An operations team needs to read AWS WAF logs and create alarms for patterns in those logs. The solution should require the least operational effort. What is the simplest way to provide log access and allow alarms to be created?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a CloudWatch Logs log group, configure the WAF web ACL to send logs there, and let the operations team create CloudWatch metric filters and alarms..
Why this is the answer
The simplest solution with the least operational effort is to send WAF logs directly to CloudWatch Logs. AWS WAF has native integration with CloudWatch Logs, allowing you to configure a web ACL to send logs to a specified log group. Once logs are in CloudWatch Logs, the operations team can easily create CloudWatch metric filters to identify specific patterns and then set up CloudWatch alarms based on these metrics. This approach leverages existing AWS services without requiring additional infrastructure setup or complex data processing pipelines. Provisioning an OpenSearch cluster, using Lambda functions, or setting up Athena all involve more complex architectures, additional service management, and higher operational overhead compared to the direct CloudWatch Logs integration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed