Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam DOP-C02 Topic 5 Question 41 Discussion

Actual exam question for Amazon's DOP-C02 exam
Question #: 41
Topic #: 5
[All DOP-C02 Questions]

A company uses AWS WAF to protect its cloud infrastructure. A DevOps engineer needs to give an operations team the ability to analyze log messages from AWS WAR. The operations team needs to be able to create alarms for specific patterns in the log output.

Which solution will meet these requirements with the LEAST operational overhead?

Show Suggested Answer Hide Answer
Suggested Answer: A

Step 2: Creating CloudWatch Metric Filters CloudWatch metric filters can be used to search for specific patterns in log data. The operations team can create filters for certain log patterns and set up alarms based on these filters.

Action: Instruct the operations team to create CloudWatch metric filters to detect patterns in the WAF log output.

Why: Metric filters allow the team to trigger alarms based on specific patterns without needing to manually search through logs.

This corresponds to Option A: Create an Amazon CloudWatch Logs log group. Configure the appropriate AWS WAF web ACL to send log messages to the log group. Instruct the operations team to create CloudWatch metric filters.

Contribute your Thoughts:

Irving
9 days ago
Option A all the way! It's the most cost-effective and easy to implement. No need to spin up a whole OpenSearch cluster or deal with the hassle of Athena.
upvoted 0 times
...
Joanne
10 days ago
True, but sending logs directly to CloudWatch Logs in option A seems simpler.
upvoted 0 times
...
Lacresha
12 days ago
Haha, I bet the operations team is thrilled to write SQL queries and set up Athena just to analyze some WAF logs. Why make things more complicated than they need to be?
upvoted 0 times
...
Lanie
13 days ago
The CloudWatch Logs option seems the most efficient and reliable. I like how it allows the operations team to create custom alarms and alerts without additional overhead.
upvoted 0 times
Lashawn
7 days ago
A: Option A seems like the best choice. It allows the operations team to easily create alarms for specific log patterns.
upvoted 0 times
...
...
Luann
21 days ago
But option D also uses CloudWatch for analysis, it could be a good alternative.
upvoted 0 times
...
Cassie
23 days ago
This is the easiest and most straightforward solution. No need to set up additional services like OpenSearch or Athena. Just send the logs to CloudWatch and use the built-in metric filters.
upvoted 0 times
Christene
4 days ago
B: I agree, setting up CloudWatch Logs with AWS WAF is the least complicated solution.
upvoted 0 times
...
Billye
11 days ago
A: Option A is definitely the way to go. It's simple and efficient.
upvoted 0 times
...
...
Shelton
29 days ago
I agree with Joanne, sending logs to CloudWatch Logs seems efficient.
upvoted 0 times
...
Joanne
1 months ago
I think option A is the best choice.
upvoted 0 times
...

Save Cancel