Courseiva
Data Security and GovernancemediumMultiple SelectObjective-mapped

DEA-C01 Amazon Redshift Audit Logging Practice Question

A company uses Amazon Redshift to store customer data. The security team requires that all queries are logged for auditing purposes. Which step should be taken to meet this requirement? (Select ONE.)

⚠ Common exam trap

The trap is that many candidates assume AWS CloudTrail can log SQL queries, but it only logs API calls. The correct answer is solely Amazon Redshift's native audit logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Amazon Redshift audit logging to an S3 bucket.

The requirement is to log all queries for auditing. Amazon Redshift's native audit logging captures connection logs, user activity logs, and query logs, and can be exported to an S3 bucket. This is the only step that directly logs SQL queries. AWS CloudTrail does not log SQL queries; it logs management API calls (e.g., CreateCluster, ModifyCluster). Therefore, only Option E meets the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable AWS CloudTrail database audit logging.

    Why it's wrong here

    AWS CloudTrail does not have a feature called 'database audit logging' for Redshift. This option is incorrect.

  • Use AWS CloudTrail to log Redshift API calls.

    Why it's wrong here

    AWS CloudTrail logs Redshift API calls such as CreateCluster or ModifyCluster, but it does not log SQL queries. This does not meet the requirement to log all queries.

  • Enable logging on the Redshift security group.

    Why it's wrong here

    Security groups control network traffic, not query logging. This option is incorrect.

  • Enable VPC Flow Logs for the Redshift cluster.

    Why it's wrong here

    VPC Flow Logs capture network traffic metadata, not SQL queries. This option is incorrect.

  • Enable Amazon Redshift audit logging to an S3 bucket.

    Why this is correct

    Amazon Redshift supports native audit logging that captures query logs, connection logs, and user activity logs, which can be exported to an S3 bucket. This directly meets the requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,711 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.