SCS-C02 Infrastructure Security Practice Question
A company uses AWS Systems Manager Session Manager to manage EC2 instances. The security team wants to ensure that all SSH sessions are logged and that commands are recorded. What should be configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable session logging in the Session Manager preferences to send logs to Amazon S3 and CloudWatch Logs
Session Manager preferences allow logging session activity to Amazon S3 and CloudWatch Logs, which records all commands run during SSH sessions. Option B is incorrect because security groups control network access, not logging. Option C is incorrect because CloudTrail logs API calls to Systems Manager, not the commands executed within a session. Option D is incorrect because an IAM policy only controls permissions to start sessions, not the logging of session activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable session logging in the Session Manager preferences to send logs to Amazon S3 and CloudWatch Logs
Why this is correct
Enabling session logging in Session Manager preferences is the correct approach because it captures the actual interactive session stream—every keystroke, command, and output—and delivers it to centralized destinations such as Amazon S3 and CloudWatch Logs. This configuration is applied at the Systems Manager account level and can enforce audit trails for all sessions, including the ability to search and alert on command history. Without this, there is no native way to retroactively review the commands executed inside a session, making it essential for compliance and forensic requirements.
- ✗
Configure the security group to allow inbound SSH from the Session Manager service
Why it's wrong here
Session Manager does not rely on inbound SSH traffic; the AWS Systems Manager agent establishes an outbound connection to the Session Manager service over HTTPS (port 443). Therefore, configuring a security group to allow inbound SSH from the Session Manager service is technically invalid because SSH is not involved, and the session always initiates from inside the instance. Inbound security group rules would have no effect on session establishment, and port 22 remains unnecessary for this feature.
- ✗
Enable AWS CloudTrail to log Systems Manager API calls
Why it's wrong here
AWS CloudTrail records control-plane API calls such as StartSession, but it does not capture the data-plane activity—the keystrokes, command strings, or output that occur within an active Session Manager shell. While CloudTrail can show that a user started a session and when, it cannot reveal what the user actually executed inside that session. To audit command execution, you must enable Session Manager session logging, which CloudTrail cannot provide because it operates at the API level, not the interactive session level.
- ✗
Create an IAM policy that allows ssm:StartSession and attach it to the instance role
Why it's wrong here
A user-level IAM policy that allows ssm:StartSession is a permission that enables the user to initiate a Session Manager session, but it does not generate any logs of that session's activity. The policy itself is not a logging mechanism; it merely grants the API call to start the session. Furthermore, attaching this policy to the instance role would be incorrect because the instance role governs what the SSM agent can do—for logging, the agent needs write permissions to S3/CloudWatch, not the StartSession permission.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.