Subscribe all log groups to a Firehose delivery stream in a dedicated account with a Lambda automating new log group subscriptions
A company manages AWS accounts in AWS Organizations. The company needs a solution to send Amazon CloudWatch Logs data to an Amazon S3 bucket in a dedicated AWS account. The solution must support all existing and future CloudWatch Logs log groups. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement explicitly covers all existing and future log groups, so the design must both deliver the data and keep subscriptions current (D). Firehose provides the cross-account delivery to S3, and the EventBridge rule with the Lambda handles the future log groups that no manual subscription could cover (D). Options A and C both rely on AWS Backup, which is a backup service rather than a log delivery mechanism, and B describes a backup plan whose vault is an S3 bucket, which is not how AWS Backup works. The subscription filters are necessarily an account-level construct created by a caller holding the appropriate permissions, which is why the automation calls the API.
CloudWatch Logs data must reach a bucket in a dedicated account for both existing and future log groups. A CloudWatch Logs destination together with an Amazon Kinesis Data Firehose delivery stream in the DevOps account, with the S3 bucket as the delivery destination, carries the subscribed log data. Subscription filters are created for all existing log groups, and because a log group created later would have no subscription, an EventBridge rule on the CreateLogGroup event invokes a Lambda function that calls the CloudWatch Logs PutSubscriptionFilter API to subscribe new groups automatically.
Using Organizations backup policies or an AWS Backup plan to send logs to a bucket (A and B) — AWS Backup is a backup and recovery service for resource recovery points, not a log delivery pipeline, and option B additionally describes specifying an S3 bucket as a backup vault, which is not a valid AWS Backup configuration since vaults are managed storage containers, not application buckets. Omitting any automation for new log groups (C) — the plan assigns existing log groups only, so any log group created later would never be backed up or delivered, which fails the explicit requirement to support future log groups. Relying on manual subscription filters alone (D's first half) — the EventBridge rule and Lambda in option D are exactly what closes the future-log-group gap.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement has two halves: existing log groups must have their data sent to a dedicated account's S3 bucket, and future log groups must be covered as well. A CloudWatch Logs destination plus an Amazon Kinesis Data Firehose delivery stream created in the dedicated account, with the S3 bucket configured as the delivery stream's destination, provides the delivery path and the cross-account write. Subscription filters are then created for all existing log groups in all accounts so their data flows into that stream (D). The future-log-group requirement is what makes the second half necessary: a log group created after the subscriptions are configured would have no subscription and its data would never be delivered. An EventBridge rule matching CreateLogGroup events therefore invokes an AWS Lambda function that calls the CloudWatch Logs PutSubscriptionFilter API operation, which creates the subscription for each new log group automatically and closes the gap (D). D is the correct answer.Why the Other Options Are Wrong
A enables Organizations backup policies to back up all log groups to a dedicated S3 bucket and adds a bucket policy allowing access from all company accounts. AWS Organizations backup policies govern the lifecycle of AWS Backup backup plans and vaults, not the delivery of CloudWatch Logs data to a bucket, so no log data would flow to the bucket through this mechanism. B creates an AWS Backup plan, specifies a dedicated S3 bucket as the backup vault, assigns CloudWatch Logs log group resources to the plan, and creates resource assignments for all accounts. This fails on two counts: AWS Backup vaults are AWS-managed storage containers that hold recovery points rather than application buckets, so an S3 bucket cannot be specified as the vault, and backup plans operate on supported resource types for which recovery points exist, which is not a mechanism for continuously shipping log data. C creates a backup plan with an S3 bucket as the vault and assigns only the existing log groups, adding a Systems Manager Automation runbook and an AWS Config rule with remediation to assign future log groups. Beyond the invalid vault configuration, the Config rule only evaluates on a schedule or configuration change and the runbook is an additional remediation layer, making this both incorrect as a log delivery design and far more operationally complex. D is correct.Community Comment Notes
Community voted D unanimously. hzaki confirmed D twice with concise statements. aws_god noted that option C seemed like the most elegant solution but could not find documentation supporting it, then cited the CloudWatch Logs subscription filter documentation as the basis for choosing D. That distinction between C's appeal and its lack of documented support is the reason D is the answer: the log delivery mechanism with subscription filters is documented, whereas a backup-plan-based approach to log delivery is not. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →