Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator notices that an Amazon CloudWatch Logs log group is growing rapidly and suspects that an EC2 instance is sending sensitive data to the logs. What is the most effective way to detect and redact sensitive data in real-time?

⚠ Common exam trap

Many candidates confuse CloudWatch Logs Insights (a query tool) with a real-time processing capability, or they over-engineer the solution by involving S3 or Kinesis when a direct subscription filter is the simplest and most effective real-time redaction method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudWatch Logs subscription filter that invokes a Lambda function for redaction.

CloudWatch Logs subscription filters can invoke a Lambda function in real-time as log events are ingested. This allows the Lambda function to inspect, detect, and redact sensitive data (e.g., credit card numbers or passwords) before the logs are stored in the log group, meeting the requirement for real-time detection and redaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use CloudWatch Logs Insights to query and mask sensitive data.

    Why it's wrong here

    CloudWatch Logs Insights is a read-only query and analytics engine that searches log data already stored in CloudWatch Logs. It can display matching events or build visualizations, but it has no ability to rewrite or redact the actual stored log records. Because masking must happen at ingestion to prevent sensitive data from ever being persisted, Insights can only surface the problem, not fix it in real time.

  • ✗

    Enable S3 event notifications to trigger a Lambda function for redaction.

    Why it's wrong here

    S3 event notifications trigger a Lambda function only after a new object has been written to an S3 bucket. This requires first delivering the raw logs from CloudWatch Logs to S3, meaning unmasked sensitive data is already stored and accessible before Lambda executes. The asynchronous, object-creation-based flow introduces significant latency and an exposure window, unlike a subscription filter that intercepts the stream immediately at the source.

  • ✓

    Create a CloudWatch Logs subscription filter that invokes a Lambda function for redaction.

    Why this is correct

    A CloudWatch Logs subscription filter with a Lambda destination is the native near-real-time mechanism for processing incoming log events. When new log events arrive, the subscription filter immediately invokes the Lambda function, which can decode the gzip-compressed payload, redact sensitive fields, and forward the sanitized data to its final storage destination. This direct integration avoids intermediate storage or additional pipeline services, making it the most efficient and purpose-built solution for real-time log redaction.

  • ✗

    Send logs to Amazon Kinesis Data Firehose and use Lambda for redaction.

    Why it's wrong here

    Kinesis Data Firehose can use a Lambda function as a transform processor, but this approach requires first configuring a CloudWatch Logs subscription filter to deliver logs to the Firehose delivery stream, then attaching a Lambda transform to that stream. This adds extra infrastructure components and operational complexity compared to a direct subscription filter that invokes Lambda. Additionally, Firehose buffers data before invoking the transform, introducing unnecessary latency and making it a less direct and less efficient option for real-time redaction.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.