A company will process sensitive data on Amazon EC2 instances and use Amazon CloudWatch Logs to collect, store, and access log files for developer troubleshooting. A security engineer must prevent developers from viewing sensitive data in the logs, and the control must automatically apply to all new log groups. Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a CloudWatch Logs account-wide data protection policy and specify the appropriate data identifiers. Ensure developers do not have the logs:Unmask IAM permission..
Why this is the answer
The correct solution is to create a CloudWatch Logs account-wide data protection policy and specify the appropriate data identifiers, ensuring developers do not have the logs:Unmask IAM permission. CloudWatch Logs data protection policies automatically detect and mask sensitive data based on specified data identifiers (e.g., PII, PCI) across all new and existing log groups within an account. By denying the logs:Unmask permission, developers cannot view the masked sensitive data, fulfilling the requirement to prevent viewing while allowing access to other log information for troubleshooting. Exporting logs to S3 with Macie (options B and C) is a reactive discovery and remediation step, not a proactive masking solution within CloudWatch Logs itself. It also introduces additional complexity and latency for developers needing to access logs. Creating a data protection policy for each log group (option D) is not scalable or automatic for new log groups, failing the requirement for automatic application to all new log groups.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed