Courseiva

CCSP Cloud Security Operations Practice Question

A cloud engineer is configuring logging for an AWS Lambda function that processes sensitive data. The security team requires that all invocations are logged, including the request and response payloads, and that logs are retained for 90 days. Which action should the engineer take?

⚠ Common exam trap

The trap here is assuming that CloudTrail or X-Ray can capture full request and response payloads for Lambda invocations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Lambda function to log to Amazon CloudWatch Logs and set the log group retention to 90 days.

To log all invocations with request and response payloads, the Lambda function must write logs to CloudWatch Logs. This is done by including logging statements in the function code. CloudWatch Logs allows setting a retention policy of 90 days. CloudTrail, X-Ray, and AWS Config do not capture full payloads, so they are not suitable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS X-Ray tracing for the Lambda function and configure a 90-day retention for X-Ray traces.

    Why it's wrong here

    AWS X-Ray traces provide insights into performance and dependencies, but they do not log full request and response payloads. X-Ray captures metadata and segment data, but not the entire payload. Additionally, X-Ray retention is fixed at 30 days and cannot be extended to 90 days. This option fails to meet both the payload logging and retention requirements.

  • ✗

    Use AWS Config to record Lambda function configurations and set a 90-day retention for configuration history.

    Why it's wrong here

    AWS Config records configuration changes to Lambda functions, such as updates to code or environment variables, but it does not log invocations or payloads. Config is for compliance and configuration tracking, not for logging runtime data. The retention for configuration history is also not customizable to 90 days; it is retained indefinitely or as per delivery channel settings.

  • ✓

    Configure the Lambda function to log to Amazon CloudWatch Logs and set the log group retention to 90 days.

    Why this is correct

    Lambda automatically logs to CloudWatch Logs if the function's execution role has permissions. By adding logging statements in the function code, the engineer can log request and response payloads. Setting the CloudWatch Logs retention policy to 90 days meets the retention requirement. This is the standard way to capture detailed invocation logs, including payloads, for Lambda functions.

  • ✗

    Enable AWS CloudTrail logging for the Lambda function and configure a CloudWatch Logs retention policy of 90 days.

    Why it's wrong here

    AWS CloudTrail logs API calls to Lambda, such as Invoke, but it does not log the request and response payloads. CloudTrail records management events and some data events, but Lambda data events only log the invocation itself, not the payload. Therefore, this approach does not meet the requirement to log all invocations with payloads.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.