Send Network Firewall flow logs to a Kinesis Data Firehose delivery stream with a Lambda transformer
A company sends its AWS Network Firewall flow logs to an Amazon S3 bucket. The company then analyzes the flow logs by using Amazon Athena. The company needs to transform the flow logs and add additional data before the flow logs are delivered to the existing S3 bucket. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Firehose supports a Lambda transformation as a native configuration on the delivery stream, with the S3 bucket specified directly as the delivery destination, so the transform-then-deliver-to-the-existing-bucket sequence is expressed declaratively (D). That is what makes it operationally efficient. Option A's Lambda writing back into the bucket it is triggered by is inherently recursive: every object it creates triggers itself again, which is why it has to acknowledge the recursive invocation, and it adds an unbounded trigger loop. Options B and C route through EventBridge and either write to a different bucket or only reshape the event payload rather than the log contents.
The flow logs must be transformed and augmented before being delivered to the existing S3 bucket. Amazon Kinesis Data Firehose is designed for exactly this: a delivery stream configured with a Lambda transformation function ingests the records, invokes the Lambda to transform and enrich them, and delivers the transformed output to the specified S3 bucket as its destination. Changing the Network Firewall logging destination from S3 to Firehose therefore inserts the transformation step in the delivery path without any custom polling or recursive invocation logic.
Creating a Lambda triggered by object-create events on the existing bucket and writing the transformed object back to that same bucket (A) — this is recursive by construction, since each object the function writes produces another create event that invokes it again, which is why the option has to acknowledge recursive invocation; it also replaces the streaming delivery path with a polling-and-rewriting loop. Invoking a Step Functions workflow and writing to a new S3 bucket (B) — the requirement is to deliver to the existing bucket, and this option adds EventBridge, a custom event bus, a rule, and a workflow where Firehose provides the transformation natively. Using EventBridge input transformation with a new bucket as target (C) — EventBridge input transformations reshape the event payload sent to the target, not the contents of the log objects, and the option writes to a different bucket rather than the existing one.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to transform the Network Firewall flow logs and add data to them before they are delivered to the existing S3 bucket. Amazon Kinesis Data Firehose is built for managed streaming delivery with transformation: a delivery stream can be configured with an AWS Lambda transformation function, which Firehose invokes on each batch so the records can be modified and enriched, and the stream's destination is set to the existing S3 bucket. Redirecting the Network Firewall logging destination from Amazon S3 to the Firehose delivery stream therefore places the transformation inline in the delivery path and keeps the output landing in the same bucket the company already consumes, all without custom polling code or trigger loops (D). D is the correct answer.Why the Other Options Are Wrong
A creates a Lambda function triggered by object-create events on the existing S3 bucket that transforms the data and writes a new object back to that same bucket, with recursive invocation acknowledged. This design is recursive by construction: every object the function writes produces another create event, which invokes the function again, so the bucket is continuously rewritten and the trigger must special-case its own writes. It also replaces the streaming delivery path with a self-triggering loop, which is fragile and operationally costly. B enables EventBridge notifications on the bucket, creates a custom event bus and a rule reacting to object-create events, invokes a Step Functions workflow, and writes the transformed data into a new S3 bucket. This adds EventBridge, a separate event bus, a rule, and a workflow to perform a transformation Firehose performs natively, and it writes to a new bucket rather than the existing one the requirement names. C creates an EventBridge rule on the default event bus reacting to object-create events with a new S3 bucket as the target and uses an EventBridge input transformation. EventBridge input transformations customize the event payload delivered to the target, not the contents of the log objects, so they cannot transform the flow log records themselves, and this option also targets a different bucket. D is correct.Community Comment Notes
Community voted D unanimously. jamesf explained that Kinesis Data Firehose is designed for real-time streaming data delivery and transformation, and that it can ingest data, process it with a Lambda function, and deliver the transformed data, which is precisely the required sequence. d9iceguy, trungtd, and getadroit confirmed D, with getadroit citing the Firehose documentation. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →