Send Network Firewall flow logs to a Kinesis Data Firehose delivery stream with a Lambda transformer

Answer Correct answer: D — use a Kinesis Data Firehose delivery stream with a Lambda transformer targeting the existing S3 bucket.

A company sends its AWS Network Firewall flow logs to an Amazon S3 bucket. The company then analyzes the flow logs by using Amazon Athena. The company needs to transform the flow logs and add additional data before the flow logs are delivered to the existing S3 bucket. Which solution will meet these requirements?

  1. Create an AWS Lambda function to transform the data and to write a new object to the existing S3 bucket. Configure the Lambda function with an S3 trigger for the existing S3 bucket. Specify all object create events for the event type. Acknowledge the recursive invocation.
  2. Enable Amazon EventBridge notifications on the existing S3 bucket. Create a custom EventBridge event bus. Create an EventBridge rule that is associated with the custom event bus. Configure the rule to react to all object create events for the existing S3 bucket and to invoke an AWS Step Functions workflow. Configure a Step Functions task to transform the data and to write the data into a new S3 bucket.
  3. Create an Amazon EventBridge rule that is associated with the default EventBridge event bus. Configure the rule to react to all object create events for the existing S3 bucket. Define a new S3 bucket as the target for the rule. Create an EventBridge input transformation to customize the event before passing the event to the rule target.
  4. Create an Amazon Kinesis Data Firehose delivery stream that is configured with an AWS Lambda transformer. Specify the existing S3 bucket as the destination. Change the Network Firewall logging destination from Amazon S3 to Kinesis Data Firehose. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Firehose supports a Lambda transformation as a native configuration on the delivery stream, with the S3 bucket specified directly as the delivery destination, so the transform-then-deliver-to-the-existing-bucket sequence is expressed declaratively (D). That is what makes it operationally efficient. Option A's Lambda writing back into the bucket it is triggered by is inherently recursive: every object it creates triggers itself again, which is why it has to acknowledge the recursive invocation, and it adds an unbounded trigger loop. Options B and C route through EventBridge and either write to a different bucket or only reshape the event payload rather than the log contents.

The flow logs must be transformed and augmented before being delivered to the existing S3 bucket. Amazon Kinesis Data Firehose is designed for exactly this: a delivery stream configured with a Lambda transformation function ingests the records, invokes the Lambda to transform and enrich them, and delivers the transformed output to the specified S3 bucket as its destination. Changing the Network Firewall logging destination from S3 to Firehose therefore inserts the transformation step in the delivery path without any custom polling or recursive invocation logic.

Creating a Lambda triggered by object-create events on the existing bucket and writing the transformed object back to that same bucket (A) — this is recursive by construction, since each object the function writes produces another create event that invokes it again, which is why the option has to acknowledge recursive invocation; it also replaces the streaming delivery path with a polling-and-rewriting loop. Invoking a Step Functions workflow and writing to a new S3 bucket (B) — the requirement is to deliver to the existing bucket, and this option adds EventBridge, a custom event bus, a rule, and a workflow where Firehose provides the transformation natively. Using EventBridge input transformation with a new bucket as target (C) — EventBridge input transformations reshape the event payload sent to the target, not the contents of the log objects, and the option writes to a different bucket rather than the existing one.

Community Discussion (4 comments)

jamesf 👍 4 Selected: D
Amazon Kinesis Data Firehose: Kinesis Data Firehose is designed for real-time streaming data delivery and transformation. It can ingest data, process it with a Lambda function, and deliver the transformed data to destinations like Amazon S3, Redshift, or Elasticsearch. https://aws.amazon.com/firehose/faqs/ AWS Lambda Transformer: By configuring a Lambda function as a transformer within Kinesis Data Firehose, you can implement custom logic to transform the flow logs and add any additional data required before the logs are written to the existing S3 bucket.
d9iceguy 👍 3 Selected: D
D for me
trungtd 👍 4 Selected: D
D for me
getadroit 👍 3
Dhttps://aws.amazon.com/firehose/faqs/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is to transform the Network Firewall flow logs and add data to them before they are delivered to the existing S3 bucket. Amazon Kinesis Data Firehose is built for managed streaming delivery with transformation: a delivery stream can be configured with an AWS Lambda transformation function, which Firehose invokes on each batch so the records can be modified and enriched, and the stream's destination is set to the existing S3 bucket. Redirecting the Network Firewall logging destination from Amazon S3 to the Firehose delivery stream therefore places the transformation inline in the delivery path and keeps the output landing in the same bucket the company already consumes, all without custom polling code or trigger loops (D). D is the correct answer.

Why the Other Options Are Wrong

A creates a Lambda function triggered by object-create events on the existing S3 bucket that transforms the data and writes a new object back to that same bucket, with recursive invocation acknowledged. This design is recursive by construction: every object the function writes produces another create event, which invokes the function again, so the bucket is continuously rewritten and the trigger must special-case its own writes. It also replaces the streaming delivery path with a self-triggering loop, which is fragile and operationally costly. B enables EventBridge notifications on the bucket, creates a custom event bus and a rule reacting to object-create events, invokes a Step Functions workflow, and writes the transformed data into a new S3 bucket. This adds EventBridge, a separate event bus, a rule, and a workflow to perform a transformation Firehose performs natively, and it writes to a new bucket rather than the existing one the requirement names. C creates an EventBridge rule on the default event bus reacting to object-create events with a new S3 bucket as the target and uses an EventBridge input transformation. EventBridge input transformations customize the event payload delivered to the target, not the contents of the log objects, so they cannot transform the flow log records themselves, and this option also targets a different bucket. D is correct.

Community Comment Notes

Community voted D unanimously. jamesf explained that Kinesis Data Firehose is designed for real-time streaming data delivery and transformation, and that it can ingest data, process it with a Lambda function, and deliver the transformed data, which is precisely the required sequence. d9iceguy, trungtd, and getadroit confirmed D, with getadroit citing the Firehose documentation. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide