A company needs a centralized solution to analyze log files across an AWS Organizations organization. The solution must aggregate and normalize events from the entire organization, from all AWS Marketplace solutions running in the company’s accounts, and from on-premises systems. Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Designate a delegated Amazon Security Lake administrator account in the organization. Enable and configure Security Lake for the organization, add the required accounts and sources, and use Amazon Athena to query the normalized log data..
Why this is the answer
The correct solution is to use Amazon Security Lake. Security Lake is designed for centralizing security logs across an AWS Organizations organization, including AWS services, AWS Marketplace solutions, and on-premises sources. It automatically normalizes data into the Open Cyber Security Schema Framework (OCSF) format, making it easy to query with Amazon Athena. Incorrect options: Creating a centralized S3 bucket requires manual configuration for normalization and querying across diverse log types, which Security Lake automates. Setting up CloudWatch Logs with subscription filters to OpenSearch Service is a viable solution for some log types but doesn't inherently normalize data from all specified sources (especially AWS Marketplace and on-premises) into a unified schema like Security Lake does. Using an SCP to enforce S3 log delivery still lacks the automatic normalization and comprehensive source integration that Security Lake provides. Querying S3 directly with OpenSearch Service would require significant setup for varied log formats.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed