Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 524 discussion

A company wants to analyze and troubleshoot Access Denied errors and Unauthorized errors that are related to IAM permissions. The company has AWS CloudTrail turned on.

Which solution will meet these requirements with the LEAST effort?

  • A. Use AWS Glue and write custom scripts to query CloudTrail logs for the errors.
  • B. Use AWS Batch and write custom scripts to query CloudTrail logs for the errors.
  • C. Search CloudTrail logs with Amazon Athena queries to identify the errors.
  • D. Search CloudTrail logs with Amazon QuickSight. Create a dashboard to identify the errors.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
awsgeek75
5 months, 2 weeks ago
Selected Answer: C
https://docs.aws.amazon.com/athena/latest/ug/cloudtrail-logs.html When troubleshooting you will want to query specific things in the log and Athena provides query language for that. Quick Sight is data analytics and visualisation tool. You can use it to aggregate data and maybe make a dashboard for number of errors by type etc but that doesn't help you troubleshoot anything. C is correct
upvoted 2 times
...
pentium75
6 months ago
Selected Answer: C
"Search CloudTrail logs with Amazon QuickSight", that doesn't work. QuickSight can visualize Athena query results, so "search CloudTrail logs with Amazon Athena, then create a dashboard with Amazon QuickSight" would make sense. But QuickSight without Athena won't work.
upvoted 3 times
...
Wuhao
6 months, 4 weeks ago
Selected Answer: C
Athena is for searching
upvoted 2 times
...
bogobob
7 months, 3 weeks ago
Selected Answer: D
The question asks specifically to "analyze and troubleshoot". While Athena is easy to get the data, you then just have a list of logs. Not very useful to troubleshoot...
upvoted 1 times
awsgeek75
5 months, 2 weeks ago
How will pretty pictures in QuickSight help with troubleshooting?
upvoted 1 times
...
pentium75
6 months ago
But without Athena, there is nothing you can visualize in QuickSight.
upvoted 1 times
...
...
NickGordon
7 months, 4 weeks ago
Selected Answer: D
Quick Sight is an analytics tool. Sounds like a LEAST effort option
upvoted 2 times
...
Guru4Cloud
10 months, 2 weeks ago
Selected Answer: C
Athena allows you to run SQL queries on data in Amazon S3, including CloudTrail logs. It is the easiest way to query the logs and identify specific errors without needing to write any custom code or scripts. With Athena, you can write simple SQL queries to filter the CloudTrail logs for the "AccessDenied" and "UnauthorizedOperation" error codes. This will return the relevant log entries that you can then analyze.
upvoted 3 times
...
TariqKipkemei
11 months, 3 weeks ago
Selected Answer: C
C for me. Using Athena with CloudTrail logs is a powerful way to enhance your analysis of AWS service activity. For example, you can use queries to identify trends and further isolate activity by attributes, such as source IP address or user. https://docs.aws.amazon.com/athena/latest/ug/cloudtrail-logs.html#:~:text=CloudTrail%20Lake%20documentation.-,Using%20Athena,-with%20CloudTrail%20logs
upvoted 1 times
...
james2033
11 months, 3 weeks ago
Selected Answer: C
IAM and CloudTrail https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html#stscloudtrailexample-assumerole . Query CloudTrail logs by Athena https://docs.aws.amazon.com/athena/latest/ug/cloudtrail-logs.html#tips-for-querying-cloudtrail-logs#tips-for-querying-cloudtrail-logs
upvoted 1 times
james2033
11 months, 3 weeks ago
Choose C, not D, because need “analyze and troubleshoot”, not just see on dashboard (in D).
upvoted 1 times
...
...
Selected Answer: C
Amazon Athena is an interactive query service provided by AWS that enables you to analyze data , is a little bit more suitable integrated with cloud trail that permit to verify WHO accessed the service.
upvoted 1 times
...
manuh
1 year ago
Selected Answer: C
Dashboard isnt requires. Also refer to this https://repost.aws/knowledge-center/troubleshoot-iam-permission-errors
upvoted 1 times
...
haoAWS
1 year ago
Selected Answer: D
I am struggling for the C and D for a long time, and ask the chatGPT. The chatGPT says D is better, since Athena requires more expertise on SQL.
upvoted 1 times
...
antropaws
1 year ago
Selected Answer: D
Both C and D are feasible. I vote for D: Amazon QuickSight supports logging the following actions as events in CloudTrail log files: - Whether the request was made with root or AWS Identity and Access Management user credentials - Whether the request was made with temporary security credentials for an IAM role or federated user - Whether the request was made by another AWS service https://docs.aws.amazon.com/quicksight/latest/user/logging-using-cloudtrail.html
upvoted 1 times
...
PCWu
1 year ago
Selected Answer: C
The Answer will be C: Need to use Athena to query keywords and sort out the error logs. D: No need to use Amazon QuickSight to create the dashboard.
upvoted 1 times
...
Axeashes
1 year ago
Selected Answer: C
"Using Athena with CloudTrail logs is a powerful way to enhance your analysis of AWS service activity." https://docs.aws.amazon.com/athena/latest/ug/cloudtrail-logs.html
upvoted 1 times
...
oras2023
1 year ago
Selected Answer: C
Analyse and TROUBLESHOOT, look like Athena
upvoted 1 times
oras2023
1 year ago
https://docs.aws.amazon.com/athena/latest/ug/cloudtrail-logs.html
upvoted 1 times
...
...
Selected Answer: D
It specifies analyze, not query logs. Which is why option D is the best one as it provides dashboards to analyze the logs.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in