exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 79 discussion

A company is managing health records on-premises. The company must keep these records indefinitely, disable any modifications to the records once they are stored, and granularly audit access at all levels. The chief technology officer (CTO) is concerned because there are already millions of records not being used by any application, and the current infrastructure is running out of space. The CTO has requested a solutions architect design a solution to move existing data and support future records.
Which services can the solutions architect recommend to meet these requirements?

  • A. Use AWS DataSync to move existing data to AWS. Use Amazon S3 to store existing and new data. Enable Amazon S3 object lock and enable AWS CloudTrail with data events.
  • B. Use AWS Storage Gateway to move existing data to AWS. Use Amazon S3 to store existing and new data. Enable Amazon S3 object lock and enable AWS CloudTrail with management events.
  • C. Use AWS DataSync to move existing data to AWS. Use Amazon S3 to store existing and new data. Enable Amazon S3 object lock and enable AWS CloudTrail with management events.
  • D. Use AWS Storage Gateway to move existing data to AWS. Use Amazon Elastic Block Store (Amazon EBS) to store existing and new data. Enable Amazon S3 object lock and enable Amazon S3 server access logging.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rahul1211
Highly Voted 3 years, 8 months ago
I think it's A. "Use AWS DataSync to migrate existing data to Amazon S3, and then use the File Gateway configuration of AWS Storage Gateway to retain access to the migrated data and for ongoing updates from your on-premises file-based applications." Need a solution to move existing data and support future records -> so, AWS DataSync should be used for migration. Need granular audit access at all levels -> so, Data Events should be used in CloudTrail, Management Events is enabled by default.
upvoted 89 times
KALRAV
3 years, 7 months ago
Purpose of storage gateway is different - https://docs.aws.amazon.com/storagegateway/latest/userguide/WhatIsStorageGateway.html That eliminates storage gateway options B & D Ans: A suits the most
upvoted 4 times
...
AI
3 years, 7 months ago
The answer is A. My logic is as follows. Eliminate storage gateway as the records are of millions and the company wants to store whole data in AWS. Now, D is wrong, EBS and S3 - why? You are left with s3 options. And .. AWS CloudTrail now supports Amazon S3 Data Events. You can now record all API actions on S3 Objects and receive detailed information such as the AWS account of the caller, IAM user role of the caller, time of the API call, IP address of the API, and other details. This is the requirement of the solution. Hence, A is the correct answer.
upvoted 9 times
...
...
djangoUnchained
Highly Voted 3 years, 8 months ago
We need AWS Datasync to move the data, so that leaves A or C. Cloudtrail support s3 data events. My take is A.
upvoted 35 times
djangoUnchained
3 years, 8 months ago
Definitely A, cloudtrail has management events enabled by default: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-concepts.html
upvoted 33 times
...
SangyaB
3 years, 7 months ago
I second you , it should be A. Only CloudTrail with data events can audit S3 objects files level and also DataSync is build to transfer data from On primise to AWS S3.
upvoted 3 times
...
...
ogerber
Most Recent 2 years, 7 months ago
Selected Answer: A
both A and B are ok. the difference we need to conceder is if we want cloud trail to track data or management logs. I vote data. so A.
upvoted 1 times
...
17Master
2 years, 8 months ago
Selected Answer: B
After reviewing both services, I find a small difference and I choose B. Because of the backup from the on-premise installations Here the links: https://aws.amazon.com/es/datasync/ - https://aws.amazon.com/es/storagegateway/
upvoted 1 times
...
jopeg
2 years, 9 months ago
Selected Answer: A
I vote A
upvoted 1 times
...
Arshadul
2 years, 12 months ago
Keys: --> retain health records with auditing access at all levels Expectation: Migrate old data and support future records with granular monitoring Distractors: B/C/D B/D are distractor as they talk about Storage gateway which is useful to simulataneously backup data in aws along with caching the data on prem C is a distractor as it talks about management event with CL which is capturing management operations that are performed on resources in AWS account like bucket creation managing IAM services, etc A is correct as DataSync is the best solution for migrating data from on-prem to aws. S3 is the right solution for storage, CL with data events which monitors object-level API activity (for example, GetObject, DeleteObject, and PutObject API operations) which is needed
upvoted 2 times
...
gargaditya
3 years, 6 months ago
Q: When do I use AWS DataSync and when do I use AWS Storage Gateway? A: Use AWS DataSync to migrate existing data to Amazon S3, and subsequently use the File Gateway configuration of AWS Storage Gateway to retain access to the migrated data and for ongoing updates from your on-premises file-based applications. You can use a combination of DataSync and File Gateway to minimize your on-premises infrastructure while seamlessly connecting on-premises applications to your cloud storage. AWS DataSync enables you to automate and accelerate online data transfers to AWS Storage services. After the initial data transfer phase using AWS DataSync, File Gateway provides your on-premises applications with low latency access to the migrated data. When using DataSync with NFS shares, POSIX metadata from your source on-premises storage is preserved, and permissions from the source storage apply when accessing your files using File Gateway.
upvoted 2 times
gargaditya
3 years, 6 months ago
D does not make sense-talks about EBS ,then talking about S3 EBS does not have lock for compliance. The other main part(keyword) is CloudTrail 'data' vs 'management' events. Management Events: • Operations that are performed on resources in your AWS account • Examples: -Configuring security (IAM AttachRolePolicy) - Configuring rules for routing data (Amazon EC2 CreateSubnet) -Setting up logging (AWS CloudTrail CreateTrail) • By default, trails are configured to log management events. • Can separate Read Events (that don’t modify resources) from Write Events (that may modify resources) ==== Data Events: • By default, data events are not logged (because high volume operations) • Amazon S3 object-level activity (ex: GetObject, DeleteObject, PutObject): can separate Read and Write Events • AWS Lambda function execution activity (the Invoke API)
upvoted 1 times
...
...
ecastilla
3 years, 7 months ago
AWS dataSync is the correct service, so B and D are out. Management events are the type of events that are enabled by default in a trail. So C is out. Answer is A
upvoted 2 times
...
joshuaquek
3 years, 7 months ago
AWS Storage Gateway gives you ACCESS only but is not a service that move the data for you, while AWS DataSync gives you the ABILITY and is a service that helps to move the data for you.
upvoted 3 times
joshuaquek
3 years, 7 months ago
to add on, I am choosing A because of the Cloudtrail Data Events too - "granular audit access". See the video to understand the difference between Cloudtrail management events and data events: https://www.youtube.com/watch?v=qelcK5xRB0Y
upvoted 2 times
...
...
woke
3 years, 7 months ago
A. Use AWS DataSync to move existing data to AWS. Use Amazon S3 to store existing and new data. Enable Amazon S3 object lock and enable AWS CloudTrail with data events.
upvoted 4 times
...
karthisena
3 years, 7 months ago
Explanation: Keyword: Move existing data and support future records + Granular audit access at all levels Use AWS DataSync to migrate existing data to Amazon S3, and then use the File Gateway configuration of AWS Storage Gateway to retain access to the migrated data and for ongoing updates from your on- premises file-based applications. Need a solution to move existing data and support future records = AWS DataSync should be used for migration. Need granular audit access at all levels = Data Events should be used in CloudTrail, Management Events is enabled by default.
upvoted 2 times
...
JWGrace
3 years, 7 months ago
Should be C, right? AWS CloudTrail with management events instead of data events.
upvoted 1 times
lehoang15tuoi
3 years, 7 months ago
When someone accesses something, its a S3 GetObject request. It’s a data event. So if you want to audit accesses, you need logs for data events
upvoted 1 times
...
...
DMR
3 years, 7 months ago
Ans = A CloudTrail data events CloudTrail data events are disabled by default. You can enable logging at an additional cost. Data events are also known as data plane operations and are often high-volume activities. Data events aren't viewable in CloudTrail event history and are charged for all copies at a reduced rate compared to management events. For instructions to log data events to an Amazon Simple Storage Service (Amazon S3) bucket, see Logging Data Events with the AWS Management Console.
upvoted 3 times
...
Pavan111
3 years, 7 months ago
Key takeaways: 1. Store data infinitely ( S3 ) 2. Auditing ( CloudTrail ) 3. Prevent modifying data once uploaded ( Object lock )
upvoted 2 times
...
syu31svc
3 years, 7 months ago
Correct answer is A as AWS Data Sync can be used to move the data from on-premises to AWS S3. Data can be stored in S3 with object lock to prevent any modifications. CloudTrail S3 Data events can be enabled to granular audit access at all levels.
upvoted 1 times
...
KK_uniq
3 years, 7 months ago
MOve data from onprem Datasync for sure
upvoted 1 times
...
dmscountera
3 years, 7 months ago
data events are not enabled by default - A
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...