Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses AWS Systems Manager Session Manager to manage EC2 instances. The security team wants to ensure that all SSH sessions are logged and that commands are recorded. What should be configured?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable session logging in the Session Manager preferences to send logs to Amazon S3 and CloudWatch Logs

Session Manager preferences allow logging session activity to Amazon S3 and CloudWatch Logs, which records all commands run during SSH sessions. Option B is incorrect because security groups control network access, not logging. Option C is incorrect because CloudTrail logs API calls to Systems Manager, not the commands executed within a session. Option D is incorrect because an IAM policy only controls permissions to start sessions, not the logging of session activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable session logging in the Session Manager preferences to send logs to Amazon S3 and CloudWatch Logs

    Why this is correct

    Enabling session logging in Session Manager preferences is the correct approach because it captures the actual interactive session stream—every keystroke, command, and output—and delivers it to centralized destinations such as Amazon S3 and CloudWatch Logs. This configuration is applied at the Systems Manager account level and can enforce audit trails for all sessions, including the ability to search and alert on command history. Without this, there is no native way to retroactively review the commands executed inside a session, making it essential for compliance and forensic requirements.

  • ✗

    Configure the security group to allow inbound SSH from the Session Manager service

    Why it's wrong here

    Session Manager does not rely on inbound SSH traffic; the AWS Systems Manager agent establishes an outbound connection to the Session Manager service over HTTPS (port 443). Therefore, configuring a security group to allow inbound SSH from the Session Manager service is technically invalid because SSH is not involved, and the session always initiates from inside the instance. Inbound security group rules would have no effect on session establishment, and port 22 remains unnecessary for this feature.

  • ✗

    Enable AWS CloudTrail to log Systems Manager API calls

    Why it's wrong here

    AWS CloudTrail records control-plane API calls such as StartSession, but it does not capture the data-plane activity—the keystrokes, command strings, or output that occur within an active Session Manager shell. While CloudTrail can show that a user started a session and when, it cannot reveal what the user actually executed inside that session. To audit command execution, you must enable Session Manager session logging, which CloudTrail cannot provide because it operates at the API level, not the interactive session level.

  • ✗

    Create an IAM policy that allows ssm:StartSession and attach it to the instance role

    Why it's wrong here

    A user-level IAM policy that allows ssm:StartSession is a permission that enables the user to initiate a Session Manager session, but it does not generate any logs of that session's activity. The policy itself is not a logging mechanism; it merely grants the API call to start the session. Furthermore, attaching this policy to the instance role would be incorrect because the instance role governs what the SSM agent can do—for logging, the agent needs write permissions to S3/CloudWatch, not the StartSession permission.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.