AnswerCorrect answer: B — use CloudTrail to capture Cognito events in S3 and query InitiateAuth/SignUp with Athena.
A company uses Amazon Cognito as an OAuth 2.0 identity platform for its web and mobile applications. The company needs to capture successful and unsuccessful login attempts. The company also needs to query the data about the login attempts. Which solution will meet these requirements?
Configure Cognito to send logs of user activity to Amazon CloudWatch. Configure Amazon EventBridge to invoke an AWS Lambda function to export the logs to an Amazon S3 bucket. Use Amazon Athena to query the logs for event names of SignUp with event sources of cognito-idp.amazonaws.com.
Enable AWS CloudTrail to deliver logs to an Amazon S3 bucket. Use Amazon Athena to query the logs for event names of InitiateAuth with event sources of cognito-idp.amazonaws.com. Correct Answer
Configure AWS CloudTrail to send Cognito CloudTrail events to Amazon CloudWatch for monitoring. Query the event logs for event names of SignUp with event sources of cognito-idp.amazonaws.com.
Configure Amazon CloudWatch metrics to monitor and report Cognito events. Create a CloudWatch dashboard for the provided metrics. Display the Cognito user pools for event names of InitiateAuth with event sources of cognito-idp.amazonaws.com.
Community Votes
B
80%
A
20%
80% of anonymous learners picked answer B.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Cognito authentication attempts surface as CloudTrail management events (InitiateAuth for sign-in, SignUp for registration), so CloudTrail → S3 → Athena (B) is the correct capture-and-query pipeline. Cognito does not emit user auth activity to CloudWatch logs by default (A's CloudWatch path and D's metrics/dashboard are insufficient for querying individual attempts). B is correct; A was a minority alternative.
To capture both successful and unsuccessful Cognito login attempts and query them, use AWS CloudTrail, which records Cognito API calls such as InitiateAuth and SignUp (with event source cognito-idp.amazonaws.com), deliver the logs to an S3 bucket, and query the events with Amazon Athena. Cognito does not stream raw login-activity logs to CloudWatch by default, so CloudTrail is the source of truth for auth events.
Assuming Cognito sends login activity to CloudWatch (A/D)—by default auth events are CloudTrail management events, not CloudWatch log streams, so you cannot query individual attempts there. Using CloudWatch metrics/dashboards (D)—they aggregate, they do not let you query specific InitiateAuth/SignUp events. CloudTrail + Athena (B) is the queryable source.
Community Discussion (4 comments)
Pmktechno👍 2Selected: B
AWS CloudTrail provides detailed logs of all API calls made to Amazon Cognito, including login attempts. Amazon S3 is used to store these logs, ensuring they are easily accessible and durable. Amazon Athena allows you to run SQL queries on the logs stored in S3, making it straightforward to filter and analyze the data for specific events, such as InitiateAuth, which corresponds to login attempts. This setup ensures that you can capture both successful and unsuccessful login attempts and query the data efficiently.
sypaladinzi👍 1Selected: B
B is the Answer: CloudTrail logs all API calls to Cognito, including login attempts (InitiateAuth events). S3 stores the logs for analysis. Athena allows querying these logs for successful and unsuccessful login attempts using event names (InitiateAuth) and sources (cognito-idp.amazonaws.com).
Ucy👍 1Selected: B
B is correct CloudTrail to deliver logs to an Amazon S3 bucket. Use Amazon Athena to query the logs
jdx000👍 1Selected: A
A is the answer
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
Amazon Cognito authentication activity (InitiateAuth for sign-in, SignUp for registration) is recorded as AWS CloudTrail management events with event source cognito-idp.amazonaws.com. Delivering those CloudTrail logs to an S3 bucket and querying them with Amazon Athena lets the company both capture and analyze successful and unsuccessful login attempts.
Why the Other Options Are Wrong
A relies on Cognito sending user-activity logs to CloudWatch and a Lambda export, but Cognito auth events are CloudTrail events, not CloudWatch log streams, so querying is unreliable there. C similarly assumes CloudTrail-to-CloudWatch monitoring covers querying, which it does not. D uses CloudWatch metrics/dashboards, which aggregate and do not allow querying individual events. B is correct.
Community Comment Notes
Community voted B (80), with A a 20 minority. Commenters noted CloudTrail logs all Cognito API calls including login attempts (InitiateAuth) to S3, and Athena queries them; A's CloudWatch path was seen as less complete for querying. B confirmed.