies. The information that the company needs to analyze is in application logs. All the EC2 instances currently send logs to Amazon CloudWatch Logs.

A security engineer must set up the log aggregation. The security engineer must collect logs from all the company's AWS accounts into a centralized location to facilitate analysis.

Which solution will meet this requirement?

  • A. Log in to each account four times a day. Filter the required CloudWatch Logs data. Copy and paste the logs into an Amazon S3 bucket that is in the security engineer's account.
  • B. Set up CloudWatch Logs Insights in each account. Use CloudWatch Logs subscriptions to send the CloudWatch Logs Insights query results to the security engineer's account.
  • C. Set up an AWS Config aggregator to collect AWS configuration data from multiple sources. View the aggregator data from the security engineer's account.
  • D. Set up Amazon CloudWatch cross-account log data sharing with subscriptions in each account. Send the logs to an Amazon Kinesis Data Firehose stream in the security engineer's account.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Noexperience
1 year, 9 months ago
Selected Answer: D
Set up Amazon CloudWatch cross-account log data sharing with subscriptions in each account. Send the logs to an Amazon Kinesis Data Firehose stream in the security engineer's account.
upvoted 2 times
...
6_8ftwin
1 year, 11 months ago
Selected Answer: D
https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CrossAccountSubscriptions-Firehose.html
upvoted 3 times
...
cloudesigner
1 year, 12 months ago
D. CloudWatch Cross-Account log data sharing with subscriptions https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CrossAccountSubscriptions.html
upvoted 1 times
...
cloudenthusiast
2 years ago
Selected Answer: D
Option D, setting up Amazon CloudWatch cross-account log data sharing with subscriptions, is the most appropriate solution. This allows the security engineer to configure log data sharing across multiple accounts using CloudWatch subscriptions. The logs can be sent to an Amazon Kinesis Data Firehose stream in the security engineer's account, which acts as the centralized location for log aggregation.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...