AWS Certified SysOps Administrator – AssociateSecurity and ComplianceHard

A company is developing a new serverless application using AWS Lambda functions. Due to strict compliance requirements, all logs generated by these Lambda functions must be retained for 7 years and immutable. Which AWS service and configuration should the SysOps administrator use to meet these requirements?

  1. AAmazon CloudWatch Logs with a 7-year retention policy and S3 Object Lock in Compliance mode on the target S3 bucket via a CloudWatch Logs destination.
  2. BAmazon CloudWatch Logs with a 7-year retention policy and S3 Glacier Deep Archive.
  3. CAmazon CloudWatch Logs with a 7-year retention policy and a custom Lambda function to move logs to S3 with S3 Object Lock in Compliance mode.
  4. DAmazon CloudWatch Logs with a 7-year retention policy and a subscription filter to Kinesis Data Firehose, delivering to S3 with S3 Object Lock in Governance mode.
Show answer & explanation

Correct answer: A. Amazon CloudWatch Logs with a 7-year retention policy and S3 Object Lock in Compliance mode on the target S3 bucket via a CloudWatch Logs destination.

CloudWatch Logs can be configured with a 7-year retention policy. To ensure immutability, logs can be exported to an S3 bucket configured with S3 Object Lock in Compliance mode. CloudWatch Logs supports destinations directly to S3, allowing this integration for long-term immutable archival.

Why the other options are wrong

  • B. S3 Glacier Deep Archive provides long-term retention but doesn't inherently provide immutability for logs exported from CloudWatch Logs without additional S3 Object Lock configuration.
  • C. While a custom Lambda could move logs, CloudWatch Logs Destinations is a native, simpler, and more robust way to export logs to S3. S3 Object Lock in Compliance mode is correct for immutability.
  • D. Kinesis Data Firehose is a valid delivery mechanism, but Governance mode for S3 Object Lock isn't as strict as Compliance mode for true immutability, as it allows privileged users to delete objects.

Lambda Log Archiving for Compliance

Archiving AWS Lambda function logs for compliance typically involves long-term retention and immutability, often achieved by integrating CloudWatch Logs with S3 Object Lock.

  • Lambda logs are sent to CloudWatch Logs.
  • CloudWatch Logs supports retention policies.
  • Logs can be exported from CloudWatch Logs to S3.
  • S3 Object Lock in Compliance mode provides immutability.

Memory trick: CloudWatch to S3 Lock, Compliance Mode for Immutability.

More Security and Compliance questions