20+ practice questions focused on Security Logging and Monitoring — one of the most tested topics on the AWS Certified Security Specialty SCS-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security Logging and Monitoring PracticeA company uses Amazon GuardDuty and wants to suppress low-severity findings that are known false positives. What is the recommended approach?
Explanation: GuardDuty filters allow you to automatically suppress low-severity findings that are known false positives by setting the filter action to 'ARCHIVE'. This prevents the findings from appearing in the active findings list without disabling detection or deleting data. Filters are the recommended approach because they are purpose-built for this use case and preserve the audit trail.
A security engineer needs to capture all network traffic between EC2 instances in a VPC for forensic analysis. Which TWO services should be used together? (Choose TWO.)
Explanation: Amazon VPC Flow Logs capture IP traffic information for network interfaces in a VPC, including metadata such as source/destination IPs, ports, protocols, and packet accept/reject decisions. To perform forensic analysis on this raw flow log data, you can use Amazon Athena to query the logs directly from S3 using standard SQL, enabling efficient filtering and pattern detection across large volumes of network traffic.
Which TWO AWS services provide native integration with Amazon CloudWatch Logs for real-time monitoring of application logs? (Choose TWO.)
Explanation: Amazon EC2 is correct because the CloudWatch agent (or the legacy CloudWatch Logs agent) can be installed on EC2 instances to stream application and OS logs directly to CloudWatch Logs log groups in near real time, where metric filters and alarms can act on them. AWS Lambda is correct because it natively integrates with CloudWatch Logs: every invocation automatically writes stdout/stderr to a log group named /aws/lambda/<function-name>, enabling real-time monitoring without any agent installation. Amazon S3 is not a log-streaming source for CloudWatch Logs; it only stores objects and would require custom code or subscription filters to forward data. Amazon Route 53 publishes DNS query logs, but these are delivered to CloudWatch Logs only via explicit query logging configuration and are not application logs. AWS CloudTrail records API activity and delivers events to S3 and CloudWatch Logs, but it captures control-plane audit events, not application logs.
A security engineer needs to monitor cross-account access to resources. Which THREE AWS services can be used to log or detect such access? (Choose THREE.)
Explanation: AWS CloudTrail is correct because it logs all API calls made to the AWS environment, including cross-account access events such as AssumeRole, GetFederationToken, or any action performed by an IAM role from another account. These logs capture the source identity, target resource, and request parameters, enabling security engineers to detect and audit cross-account activity.
Refer to the exhibit. A security engineer reviews a CloudTrail log entry. What is the MOST concerning security issue?
Explanation: The root user has unrestricted access and should be used only for a few account-level tasks. Although CloudTrail audits root user activity, any routine API call by the root user violates the principle of least privilege and indicates a serious security misconfiguration. The most concerning issue is the root user performing actions beyond its limited scope, as it can indicate credential compromise or lack of proper IAM governance.
+15 more Security Logging and Monitoring questions available
Practice all Security Logging and Monitoring questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security Logging and Monitoring. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security Logging and Monitoring questions on the SCS-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security Logging and Monitoring is tested as part of the AWS Certified Security Specialty SCS-C02 blueprint. Practicing with targeted Security Logging and Monitoring questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SCS-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security Logging and Monitoring is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security Logging and Monitoring practice session with instant scoring and detailed explanations.
Start Security Logging and Monitoring Practice →