Question 1 · choose 2
A compliance review of an application's Amazon CloudWatch Logs log groups finds two gaps. The log data must be encrypted with a customer managed KMS key that the security team controls and can disable, and log events older than 400 days must be deleted automatically. Today the log groups use the default encryption and never expire. Which actions should the DevOps engineer take? (Choose TWO.)
- AAssociate the customer managed KMS key with each log group, after allowing the CloudWatch Logs service principal to use the key in its key policy
- BSet the retention of each log group to 400 days
- CExport the log groups to an S3 bucket every day and turn on SSE-KMS with the customer managed key for the bucket
- DAttach a data protection policy to each log group so that log events are protected with the security team's KMS key
- EMove the log groups to the Infrequent Access log class so that old log events expire after 400 days
Show the answer and why
AAssociate the customer managed KMS key with each log group, after allowing the CloudWatch Logs service principal to use the key in its key policy
Correct
Encryption with AWS KMS is turned on per log group by associating a KMS key, and the key policy must give the CloudWatch Logs service principal permission to use the key.
BSet the retention of each log group to 400 days
Correct
400 days is one of the allowed retention values, and data older than the retention setting is deleted automatically.
CExport the log groups to an S3 bucket every day and turn on SSE-KMS with the customer managed key for the bucket
Incorrect
This encrypts the exported copies in S3, not the log data stored in CloudWatch Logs, and the log groups still never expire.
DAttach a data protection policy to each log group so that log events are protected with the security team's KMS key
Incorrect
A data protection policy does not change the KMS key that encrypts the log group's data.
EMove the log groups to the Infrequent Access log class so that old log events expire after 400 days
Incorrect
The log class does not decide when log events expire. Expiry is set by the retention setting.
CloudWatch Logs always encrypts data at rest; associating a customer managed KMS key with a log group puts the encryption under the key owner's control. Retention is a separate per-log-group setting with fixed allowed values.
AWS documentation