Send Redshift user activity audit logs to CloudWatch and display them with a CloudWatch Logs dashboard widget
A company uses Amazon Redshift as its data warehouse solution. The company wants to create a dashboard to view changes to the Redshift users and the queries the users perform. Which combination of steps will meet this requirement? (Choose two.)
Community Votes
84% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement is a dashboard showing user changes and queries, and the shortest path is CloudWatch end to end: Redshift audit logging with user activity logs enabled delivers to CloudWatch, and a CloudWatch dashboard log widget renders it (C and D). Option A sends CloudTrail to CloudWatch, but CloudTrail records Redshift API calls such as cluster modifications, not the SQL statements users execute inside the cluster, so it cannot show their queries. Option B's default audit logging captures connection and query information but only to S3, and option E requires a Lambda plus a custom widget type to surface data that CloudWatch can already display natively.
Redshift database audit logging can include user activity logging, which records connections, disconnections, and the SQL statements users run. Configuring the cluster's database audit logging to include user activity logs and targeting Amazon CloudWatch as the destination puts that data where it can be charted directly, and a CloudWatch dashboard with a log widget configured to show user details from the Redshift logs presents both the user changes and their queries.
Creating a CloudTrail trail writing to a CloudWatch log group (A) — CloudTrail records the management API activity against the Redshift cluster, not the SQL statements users run inside the database, so the dashboard would not show user queries. Using S3 as the audit log destination (B) — Srikantha and tdlAws both noted default audit logging does capture users and queries and writes them to S3, but the requirement is a CloudWatch dashboard, and S3 data would need Athena plus a custom Lambda to visualize, which is what option E proposes. Using a Lambda and a custom dashboard widget type (E) — unnecessary, because audit logs delivered to CloudWatch can be rendered by a standard log widget.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Redshift database audit logging can be configured to include user activity logging, which captures connections, disconnections, and the SQL statements users execute. Setting CloudWatch as the audit log destination places that data directly into CloudWatch, where it is immediately queryable and chartable (C). A CloudWatch dashboard containing a log widget, configured to display user details from those Redshift logs, then shows both the changes to Redshift users and the queries they ran, which is exactly the requested dashboard (D). C and D together give the shortest path from database audit logging to a visualization with no intermediate storage or custom code.Why the Other Options Are Wrong
A creates a CloudWatch log group and a CloudTrail trail writing to it. CloudTrail captures the management API activity performed against the Redshift cluster, such as cluster modifications and parameter changes, but it does not record the SQL statements users run inside the database, so a dashboard built on it cannot show user queries. B creates an S3 bucket, enables default audit logging, and targets the bucket; as Srikantha and tdlAws observed, default audit logging does record user connections and queries and writing them to S3 is valid, but the requirement is a dashboard and S3-resident logs would require another service to visualize. E creates a Lambda that queries the logs with Athena plus a custom dashboard widget type that calls it; this builds a custom visualization pipeline for data that CloudWatch can display natively once the logs are delivered there, so it adds unnecessary overhead. C and D are the correct combination.Community Comment Notes
Community voted C,D (77), with B,E a 15 percent minority and B,C appearing as another minority position. pma17 gave the decisive point: to log user queries the user activity logs must be included, which requires additional configuration on the cluster and is not mentioned in option B, and then CloudWatch is the only option that displays the logs directly. Impromptu made the same point, noting audit logging can be sent to CloudWatch Logs so a dashboard is straightforward. siheom favored B and C, which combines S3 delivery with CloudWatch display.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →