AnswerCorrect answer: C — Amazon Security Lake (delegated admin) aggregates and normalizes org, Marketplace, and on-prem logs for Athena queries.
A company needs to create a centralized solution to analyze log files. The company uses an organization in AWS Organizations to manage its AWS accounts. The solution must aggregate and normalize events from the following sources: • The entire organization in Organizations • All AWS Marketplace offerings that run in the company’s AWS accounts • The company's on-premises systems Which solution will meet these requirements?
Configure a centralized Amazon S3 bucket for the logs. Enable VPC Flow Logs, AWS CloudTrail. and Amazon Route 53 logs in all accounts. Configure all accounts to use the centralized S3 bucket. Configure AWS Glue crawlers to parse the log files. Use Amazon Athena to query the log data.
Configure log streams in Amazon CloudWatch Logs for the sources that need monitoring Create log subscription filters for each log stream. Forward the messages to Amazon OpenSearch Service for analysis.
Set up a delegated Amazon Security Lake administrator account in Organizations. Enable and configure Security Lake for the organization. Add the accounts that need monitoring. Use Amazon Athena to query the log data. Correct Answer
Apply an SCP to configure all member accounts and services to deliver log files to a centralized Amazon S3 bucket. Use Amazon OpenSearch Service to query the centralized S3 bucket for log entries.
Community Votes
C
100%
100% of anonymous learners picked answer C.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Security Lake's purpose is exactly centralized, normalized security-log collection across AWS accounts, third-party/SaaS (including Marketplace) sources, and on-premises, converting events to the Open Cybersecurity Schema Framework (OCSF). Setting a delegated admin account in Organizations gives the centralized management the scenario requires, and Athena queries the resulting data lake.
A company needs one place to aggregate and normalize logs from its entire Organizations organization, AWS Marketplace offerings, and on-premises systems. Amazon Security Lake is a delegated-administrator service in Organizations that automatically collects and normalizes security data from AWS, SaaS/Marketplace, and on-prem sources into the OCSF schema, stored in an account-owned data lake that Amazon Athena can query.
Hand-rolling S3 + CloudTrail/VPC Flow Logs + Glue + Athena, which stores logs centrally but does not normalize heterogeneous sources (Marketplace, on-prem) into one schema and is far more operationally heavy than Security Lake.
Community Discussion (7 comments)
TareDHakim👍 1Selected: C
agree with Security Lake being ideal for purpose.
nischal77777👍 3Selected: C
Amazon Security Lake is designed to automatically collect, normalize, and store security-related data across AWS accounts and on-premises systems. Security Lake can be set up in a delegated administrator account within AWS Organizations, allowing centralized management and configuration across all accounts in the organization. Amazon Athena can be used to query and analyze the log data stored in Security Lake, providing a powerful and flexible way to gain insights from the aggregated logs. Using Amazon Security Lake provides a streamlined and integrated approach to centralized log management across your entire AWS organization and on-premises systems, making it the most effective and efficient solution for your needs.
Savinda👍 2Selected: C
C should be the answer
xekiva3329👍 3Selected: C
answer: C
cumzle_com👍 3Selected: C
Considering the requirements to aggregate and normalize logs from the entire AWS organization, AWS Marketplace offerings, and on-premises systems into a centralized solution for analysis, Amazon Security Lake appears to provide a more comprehensive and automated approach compared to Options A/B
grekh001👍 4
C Amazon Security Lake automatically centralizes security data from AWS environments, SaaS providers, on premises, and cloud sources into a purpose-built data lake stored in your account. With OCSF support, the service normalizes and combines security data from AWS and a broad range of enterprise security data sources. https://aws.amazon.com/security-lake/
aescudero51👍 2Selected: B
Answer A: While S3 can store logs centrally, it lacks the log management and analysis features of CloudWatch Logs and OpenSearch Service. Additionally, using Glue crawlers and Athena would be a more complex approach for real-time analysis. Answer C: Security Lake is primarily focused on security data analysis, and it might be overkill for general log analysis from various sources. Answer D: SCP can enforce centralized log storage in S3, but it wouldn't offer the collection, filtering, and advanced analytics capabilities needed. Additionally, querying logs directly from S3 with OpenSearch Service would be inefficient. Therefore, Answer B offers a centralized, flexible, and scalable solution for collecting, filtering, and analyzing logs from the organization, on-premises systems, and AWS Marketplace offerings.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
Security Lake is built to automatically centralize and normalize security data from the whole AWS organization, SaaS providers (which cover AWS Marketplace-run offerings), and on-premises systems into OCSF-formatted data in your own account. A delegated administrator account in Organizations provides the centralized control, and Athena queries the data lake, satisfying aggregation, normalization, and analysis in one managed service.
Why the Other Options Are Wrong
A stores logs in a central S3 bucket and uses Glue/Athena, but it does not normalize Marketplace and on-prem sources into a common schema and is manually assembled. B forwards only CloudWatch Logs sources to OpenSearch and cannot ingest the full organization, Marketplace, and on-prem breadth. D uses an SCP to force log delivery, which is brittle and cannot normalize or cover on-prem/Marketplace sources.
Community Comment Notes
Community chose C (86 votes), citing Security Lake's automatic normalization via OCSF and delegated-admin setup in Organizations. A commenter noted A lacks normalization and is more complex for the required heterogeneous sources.