AWS Certified DevOps Engineer – ProfessionalMonitoring and LoggingHard

A financial services company uses AWS Lambda functions for processing sensitive customer data. Due to strict compliance requirements, all invocations of these Lambda functions must be logged, and the logs must be retained for seven years in an immutable state. The solution must also allow for centralized access and analysis by authorized personnel while minimizing operational overhead.

  1. AConfigure Lambda functions to send logs to CloudWatch Logs, create a subscription filter to stream logs to an S3 bucket, and enable S3 object lock.
  2. BUse CloudWatch Logs with a custom retention policy of seven years and configure IAM policies for centralized access.
  3. CConfigure Lambda functions to send logs to Amazon S3 directly, then enable S3 object lock for immutability and lifecycle policies for retention.
  4. DEnable AWS CloudTrail data events for Lambda, configure CloudTrail to deliver logs to an S3 bucket with S3 object lock, and use Athena for analysis.
Show answer & explanation

Correct answer: D. Enable AWS CloudTrail data events for Lambda, configure CloudTrail to deliver logs to an S3 bucket with S3 object lock, and use Athena for analysis.

AWS CloudTrail data events capture API calls and resource activities, including Lambda function invocations. Delivering these logs to an S3 bucket with S3 Object Lock ensures immutability and long-term retention for compliance. Amazon Athena can then be used for efficient, centralized analysis of these logs without operational overhead.

Why the other options are wrong

  • A. While CloudWatch Logs can stream to S3, this method captures runtime logs (stdout/stderr) from the function, not the invocation event itself as an API call, and involves more components than CloudTrail for this specific requirement.
  • B. CloudWatch Logs has a maximum retention period of 10 years, but it's not designed for immutable archival of API invocation events in the same way CloudTrail + S3 Object Lock is for compliance. It also captures runtime logs, not invocation events as API calls.
  • C. Lambda functions cannot directly send logs to S3. They send logs to CloudWatch Logs by default.

CloudTrail Data Events for Lambda

AWS CloudTrail can record data events for Lambda functions, capturing details of function invocations as API calls, distinct from runtime logs.

  • Captures 'Invoke' API calls for Lambda functions.
  • Logs are delivered to an S3 bucket.
  • Essential for compliance and auditing of function usage.

Memory trick: CloudTrail's 'Data Diary' on S3 is the immutable truth for Lambda calls.

More Monitoring and Logging questions