Courseiva

DEA-C01 Amazon Redshift Audit Logging Practice Question

A company uses Amazon Redshift to store customer data. The security team requires that all queries are logged for auditing purposes. Which step should be taken to meet this requirement? (Select ONE.)

⚠ Common exam trap

The trap is that many candidates assume AWS CloudTrail can log SQL queries, but it only logs API calls. The correct answer is solely Amazon Redshift's native audit logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Amazon Redshift audit logging to an S3 bucket.

The requirement is to log all queries for auditing. Amazon Redshift's native audit logging captures connection logs, user activity logs, and query logs, and can be exported to an S3 bucket. This is the only step that directly logs SQL queries. AWS CloudTrail does not log SQL queries; it logs management API calls (e.g., CreateCluster, ModifyCluster). Therefore, only Option E meets the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS CloudTrail database audit logging.

    Why it's wrong here

    CloudTrail records Redshift API management calls, not the SQL statements executed against the cluster. It is tempting because CloudTrail is the standard AWS auditing service, and it would be correct for tracking cluster creation, resizing, or IAM changes, but query-level auditing requires the database audit logging parameter.

  • ✗

    Use AWS CloudTrail to log Redshift API calls.

    Why it's wrong here

    CloudTrail records AWS API calls such as CreateCluster or ModifyCluster, not the SQL statements users run inside Redshift. It is tempting because CloudTrail is the default AWS auditing service, but query-level auditing needs Redshift database audit logging or the STL system tables.

  • ✗

    Enable logging on the Redshift security group.

    Why it's wrong here

    Security groups are stateful packet filters controlling inbound and outbound traffic; they cannot record SQL statements. It is tempting because security groups are a familiar Redshift network control, but query auditing requires database-level logging such as the audit log or STL system tables, not connection filtering.

  • ✗

    Enable VPC Flow Logs for the Redshift cluster.

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata for network interfaces, not the SQL statements Redshift executes, so query text is never recorded. It is tempting because flow logs do provide auditing of network connections, and they would be the right choice for tracing traffic to or from the cluster rather than query-level audit trails.

  • ✓

    Enable Amazon Redshift audit logging to an S3 bucket.

    Why this is correct

    Audit logging captures connection, user, and query activity, then delivers it to Amazon S3 for durable retention. This directly satisfies the security team's requirement that all queries are logged for auditing, since S3 provides the persistent, reviewable store auditors need.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.