Soru

Zorluk: KolayVPC Flow Logs and Network Monitoring

A SysOps Administrator is configuring a new VPC Flow Log to send traffic data to an Amazon CloudWatch Logs group. To manage costs, the administrator wants to ensure that the flow logs are retained for exactly 90 days.

Which action must the administrator take to configure this retention period?

  1. Configure the retention setting directly on the target CloudWatch Logs group to 90 days.Cevap
  2. B
    Define a 90-day retention period in the properties of the VPC Flow Log configuration during its creation.
  3. C
    Create an Amazon EventBridge rule that triggers an AWS Lambda function to delete logs older than 90 days from the log group.
  4. D
    Configure the IAM role used by the VPC Flow Log with an inline policy containing an iam:PassRole statement that expires after 90 days.

Cevap

Configure the retention setting directly on the target CloudWatch Logs group to 90 days.
The correct answer is to configure the retention setting directly on the target CloudWatch Logs group. VPC Flow Logs do not store data or maintain retention settings on their own resource. They deliver logs to CloudWatch Logs or Amazon S3, and the retention or lifecycle rules must be configured on those destination resources.

Adım Adım Çözüm

1
Identify where VPC Flow Logs store data.
VPC Flow Logs are sent to a destination, in this case, an Amazon CloudWatch Logs group.
VPC Flow Logs do not store data directly; they deliver log events to the designated log group.
2
Determine how log retention is managed in CloudWatch.
Retention settings are configured at the Log Group level in CloudWatch Logs.
CloudWatch Logs groups allow you to define a retention period (e.g., 90 days) to automatically delete older log events.
3
Select the option that configures retention at the destination.
Changing the target CloudWatch Logs group's retention period to 90 days.
This is the native, cost-efficient, and direct way to manage the storage duration of flow logs.

Anahtar Kavram

VPC Flow Logs deliver traffic logs to Amazon CloudWatch Logs or Amazon S3. The retention period and lifecycle of the logs must be configured directly on the target destination (e.g., CloudWatch Log Group retention settings or S3 Lifecycle policies), as the VPC Flow Logs resource itself does not support retention configuration.
Bu soruyu puanla