AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A company is developing a new serverless application using AWS Lambda functions. The application processes highly sensitive customer data, and the security team requires that all Lambda function invocations and their outcomes are logged and audited for compliance purposes. The logs must be retained for at least 7 years. Which AWS service combination should the SysOps administrator implement to meet these requirements efficiently?

  1. AConfigure Lambda to send logs to AWS CloudTrail and enable CloudTrail's S3 integration for long-term storage.
  2. BConfigure Lambda to send logs to Amazon CloudWatch Logs, then use a CloudWatch Logs subscription filter to send them to Amazon Kinesis and then to S3 with Object Lock.
  3. CConfigure Lambda to send logs to Amazon CloudWatch Logs, then export the logs to an S3 bucket with Object Lock and configure a lifecycle policy.
  4. DConfigure Lambda to send logs to Amazon S3 directly and enable S3 Object Lock.
Show answer & explanation

Correct answer: C. Configure Lambda to send logs to Amazon CloudWatch Logs, then export the logs to an S3 bucket with Object Lock and configure a lifecycle policy.

AWS Lambda automatically integrates with Amazon CloudWatch Logs for logging function invocations and stdout/stderr. To meet the 7-year retention requirement, logs from CloudWatch Logs can be exported to an S3 bucket. S3 Object Lock provides WORM (Write Once, Read Many) protection for compliance, and S3 lifecycle policies can manage the retention period efficiently, moving data to cheaper storage classes over time.

Why the other options are wrong

  • A. CloudTrail logs API activity, not the detailed application logs (stdout/stderr) from Lambda function invocations. While CloudTrail is important for auditing, it doesn't capture the operational logs from the Lambda function itself as required.
  • B. While technically possible, sending logs through Kinesis from CloudWatch Logs for long-term S3 storage is overly complex and unnecessary for this specific requirement; direct export is more efficient.
  • D. Lambda does not directly send logs to S3; it sends them to CloudWatch Logs.

Lambda Log Archiving for Compliance

To meet long-term compliance retention for AWS Lambda application logs, send logs to CloudWatch Logs, then export to S3 with Object Lock and lifecycle policies.

  • Lambda logs to CloudWatch Logs automatically.
  • CloudWatch Logs can export to S3.
  • S3 Object Lock provides WORM compliance.
  • S3 lifecycle policies manage retention and cost.

Memory trick: CloudWatch catches, S3 secures, Object Lock locks it down.

More Security and Compliance questions