A cloud administrator needs to ensure that log data is retained for one year to meet compliance requirements. Which action should be taken for the log group in CloudWatch Logs?
Setting the log group's retention policy to 365 days directly satisfies the one-year compliance requirement, since CloudWatch Logs deletes events automatically once the configured retention period elapses. Configuring this at the log group level applies uniformly to every log stream within it, avoiding per-stream management and preventing indefinite storage costs.
Why this answer
CloudWatch Logs log groups have a retention setting that controls how long log events are kept before automatic deletion. Setting the retention policy to 365 days ensures logs are retained for exactly one year, meeting the compliance requirement without manual intervention.
Exam trap
CV0-004 often tests whether candidates know that retention is a native log group setting — candidates pick workarounds like EventBridge deletion rules or S3 export, missing the simple built-in retention policy configuration.
How to eliminate wrong answers
Option B is wrong because CloudWatch Events (now EventBridge) rules trigger actions based on events or schedules, but using a rule to delete logs after one year is an indirect, error-prone approach — the native retention setting already handles this. Option C is wrong because enabling encryption increases data durability and security but does not affect retention duration; encryption and retention are independent settings. Option D is wrong because exporting logs to S3 and deleting the log group removes the logs from CloudWatch and requires managing retention in S3 separately — it does not set retention on the log group as the question asks.