A company must retain Amazon CloudWatch Logs data for 90 days and receive an alert in AWS Security Hub when any log group retention policy is noncompliant. Which solution provides the required notifications?
Choose an answer
Tap an option to check your answer.
Correct answer: Use the AWS Config managed rule that evaluates log group retention periods, and ensure that AWS Config is integrated with Security Hub..
Why this is the answer
The correct solution is to use the AWS Config managed rule that evaluates log group retention periods and ensure AWS Config is integrated with Security Hub. AWS Config continuously monitors resource configurations for compliance. There is a specific managed rule, cloudwatch-log-group-retention-period-check, designed to assess if CloudWatch Logs have the specified retention period. When this rule detects non-compliance, and AWS Config is integrated with Security Hub, Security Hub automatically receives findings, triggering the required alerts. Creating a custom action in Security Hub or a Security Hub automation rule cannot directly assess CloudWatch Logs retention periods; these are for responding to findings, not generating them from scratch. A CloudWatch Logs data protection policy focuses on sensitive data detection within logs, not the retention period itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed