CCSP Cloud Security Operations Practice Question
A cloud engineer is configuring logging for an AWS Lambda function that processes sensitive data. The security team requires that all invocations are logged, including the request and response payloads, and that logs are retained for 90 days. Which action should the engineer take?
⚠ Common exam trap
The trap here is assuming that CloudTrail or X-Ray can capture full request and response payloads for Lambda invocations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Lambda function to log to Amazon CloudWatch Logs and set the log group retention to 90 days.
To log all invocations with request and response payloads, the Lambda function must write logs to CloudWatch Logs. This is done by including logging statements in the function code. CloudWatch Logs allows setting a retention policy of 90 days. CloudTrail, X-Ray, and AWS Config do not capture full payloads, so they are not suitable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS X-Ray tracing for the Lambda function and configure a 90-day retention for X-Ray traces.
Why it's wrong here
AWS X-Ray traces provide insights into performance and dependencies, but they do not log full request and response payloads. X-Ray captures metadata and segment data, but not the entire payload. Additionally, X-Ray retention is fixed at 30 days and cannot be extended to 90 days. This option fails to meet both the payload logging and retention requirements.
- ✗
Use AWS Config to record Lambda function configurations and set a 90-day retention for configuration history.
Why it's wrong here
AWS Config records configuration changes to Lambda functions, such as updates to code or environment variables, but it does not log invocations or payloads. Config is for compliance and configuration tracking, not for logging runtime data. The retention for configuration history is also not customizable to 90 days; it is retained indefinitely or as per delivery channel settings.
- ✓
Configure the Lambda function to log to Amazon CloudWatch Logs and set the log group retention to 90 days.
Why this is correct
Lambda automatically logs to CloudWatch Logs if the function's execution role has permissions. By adding logging statements in the function code, the engineer can log request and response payloads. Setting the CloudWatch Logs retention policy to 90 days meets the retention requirement. This is the standard way to capture detailed invocation logs, including payloads, for Lambda functions.
- ✗
Enable AWS CloudTrail logging for the Lambda function and configure a CloudWatch Logs retention policy of 90 days.
Why it's wrong here
AWS CloudTrail logs API calls to Lambda, such as Invoke, but it does not log the request and response payloads. CloudTrail records management events and some data events, but Lambda data events only log the invocation itself, not the payload. Therefore, this approach does not meet the requirement to log all invocations with payloads.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.