ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 357 - SAA-C03 discussion

Report
Export

A company’s security team requests that network traffic be captured in VPC Flow Logs. The logs will be frequently accessed for 90 days and then accessed intermittently. What should a solutions architect do to meet these requirements when configuring the logs?

A.
Use Amazon CloudWatch as the target. Set the CloudWatch log group with an expiration of 90 days
Answers
A.
Use Amazon CloudWatch as the target. Set the CloudWatch log group with an expiration of 90 days
B.
Use Amazon Kinesis as the target. Configure the Kinesis stream to always retain the logs for 90 days.
Answers
B.
Use Amazon Kinesis as the target. Configure the Kinesis stream to always retain the logs for 90 days.
C.
Use AWS CloudTrail as the target. Configure CloudTrail to save to an Amazon S3 bucket, and enable S3 Intelligent-Tiering.
Answers
C.
Use AWS CloudTrail as the target. Configure CloudTrail to save to an Amazon S3 bucket, and enable S3 Intelligent-Tiering.
D.
Use Amazon S3 as the target. Enable an S3 Lifecycle policy to transition the logs to S3 Standard- Infrequent Access (S3 Standard-IA) after 90 days.
Answers
D.
Use Amazon S3 as the target. Enable an S3 Lifecycle policy to transition the logs to S3 Standard- Infrequent Access (S3 Standard-IA) after 90 days.
Suggested answer: D

Explanation:

There's a table here that specifies that VPC Flow logs can go directly to S3. Does not need to go via CloudTrail and then to S3. Nor via CW. https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AWS-logs-and-resourcepolicy.html#AWS-logs-infrastructure-S3

asked 16/09/2024
Joseph Lewis
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first