AnswerCorrect answer: C — Kinesis Agent feeds Firehose, Managed Flink processes in real time, and OpenSearch stores logs for 365 days with an ISM delete policy.
A company wants to create a log analytics solution for logs generated from its on-premises devices. The logs are collected from the devices onto a server on premises. The company wants to use AWS services to perform near real-time log analysis. The company also wants to store these logs for 365 days for pattern matching and substring search capabilities later. Which solution will meet these requirements with the LEAST development overhead?
Install Amazon Kinesis Agent on the on-premises server to send the logs to Amazon DynamoDB. Configure an AWS Lambda trigger on DynamoDB streams to perform near real-time log analysis. Export the DynamoDB data to Amazon S3 periodically. Run Amazon Athena queries for pattern matching and substring search. Set up S3 Lifecycle policies to delete the log data after 365 days.
Install Amazon Managed Streaming for Apache Kafka (Amazon MSK) on the on-premises server. Create an MSK cluster to collect the streaming data and analyze the data in real time. Set the data retention period to 365 days to store the logs persistently for pattern matching and substring search.
Install Amazon Kinesis Agent on the on-premises server to send the logs to Amazon Kinesis Data Firehose. Configure Amazon Managed Service for Apache Flink (previously known as Amazon Kinesis Data Analytics) as the destination for real-time processing. Store the logs in Amazon OpenSearch Service for pattern matching and substring search. Configure an OpenSearch Service Index State Management (ISM) policy to delete the data after 365 days. Correct Answer
Use Amazon API Gateway and AWS Lambda to write the logs from the on-premises server to Amazon DynamoDB. Configure a Lambda trigger on DynamoDB streams to perform near real-time log analysis. Run Amazon Athena federated queries on DynamoDB data for pattern matching and substring search. Set up TTL to delete data after 365 days.
Community Votes
C
100%
100% of anonymous learners picked answer C.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The Kinesis Agent + Firehose + Managed Flink + OpenSearch combo is a fully managed, low-code pipeline: Agent collects, Firehose delivers, Flink processes in real time, OpenSearch stores and searches with ISM lifecycle deletion. DynamoDB+Lambda (A/D) and MSK-on-prem (B, which is not installable on premises) require far more custom development.
On-premises device logs must be analyzed in near real time on AWS and retained 365 days for pattern/substring search. Install the Kinesis Agent on premises to send logs to Kinesis Data Firehose, use Managed Service for Apache Flink as the real-time processing destination, and persist logs in OpenSearch Service with an Index State Management policy that deletes data after 365 days—least development overhead.
Routing through DynamoDB + Lambda (A/D)—that forces you to build and manage Lambda functions for both real-time analysis and querying, plus DynamoDB is not ideal for substring/log search. Choosing MSK (B) is invalid because MSK is a managed AWS service, not something installed on-premises.
Community Discussion (4 comments)
aescudero51👍 3Selected: C
My answer is C. Pre-built tools: Leverages pre-built tools like Kinesis Agent for data collection and Firehose for delivery. Flink provides real-time processing capabilities without needing to build custom logic. Managed Services: Utilizes managed services like OpenSearch Service which eliminates the need for manual provisioning and maintenance of an Elasticsearch cluster. Automated Lifecycle Management: OpenSearch Service ISM policy automates data deletion after 365 days, reducing manual intervention.
Certified101👍 3Selected: C
The correct answer is: C. Install Amazon Kinesis Agent on the on-premises server to send the logs to Amazon Kinesis Data Firehose. Configure Amazon Managed Service for Apache Flink (previously known as Amazon Kinesis Data Analytics) as the destination for real-time processing. Store the logs in Amazon OpenSearch Service for pattern matching and substring search. Configure an OpenSearch Service Index State Management (ISM) policy to delete the data after 365 days. This solution meets all the requirements with the least development overhead. Amazon Kinesis Agent can be used to collect and send logs to Amazon Kinesis Data Firehose, which can handle real-time streaming data. Amazon Managed Service for Apache Flink can be used for real-time processing. The logs can be stored in Amazon OpenSearch Service (formerly known as Amazon Elasticsearch Service), which provides powerful search capabilities. An ISM policy can be configured to automatically delete data after 365 days. The other options either involve more development overhead or do not meet all the requirements.
Nash101👍 1
C A. DynamoDB with Lambda: This option requires building and managing Lambda functions for both real-time analysis and triggering Athena queries. Additionally, DynamoDB might not be the optimal choice for long-term log storage due to its cost structure. B. Amazon MSK: While MSK can handle streaming data, it requires more configuration and potentially custom code for real-time analysis compared to a managed service like AMSK. D. API Gateway and Lambda: This option requires significant development effort to build and manage API Gateway endpoints and Lambda functions for log ingestion and analysis. Additionally, using DynamoDB with federated Athena queries might be less performant for complex log search needs compared to OpenSearch Service.
Zek👍 3
I think answer is C B is wrong because Amazon Managed Streaming for Apache Kafka (Amazon MSK) is not a service that is installed on-premises, it is a managed service on AWS.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
The Kinesis Agent runs on premises to ship logs into Firehose; Firehose delivers to Managed Service for Apache Flink for near-real-time processing, and OpenSearch Service stores the logs for pattern matching and substring search with an ISM policy deleting them after 365 days. This is the least-development-overhead, fully managed path.
Why the Other Options Are Wrong
A and D push logs into DynamoDB and rely on Lambda triggers plus Athena/TTL for search—significant custom code and DynamoDB is a poor fit for substring log search. B is invalid because Amazon MSK is a managed AWS service and cannot be 'installed on the on-premises server' as described. C is the correct managed pipeline.
Community Comment Notes
Community voted C (100). Commenters praised the pre-built tools (Kinesis Agent, Firehose, Flink) and noted B fails because MSK is not on-prem-installable. C was described as least overhead.