The company has had issues related to specific Host headers and hostnames. As a first step, the company configured AWS WAF web ACLs. The security engineer must build a centralized log analytics solution for AWS WAF logs and be able to filter requests by host with the highest operational efficiency. Access logging for the web ACLs is being enabled. What should the engineer do next?
Choose an answer
Tap an option to check your answer.
Correct answer: Set Amazon CloudWatch as the access log destination. Use Amazon CloudWatch Logs Insights to build queries that filter by host..
Why this is the answer
The most operationally efficient solution is to set Amazon CloudWatch as the access log destination and use CloudWatch Logs Insights. CloudWatch Logs Insights is specifically designed for interactive analysis of log data, offering powerful query capabilities to filter by host directly within CloudWatch, eliminating the need for additional services or data transfers. This provides the highest operational efficiency for real-time analysis. Setting Amazon Redshift as the access log destination is less efficient because Redshift is a data warehouse optimized for complex analytical queries on large datasets, not real-time log analysis. Using the Athena Redshift connector adds complexity. Exporting logs to S3 and then using Athena (option C) is a viable option for long-term storage and analysis but introduces an additional step and latency compared to direct CloudWatch Logs Insights. Using Redshift Spectrum (option D) also adds complexity and is generally used for querying data directly in S3, not directly from CloudWatch Logs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed