SCS-C02 Security Logging and Monitoring • Set 2
SCS-C02 Security Logging and Monitoring Practice Test 2 — 15 questions with explanations. Free, no signup.
A company runs a critical application on an Auto Scaling group of EC2 instances behind an Application Load Balancer. The security team enabled VPC Flow Logs, CloudTrail, and CloudWatch Logs for the application tier. Recently, they noticed that some EC2 instances are being terminated unexpectedly by an unknown IAM user. The CloudTrail logs show the TerminateInstances API call, but the source IP address is from within the VPC CIDR range. The security team suspects the action is coming from an EC2 instance that has been compromised. They need to identify the specific compromised instance and the IAM role it used. Which combination of steps will provide the necessary information? (Choose TWO.)
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.