AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesMedium

A security auditor needs to centrally collect and analyze logs from various AWS services, including VPC Flow Logs, CloudTrail logs, and application logs from EC2 instances. They require a highly scalable and durable service that can store these logs for long periods and allow for real-time monitoring and searching. Which AWS service is BEST suited for this task?

  1. AAmazon CloudWatch Logs
  2. BAmazon Kinesis Data Firehose
  3. CAWS Config
  4. DAmazon S3
Show answer & explanation

Correct answer: A. Amazon CloudWatch Logs

Amazon CloudWatch Logs is a service that enables you to centralize logs from all of your systems, applications, and AWS services. It provides capabilities for real-time monitoring, long-term retention, and searching of log data, making it ideal for security auditing and compliance requirements across various AWS services.

Why the other options are wrong

  • B. Amazon Kinesis Data Firehose is a service for delivering real-time streaming data to destinations like S3, Redshift, or Splunk, but CloudWatch Logs is specifically designed for log management, monitoring, and searching.
  • C. AWS Config assesses, audits, and evaluates the configurations of your AWS resources but does not collect or analyze log data.
  • D. Amazon S3 is a durable object storage service, suitable for archiving logs but does not natively provide real-time monitoring, searching, or analysis capabilities of log data.

Amazon CloudWatch Logs

A service that enables you to centralize logs from all of your systems, applications, and AWS services for monitoring, storing, and accessing your log files.

  • Collects logs from EC2, Lambda, CloudTrail, VPC Flow Logs, etc.
  • Allows real-time monitoring and custom alarms.
  • Provides powerful search and filter capabilities for log data.

Memory trick: CloudWatch Logs: Watch your logs, find your answers.

More Cloud Technology and Services questions