SAP-C02 Continuous Improvement for Existing Solutions Practice Question
A company runs a multi-account AWS environment managed with AWS Organizations. Each account sends VPC Flow Logs, AWS CloudTrail logs, and application logs to a central Amazon S3 bucket in the logging account. The security team needs to query up to 5 years of logs with ad-hoc SQL, correlate events across accounts, and minimize ongoing storage cost for logs older than 90 days. The logs must remain immediately queryable without restoration. Which solution meets these requirements MOST cost-effectively?
⚠ Common exam trap
The trap here is assuming the cheapest archival storage class (Glacier Deep Archive) is always best, overlooking that its multi-hour retrieval latency breaks the immediate-query requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deliver all logs to Amazon S3, register the bucket with AWS Glue Data Catalog, and query with Amazon Athena. Transition objects older than 90 days to S3 Glacier Instant Retrieval using an S3 Lifecycle rule.
Athena with the AWS Glue Data Catalog queries S3 logs in place using standard SQL, providing ad-hoc, cross-account analysis without managing servers. Moving older objects to S3 Glacier Instant Retrieval reduces storage cost while preserving millisecond retrieval, so historical logs stay immediately queryable. Together these services satisfy the query, retention, and cost requirements more effectively than cluster-based or Deep Archive alternatives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deliver all logs to Amazon S3 and query them with Amazon CloudWatch Logs Insights after exporting each account's logs to CloudWatch Logs. Set a 5-year retention policy on the log groups.
Why it's wrong here
CloudWatch Logs Insights is designed for interactive analysis of log groups, not for cost-effective long-term archival querying. Ingesting and storing 5 years of high-volume logs in CloudWatch Logs is significantly more expensive than S3, and cross-account correlation becomes cumbersome. This approach increases cost and complexity without meeting the archival cost goal.
- ✗
Deliver all logs to Amazon S3, crawl them with AWS Glue crawlers, and query with Amazon Athena. Transition objects older than 90 days to S3 Glacier Deep Archive.
Why it's wrong here
S3 Glacier Deep Archive is the lowest-cost storage class, but archived objects are not immediately queryable; retrieval takes hours and Athena cannot query them until restored. The requirement states logs must remain immediately queryable without restoration, so Deep Archive fails that constraint despite being cheaper. Glacier Instant Retrieval is the appropriate archival class for this access pattern.
- ✗
Deliver all logs to Amazon S3, load them nightly into Amazon Redshift Spectrum external tables, and query with Amazon Redshift. Compress older data with columnar storage.
Why it's wrong here
Redshift Spectrum can query S3, but it requires provisioning and managing a Redshift cluster, which adds fixed compute cost and operational overhead that Athena avoids. For sporadic ad-hoc SQL over large log archives, a persistent cluster is more expensive and less elastic. It also does not address the immediate-query requirement for archived logs as directly as an instant-retrieval storage class.
- ✓
Deliver all logs to Amazon S3, register the bucket with AWS Glue Data Catalog, and query with Amazon Athena. Transition objects older than 90 days to S3 Glacier Instant Retrieval using an S3 Lifecycle rule.
Why this is correct
Athena queries S3 data in place using the Glue Data Catalog, so no loading or cluster management is needed, and it supports ad-hoc SQL across accounts. S3 Glacier Instant Retrieval keeps archived objects millisecond-retrievable, satisfying the immediate query requirement while cutting storage cost for logs older than 90 days. This combination is the most cost-effective fit for the stated query pattern and retention.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.