Use an organization trail in the management account with CloudWatch anomaly detection and query it with Metrics Insights

Answer Correct answer: C — use an organization trail in the management account with CloudWatch anomaly detection, and query with Metrics Insights.

A large company runs critical workloads in multiple AWS accounts. The AWS accounts are managed under AWS Organizations with all features enabled. The company stores confidential customer data in an Amazon S3 bucket. Access to the S3 bucket requires multiple levels of approval. The company wants to monitor when the S3 bucket is accessed by using the AWS CLI. The company also wants insights into the various activities performed by other users on all other S3 buckets in the AWS accounts to detect any issues. Which solution will meet these requirements?

  1. Create an AWS CloudTrail trail that is delivered to Amazon CloudWatch in each AWS account. Enable data events logs for all S3 buckets. Use Amazon GuardDuty for anomaly detection in all the AWS accounts. Use Amazon Athena to perform SQL queries on the custom metrics created from the CloudTrail logs.
  2. Create an AWS CloudTrail organization trail that is delivered to Amazon CloudWatch in the Organizations management account. Enable data events logs for all S3 buckets. Use Amazon CloudWatch anomaly detection in all the AWS accounts. Use Amazon Athena to perform SQL queries on the custom metrics created from the CloudTrail logs.
  3. Create an AWS CloudTrail organization trail that is delivered to Amazon CloudWatch in the Organizations management account. Enable data events logs for all S3 buckets. Use Amazon CloudWatch anomaly detection in all the AWS accounts. Use Amazon CloudWatch Metrics Insights to perform SQL queries on the custom metrics created from the CloudTrail logs. Correct Answer
  4. Create an AWS CloudTrail trail that is delivered to Amazon CloudWatch in each AWS account. Enable data events logs for all S3 buckets. Use a custom solution for anomaly detection in all the AWS accounts. Use Amazon CloudWatch Metrics Insights to perform SQL queries on the custom metrics created from the CloudTrail logs.

Community Votes

C
75%
B
25%

75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An organization trail captures CloudTrail data events in every member account into one place, which is what the multi-account requirement needs, whereas per-account trails in options A and D would leave the engineer querying each account separately (C). CloudWatch anomaly detection operates on CloudWatch metrics, so it is the appropriate detection mechanism (C). Because the analysis target is metrics rather than S3 data, Metrics Insights is the correct query engine; Athena queries S3 datasets and cannot run against CloudWatch metrics (B).

Monitoring S3 access across all accounts requires a single organization trail delivered to CloudWatch in the Organizations management account, with data events enabled so object-level activity on every bucket is recorded. Amazon CloudWatch anomaly detection then surfaces unusual activity for investigation, and CloudWatch Metrics Insights, which queries metric data using SQL, is the correct tool for running queries against the custom metrics derived from those logs. Athena is not appropriate because it queries data stored in S3 rather than CloudWatch metrics.

Using Amazon Athena to run SQL queries on the custom metrics created from the CloudTrail logs (A and B) — as jojewi8143 and teo2157 both pointed out, Athena performs queries against data in Amazon S3, not against CloudWatch metrics, so it is the wrong engine for metric data. Creating trails per account instead of an organization trail (A and D) — with many accounts this fragments the investigation and does not provide the consolidated visibility the requirement describes. Using a custom anomaly detection solution (D) — CloudWatch anomaly detection already provides this for metrics, so a custom solution adds work without benefit.

Community Discussion (5 comments)

jojewi8143 👍 1 Selected: C
Athena can only perform queries in S3 buckets, not in cloudwatch metrics.
teo2157 👍 2 Selected: C
Athena can only permorm queries in S3 buckets, not in cloudwatch metrics. Based on that, it's C.
Slays 👍 1 Selected: B
Athena allows for ad-hoc analysis of log data, enabling you to investigate specific events or trends without the need to set up complex data processing pipelines.
matt200 👍 3 Selected: C
Amazon CloudWatch Metrics Insights can perform SQL queries
spring21 👍 1 Selected: B
You have now set up an AWS CloudTrail organization trail that sends logs to CloudWatch, enabled anomaly detection on the CloudTrail logs, and configured Amazon Athena to query those logs with SQL. You can further optimize this setup by incorporating Lambda functions, setting more complex anomaly detection configurations, or using AWS Security Hub for better monitoring and automation.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement covers S3 access across many AWS accounts, so a CloudTrail organization trail delivered to Amazon CloudWatch in the Organizations management account is the right collection mechanism: it captures activity from every member account into a single destination, and enabling data events ensures object-level operations on all S3 buckets are recorded (C). Amazon CloudWatch anomaly detection then establishes baselines on those metrics and flags unusual activity, providing the issue detection the requirement asks for. Because the analysis target is CloudWatch metrics derived from those logs, CloudWatch Metrics Insights is the correct engine for running SQL queries, since it queries metric data directly and can even scope queries by AWS.AccountId in a monitoring account. C is the correct answer.

Why the Other Options Are Wrong

A creates a separate trail in each account rather than an organization trail, uses GuardDuty for anomaly detection instead of CloudWatch anomaly detection, and queries the resulting custom metrics with Athena. Each of these choices is wrong: per-account trails fragment the cross-account investigation, GuardDuty is a threat detection service rather than a metric anomaly detector, and Athena queries data held in Amazon S3 rather than CloudWatch metrics, as multiple commenters noted. B uses the correct organization trail and CloudWatch anomaly detection but finishes with Athena, which cannot query CloudWatch metrics, making the analysis step impossible. D creates per-account trails, replaces CloudWatch anomaly detection with a custom solution, and uses Metrics Insights; while Metrics Insights is correct, the per-account trails and the unnecessary custom anomaly detection defeat the multi-account requirement and add work. C is correct.

Community Comment Notes

Community voted C (75), with B a 25 percent minority. jojewi8143 and teo2157 gave the decisive reason, that Athena can only run queries against data in S3 buckets and not against CloudWatch metrics, and matt200 confirmed that CloudWatch Metrics Insights is the service that runs SQL queries on metrics. The B position held that Athena is good for ad-hoc log analysis, but the question's target is custom metrics.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide