AWS Certified Security – Specialty — Question 41

A Security Administrator is performing a log analysis as a result of a suspected AWS account compromise. The Administrator wants to analyze suspicious AWS
CloudTrail log files but is overwhelmed by the volume of audit logs being generated.
What approach enables the Administrator to search through the logs MOST efficiently?

Answer options

Correct answer: C

Explanation

The correct answer is C because Amazon Athena allows for efficient querying of large datasets stored in S3, making it ideal for analyzing CloudTrail logs. Option A does not help with searching logs but rather filters events, while options B and D focus on data classification and notifications, respectively, rather than efficient log analysis.