A company is ingesting log files from multiple EC2 instances into Amazon S3 using the CloudWatch agent. The logs are delivered to a CloudWatch Logs group, and a subscription filter sends them to a Lambda function for transformation, then to Firehose. The Firehose stream is configured with a buffer interval of 60 seconds and buffer size of 5 MB. The logs are critical and must be available in S3 within 5 minutes. What is the most cost-effective way to reduce the delivery latency?
Lower buffer interval reduces delivery latency.
Why this answer
Decreasing the Firehose buffer interval to 10 seconds directly reduces the maximum time data waits in the buffer before being delivered to S3, ensuring logs reach S3 within the required 5-minute window. Since the current 60-second buffer interval is the primary contributor to latency, lowering it to 10 seconds minimizes delivery delay without incurring additional costs, as Firehose charges are based on data volume, not buffer frequency.
Exam trap
The trap here is that candidates may think increasing buffer size or interval improves throughput, but the question asks for reduced latency, so decreasing the buffer interval is the direct and cost-effective solution.
How to eliminate wrong answers
Option A is wrong because replacing Firehose with Kinesis Data Streams would require additional components (e.g., a consumer to write to S3) and increase cost and complexity, not reduce latency cost-effectively. Option B is wrong because increasing the buffer size to 10 MB would allow more data to accumulate before delivery, potentially increasing latency, not reducing it. Option C is wrong because increasing the buffer interval to 120 seconds would double the maximum buffering time, worsening delivery latency.