A company has multiple AWS accounts that are in an organization in AWS Organizations. The company needs to store AWS account activity and query the data from a central location by using SQL.
Which solution will meet these requirements?
A.
Create an AWS CloudTraii trail in each account. Specify CloudTrail management events for the trail. Configure CloudTrail to send the events to Amazon CloudWatch Logs. Configure CloudWatch cross-account observability. Query the data in CloudWatch Logs Insights.
B.
Use a delegated administrator account to create an AWS CloudTrail Lake data store. Specify CloudTrail management events for the data store. Enable the data store for all accounts in the organization. Query the data in CloudTrail Lake.
C.
Use a delegated administrator account to create an AWS CloudTral trail. Specify CloudTrail management events for the trail. Enable the trail for all accounts in the organization. Keep all other settings as default. Query the CloudTrail data from the CloudTrail event history page.
D.
Use AWS CloudFormation StackSets to deploy AWS CloudTrail Lake data stores in each account. Specify CloudTrail management events for the data stores. Keep all other settings as default, Query the data in CloudTrail Lake.
By leveraging AWS CloudTrail Lake and a delegated administrator account in AWS Organizations, Option B provides a centralized and managed solution for ingesting, storing, and querying AWS account activity using SQL, meeting the company's requirements efficiently.
The other options have drawbacks or do not fully meet the requirements:
Option A: While it uses CloudWatch Logs and CloudWatch Logs Insights, it requires creating and managing CloudTrail trails in each account, which can be more complex and less centralized than using CloudTrail Lake.
Option C: This option suggests using the CloudTrail event history page for querying, which does not provide the SQL querying capabilities required by the company. Additionally, it may not offer the same level of centralization and advanced analytics as CloudTrail Lake.
Option D: While it uses CloudTrail Lake, deploying data stores in each account using CloudFormation StackSets can be more complex and less centralized than using a delegated administrator account to manage the data store for all accounts.
To enable cloudtrail lake, you need to login with admin access to cloudtrail.
https://aws.amazon.com/blogs/mt/announcing-aws-cloudtrail-lake-a-managed-audit-and-security-lake/
B
You can aggregate events within an Organization by enabling it for all accounts in the Organization with AWS CloudTrail Lake.
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
0b43291
1 week, 1 day agoDaniel76
2 months, 1 week agoc22ddd8
4 months, 2 weeks agokupo777
4 months, 4 weeks ago