A cloud engineer is configuring logging for an AWS Lambda function that processes sensitive data. The security team requires that all invocations are logged, including the request and response payloads, and that logs are retained for 90 days. Which action should the engineer take?
Lambda automatically logs to CloudWatch Logs if the function's execution role has permissions. By adding logging statements in the function code, the engineer can log request and response payloads. Setting the CloudWatch Logs retention policy to 90 days meets the retention requirement. This is the standard way to capture detailed invocation logs, including payloads, for Lambda functions.
Why this answer
To log all invocations with request and response payloads, the Lambda function must write logs to CloudWatch Logs. This is done by including logging statements in the function code. CloudWatch Logs allows setting a retention policy of 90 days.
CloudTrail, X-Ray, and AWS Config do not capture full payloads, so they are not suitable.
Exam trap
The trap here is assuming that CloudTrail or X-Ray can capture full request and response payloads for Lambda invocations.