Courseiva
Monitoring and Logging →mediumMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A company is using Amazon CloudWatch Logs to store application logs. The security team requires that logs are encrypted at rest using a customer-managed KMS key. Which TWO steps must be taken to achieve this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a statement to the KMS key policy that allows CloudWatch Logs to use the key.

To encrypt CloudWatch Logs at rest with a customer-managed KMS key, you must add a statement to the KMS key policy granting CloudWatch Logs permission to use the key (option B). Then, use the put-log-group-encryption API to associate the KMS key with the log group (option E). Option C is incorrect because CloudWatch Logs uses key policies, not grants. Option D is incorrect because you specify the key ARN at the log group level, not per log stream. Option A is incorrect because you do not need to recreate the log group; you can associate the key with an existing log group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Recreate the log group after associating the key.

    Why it's wrong here

    Recreating the log group after associating the key is unnecessary and destructive because encryption can be enabled on an existing log group via the PutLogGroupEncryption API. The API only changes the log group's encryption settings; it does not require re-creation, and recreating the group would delete all existing log streams and historical events. Therefore, this action adds no benefit and causes data loss.

  • ✓

    Add a statement to the KMS key policy that allows CloudWatch Logs to use the key.

    Why this is correct

    To use a customer-managed KMS key, the key policy must explicitly grant the CloudWatch Logs service principal (logs.<region>.amazonaws.com) the required cryptographic permissions: kms:Encrypt, kms:Decrypt, kms:ReEncrypt, kms:GenerateDataKey, and kms:DescribeKey. Without an Allow statement, CloudWatch Logs cannot decrypt the key for the log group, and the association or ingest operations will fail. The key policy is the sole authorization mechanism for this integration.

  • ✗

    Create a KMS grant to allow CloudWatch Logs to use the key.

    Why it's wrong here

    A KMS grant is not a substitute for a key policy in this scenario. Grants are used by certain AWS services in cross-account contexts such as S3 bucket encryption, but CloudWatch Logs does not call kms:CreateGrant nor rely on grants to perform encryption/decryption on log data. The service authenticates exclusively against the KMS key policy, so an attempt to create a grant would leave the log group unable to use the key.

  • ✗

    Specify the KMS key ARN when creating each log stream.

    Why it's wrong here

    Encryption in CloudWatch Logs is a property of the log group, not of individual log streams. When you create a log stream with CreateLogStream or PutLogEvents, no KMS key parameter or ARN is accepted; log streams automatically inherit the encryption configuration from their parent log group. Attempting to supply a KMS key ARN per log stream is invalid and would not achieve encryption.

  • ✓

    Use the put-log-group-encryption API to associate the KMS key with the log group.

    Why this is correct

    The PutLogGroupEncryption API is the correct operation to associate a customer-managed KMS key with a log group. It accepts the log group name or ARN and the KMS key ID, and it enables encryption at rest for newly ingested log events. This API can also update an existing log group to a different KMS key, making it the intended mechanism for this requirement.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.