Send Redshift user activity audit logs to CloudWatch and display them with a CloudWatch Logs dashboard widget

Answer Correct answer: C, D — send Redshift user activity audit logs to CloudWatch and display them with a CloudWatch dashboard log widget.

A company uses Amazon Redshift as its data warehouse solution. The company wants to create a dashboard to view changes to the Redshift users and the queries the users perform. Which combination of steps will meet this requirement? (Choose two.)

  1. Create an Amazon CloudWatch log group. Create an AWS CloudTrail trail that writes to the CloudWatch log group.
  2. Create a new Amazon S3 bucket. Configure default audit logging on the Redshift cluster. Configure the S3 bucket as the target.
  3. Configure the Redshift cluster database audit logging to include user activity logs. Configure Amazon CloudWatch as the target. Correct Answer
  4. Create an Amazon CloudWatch dashboard that has a log widget. Configure the widget to display user details from the Redshift logs. Correct Answer
  5. Create an AWS Lambda function that uses Amazon Athena to query the Redshift logs. Create an Amazon CloudWatch dashboard that has a custom widget type that uses the Lambda function.

Community Votes

CD
84%
BE
16%

84% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The requirement is a dashboard showing user changes and queries, and the shortest path is CloudWatch end to end: Redshift audit logging with user activity logs enabled delivers to CloudWatch, and a CloudWatch dashboard log widget renders it (C and D). Option A sends CloudTrail to CloudWatch, but CloudTrail records Redshift API calls such as cluster modifications, not the SQL statements users execute inside the cluster, so it cannot show their queries. Option B's default audit logging captures connection and query information but only to S3, and option E requires a Lambda plus a custom widget type to surface data that CloudWatch can already display natively.

Redshift database audit logging can include user activity logging, which records connections, disconnections, and the SQL statements users run. Configuring the cluster's database audit logging to include user activity logs and targeting Amazon CloudWatch as the destination puts that data where it can be charted directly, and a CloudWatch dashboard with a log widget configured to show user details from the Redshift logs presents both the user changes and their queries.

Creating a CloudTrail trail writing to a CloudWatch log group (A) — CloudTrail records the management API activity against the Redshift cluster, not the SQL statements users run inside the database, so the dashboard would not show user queries. Using S3 as the audit log destination (B) — Srikantha and tdlAws both noted default audit logging does capture users and queries and writes them to S3, but the requirement is a CloudWatch dashboard, and S3 data would need Athena plus a custom Lambda to visualize, which is what option E proposes. Using a Lambda and a custom dashboard widget type (E) — unnecessary, because audit logs delivered to CloudWatch can be rendered by a standard log widget.

Community Discussion (7 comments)

Srikantha 👍 1 Selected: BE
To track Redshift user activity and query execution, you need to enable Redshift audit logging. This allows you to analyze: User connections and disconnections SQL queries run Changes to database users and privileges B. Enable Redshift Audit Logging to S3 Redshift supports audit logging which includes user activity, connection logs, and user changes. Logs are delivered to an Amazon S3 bucket, which you can then query using tools like Athena. This is the most efficient and supported way to persist and analyze historical Redshift activity. E. Query logs via Athena + Display on CloudWatch Dashboard Once Redshift logs are in S3, you can set up an Athena table to query them. You can use an AWS Lambda function to run these queries. A custom widget in an Amazon CloudWatch Dashboard can call the Lambda and display the results, such as recent user actions or frequent queries. This enables a near-real-time, visual dashboard with low operational overhead.
tdlAws 👍 1 Selected: BE
Setting up the default audit log on your Redshift cluster will allow you to record database activity, including user changes and queries performed. Specifying an Amazon S3 bucket as the destination will store the logs for later analysis. Using Amazon Athena to query the logs stored in S3 allows you to create custom queries and extract the relevant data. The Amazon CloudWatch dashboard with a custom AWS Lambda-based widget can display the information directly on the dashboard.
pma17 👍 4 Selected: CD
To log users queries you need to include user activity logs which require additional setup on the Redshift cluster. So C, because it is not mentioned on B. Then to display this logs the only option is D, because E requires the logs to be on S3.
Impromptu 👍 3 Selected: CD
audit logging can be sent to cloudwatch logs. So easier to just have them in cloudwatch and make a dashboard
siheom 👍 1 Selected: BC
vote BC
uncledana 👍 1
B. Create a new Amazon S3 bucket. Configure default audit logging on the Redshift cluster. Configure the S3 bucket as the target. E. Create an AWS Lambda function that uses Amazon Athena to query the Redshift logs. Create an Amazon CloudWatch dashboard that has a custom widget type that uses the Lambda function. Explanation: To create a dashboard for viewing changes to Amazon Redshift users and the queries they perform, you need to capture the necessary audit logs and process them into a dashboard-friendly format.
tinyshare 👍 3 Selected: CD
You need to use CloudWatch for dashboard, so the target must be CloudWatch. B is wrong. CloudTrail does not record user queries. A is wrong. Use Lambda to create your own solution is not recommended, E is wrong.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Redshift database audit logging can be configured to include user activity logging, which captures connections, disconnections, and the SQL statements users execute. Setting CloudWatch as the audit log destination places that data directly into CloudWatch, where it is immediately queryable and chartable (C). A CloudWatch dashboard containing a log widget, configured to display user details from those Redshift logs, then shows both the changes to Redshift users and the queries they ran, which is exactly the requested dashboard (D). C and D together give the shortest path from database audit logging to a visualization with no intermediate storage or custom code.

Why the Other Options Are Wrong

A creates a CloudWatch log group and a CloudTrail trail writing to it. CloudTrail captures the management API activity performed against the Redshift cluster, such as cluster modifications and parameter changes, but it does not record the SQL statements users run inside the database, so a dashboard built on it cannot show user queries. B creates an S3 bucket, enables default audit logging, and targets the bucket; as Srikantha and tdlAws observed, default audit logging does record user connections and queries and writing them to S3 is valid, but the requirement is a dashboard and S3-resident logs would require another service to visualize. E creates a Lambda that queries the logs with Athena plus a custom dashboard widget type that calls it; this builds a custom visualization pipeline for data that CloudWatch can display natively once the logs are delivered there, so it adds unnecessary overhead. C and D are the correct combination.

Community Comment Notes

Community voted C,D (77), with B,E a 15 percent minority and B,C appearing as another minority position. pma17 gave the decisive point: to log user queries the user activity logs must be included, which requires additional configuration on the cluster and is not mentioned in option B, and then CloudWatch is the only option that displays the logs directly. Impromptu made the same point, noting audit logging can be sent to CloudWatch Logs so a dashboard is straightforward. siheom favored B and C, which combines S3 delivery with CloudWatch display.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide