Courseiva

CCNA Security Logging and Monitoring Questions

75 of 250 questions · Page 3/4 · Security Logging and Monitoring · Answers revealed

151
MCQhard

A security engineer is investigating a potential compromise. The engineer notices that an EC2 instance is sending outbound traffic to an unknown IP address on port 443. The engineer needs to determine if the instance is communicating with a known command and control (C2) server. Which AWS service can the engineer use to check the reputation of the destination IP address?

A.AWS CloudTrail
B.VPC Flow Logs
C.AWS Trusted Advisor
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty is a managed threat detection service that continuously consumes VPC Flow Logs, DNS query logs, CloudTrail events, and S3 data events. It applies integrated threat intelligence from AWS and third-party sources, along with machine learning and anomaly detection, to generate findings when an EC2 instance communicates with a known malicious IP, Bitcoin miner, or Tor node. Its findings include the affected resource, the malicious IP, the protocol and port, and confidence indicators, enabling a security engineer to quickly investigate and respond.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including communication with known command and control (C2) servers. It uses threat intelligence feeds, such as those from AWS and third-party partners, to check the reputation of destination IP addresses and alert on suspicious outbound traffic. In this scenario, GuardDuty can directly identify if the EC2 instance is communicating with a known C2 server by analyzing VPC Flow Logs, DNS logs, and other data sources.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which only capture raw network metadata) with a security analysis service like GuardDuty, assuming that flow logs alone can determine IP reputation without additional threat intelligence integration.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls and management events, not network traffic or IP reputation checks; it cannot analyze outbound traffic to an unknown IP address. Option B is wrong because VPC Flow Logs capture metadata about IP traffic (source/destination IP, ports, protocol) but do not provide threat intelligence or reputation scoring for destination IPs; they only log the raw network flow data. Option C is wrong because AWS Trusted Advisor inspects your AWS environment for best practices in cost, performance, security, and fault tolerance, but it does not perform real-time threat detection or IP reputation checks against C2 servers.

152
MCQmedium

A security engineer notices that an S3 bucket containing sensitive logs is publicly accessible. Which service should be used to automatically remediate this by applying a bucket policy?

A.AWS Config
B.Amazon GuardDuty
C.AWS Trusted Advisor
D.AWS CloudTrail
AnswerA

AWS Config rules continuously evaluate the bucket against your desired state; a remediation action then invokes the bucket policy automatically. This satisfies the automatic remediation requirement, unlike services that only detect or report public access without applying policy changes.

Why this answer

AWS Config is the correct service because it can continuously monitor S3 bucket configurations and automatically remediate non-compliant resources using AWS Config Rules and AWS Systems Manager Automation documents. When a rule detects that an S3 bucket is publicly accessible, it can trigger an automatic remediation action, such as applying a bucket policy that denies all public access, without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's monitoring and remediation capabilities with GuardDuty's threat detection or Trusted Advisor's advisory checks, failing to recognize that only AWS Config supports automated, rule-based remediation actions.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events to identify malicious activity, but it cannot automatically remediate S3 bucket policies. Option C is wrong because AWS Trusted Advisor provides best-practice recommendations and security checks, including S3 bucket permissions, but it does not have native automated remediation capabilities; it only generates alerts. Option D is wrong because AWS CloudTrail is a logging service that records API calls for auditing and does not have the ability to apply or modify bucket policies automatically.

153
MCQeasy

A company wants to ensure that all API calls made to their AWS account are logged and immutable. They have enabled AWS CloudTrail and are delivering logs to an S3 bucket. The security team requires that logs cannot be deleted or modified by anyone, including the root user. What should they do?

A.Enable S3 Object Lock with Compliance retention mode on the bucket.
B.Enable MFA Delete on the S3 bucket.
C.Enable S3 Versioning on the bucket.
D.Add a bucket policy that denies s3:DeleteObject for all principals.
AnswerA

S3 Object Lock in Compliance mode enforces a write-once-read-many retention period that no principal, including the AWS account root user, can shorten or bypass, so CloudTrail log objects cannot be deleted or altered for the mandated duration.

Why this answer

S3 Object Lock in Compliance mode prevents any principal — including the root user and AWS itself — from deleting or overwriting an object version until its retention period expires. This is the only option that provides true WORM (write once, read many) immutability for CloudTrail logs. It satisfies the requirement that logs cannot be deleted or modified by anyone, including root.

Exam trap

SCS-C02 often tests the confusion between MFA Delete, versioning, and Object Lock — candidates must know that only Object Lock Compliance mode is truly immutable against root, while MFA Delete and bucket policies are not.

How to eliminate wrong answers

Option B is wrong because MFA Delete only requires multi-factor authentication for delete operations — a root user with MFA can still delete objects, so it does not meet the 'including root user' requirement. Option C is wrong because S3 Versioning preserves prior versions but does not prevent deletion of the current version or the object entirely. Option D is wrong because a bucket policy denying s3:DeleteObject can be modified or removed by an account administrator or root user, so it is not immutable.

154
MCQhard

Refer to the exhibit. This is a line from a VPC Flow Log. A security analyst notices that the log shows an ACCEPT record for a connection from 10.0.1.5 to 10.0.2.10 on port 443. However, the analyst expected the connection to be denied. Which field in the flow log record indicates that the connection was accepted?

A.The action field (ACCEPT)
B.The version field (2)
C.The protocol field (6)
D.The destination port field (443)
AnswerA

The action field in VPC Flow Logs records whether the traffic was accepted or rejected by security groups and network ACLs. A value of ACCEPT confirms that the flow was allowed, making this the only field that directly answers the question of whether the traffic was permitted or blocked. Without evaluating this field, no other field can determine the outcome.

Why this answer

The action field in a VPC Flow Log record explicitly indicates whether the firewall (security group or network ACL) allowed or denied the traffic. In this case, the value 'ACCEPT' confirms that the connection from 10.0.1.5 to 10.0.2.10 on port 443 was permitted, which is why the analyst sees an ACCEPT record despite expecting a denial.

Exam trap

The trap here is that candidates may confuse the protocol or port fields with the action field, mistakenly thinking that the presence of a specific protocol (TCP) or port (443) implies acceptance, when only the action field directly records the firewall's decision.

How to eliminate wrong answers

Option B is wrong because the version field (2) indicates the flow log record format version, not the connection's acceptance or denial. Option C is wrong because the protocol field (6) represents TCP (per IANA protocol numbers), but it only identifies the transport protocol, not whether the traffic was allowed. Option D is wrong because the destination port field (443) shows the target port for HTTPS traffic, but it does not indicate the firewall's decision to accept or reject the connection.

155
MCQeasy

A security engineer is reviewing CloudTrail logs and notices an event with the key 'eventType' set to 'AwsServiceEvent'. What does this indicate?

A.The event was initiated by an IAM user via the AWS Management Console.
B.The event was initiated by an AWS service.
C.The event was a sign-in event from the AWS Management Console.
D.The event type is an error in the log.
AnswerB

When the eventType is AwsServiceEvent, it means the event was generated by an AWS service performing an action on a resource, often on behalf of a customer or as part of automatic operations. The userIdentity is typically null or represents a service role, and the eventSource field identifies the service (e.g., ec2.amazonaws.com, s3.amazonaws.com). This is the correct explanation because AwsServiceEvent is the only eventType that directly maps to an action initiated by an AWS service, not by a user or a console sign-in.

Why this answer

In AWS CloudTrail, the 'eventType' field indicates the source of the event. When set to 'AwsServiceEvent', it means the event was generated by an AWS service on behalf of the customer, such as automatic backups, scaling actions, or health checks. This is distinct from events initiated by a user or federated identity, which would have 'eventType' set to 'AwsApiCall' or 'AwsConsoleSignIn'.

Exam trap

The trap here is that candidates confuse 'AwsServiceEvent' with API calls made by a user or assume it indicates an error, when in fact it specifically denotes actions initiated by AWS services themselves, not by human users or errors.

How to eliminate wrong answers

Option A is wrong because events initiated by an IAM user via the AWS Management Console have 'eventType' set to 'AwsConsoleSignIn' or 'AwsApiCall', not 'AwsServiceEvent'. Option C is wrong because sign-in events from the AWS Management Console are captured with 'eventType' set to 'AwsConsoleSignIn', not 'AwsServiceEvent'. Option D is wrong because 'AwsServiceEvent' is a valid event type indicating a service-initiated action, not an error; errors are indicated by the 'errorCode' and 'errorMessage' fields within the event record.

156
MCQhard

A security engineer notices that S3 server access logs are not being delivered to the specified destination bucket. The source bucket has a bucket policy that grants s3:PutObject permission to the Log Delivery group. The destination bucket is in the same AWS account but a different region. What is the most likely cause of the failure?

A.The destination bucket does not have versioning enabled.
B.The destination bucket is in a different AWS account.
C.The Log Delivery group does not have an IAM role assigned.
D.The destination bucket is in a different AWS region.
AnswerD

S3 server access logs must be delivered to a destination bucket in the same AWS Region as the source bucket. The S3 logging infrastructure delivers log objects using regional endpoints, and cross-region log delivery is not supported for server access logging. If you attempt to use a destination bucket in a different Region, the configuration may fail validation in the console or, in some cases, the logs will not be delivered. This Region mismatch is precisely why the security engineer observes no server access logs flowing to the destination bucket.

Why this answer

S3 server access logs are delivered by the Log Delivery group, which is a special AWS service principal. When the destination bucket is in a different AWS region, the Log Delivery group cannot write logs cross-region because S3 server access logging only supports delivering logs to a bucket in the same region as the source bucket. This is a hard limitation of the S3 service, not a permission or configuration issue.

Exam trap

The trap here is that candidates often assume cross-region S3 operations are always supported (e.g., cross-region replication), but S3 server access logging has a specific regional restriction that is easy to overlook.

How to eliminate wrong answers

Option A is wrong because versioning on the destination bucket is not required for S3 server access log delivery; versioning is optional and unrelated to the delivery failure. Option B is wrong because the destination bucket is explicitly stated to be in the same AWS account, so cross-account issues do not apply. Option C is wrong because the Log Delivery group is a built-in AWS service principal that does not require an IAM role; it uses the bucket policy's s3:PutObject permission to write logs directly.

157
MCQeasy

A company wants to centrally collect and analyze logs from multiple AWS accounts. Which AWS service should be used to aggregate logs from various sources for monitoring and alerting?

A.Amazon S3
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerD

CloudWatch Logs accepts log streams from many sources, including CloudTrail, VPC Flow Logs and application agents, and supports metric filters, alarms and cross-account subscriptions. That aggregation plus alerting capability satisfies the centralised collection requirement across accounts.

Why this answer

Amazon CloudWatch Logs is the correct service because it provides a centralized platform for collecting, monitoring, and analyzing log data from multiple AWS accounts and on-premises sources. It supports cross-account log aggregation via subscription filters and cross-account destinations, enabling real-time monitoring and alerting through CloudWatch Logs Insights and metric filters. This makes it the appropriate choice for the stated requirement of central log aggregation for monitoring and alerting.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which records API calls) with a log aggregation service, but CloudTrail is a log source, not a centralized aggregation and analysis platform like CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a log aggregation and analysis service; while logs can be stored in S3, it lacks native real-time monitoring, alerting, and query capabilities required for centralized analysis. Option B is wrong because AWS Config is a service for evaluating and auditing resource configurations against desired policies, not for collecting and analyzing logs from multiple sources. Option C is wrong because AWS CloudTrail is specifically designed to record API activity within an AWS account, but it does not aggregate logs from other services or accounts for centralized monitoring and alerting; it is a source of logs, not an aggregation platform.

158
MCQeasy

A security engineer needs to monitor for unauthorized changes to security group rules in an AWS account. The engineer wants to receive real-time notifications when a security group rule is added, modified, or removed. Which AWS service should the engineer use to capture these API calls?

A.Amazon GuardDuty
B.AWS CloudTrail
C.VPC Flow Logs
D.AWS Config
AnswerB

AWS CloudTrail records every API call, including AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress and ModifySecurityGroupRules, delivering events to CloudWatch Logs or EventBridge for real-time alerting. This satisfies the requirement to capture the specific management events that change security group rules, which CloudWatch metrics alone cannot identify.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including EC2 APIs such as AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, AuthorizeSecurityGroupEgress, RevokeSecurityGroupEgress, CreateSecurityGroup, and DeleteSecurityGroup. By enabling CloudTrail trail with management events and optionally data events for EC2, the security engineer can capture these API calls in near real-time and stream them to Amazon CloudWatch Logs or Amazon EventBridge to trigger notifications for unauthorized changes to security group rules.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to detect configuration changes (like security group rule drift) with the real-time API call capture requirement, but AWS Config relies on CloudTrail for change notifications and has inherent latency, whereas CloudTrail directly captures the API call at the moment it occurs.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not directly capture or provide real-time notifications for specific API calls like security group rule changes. Option C is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) at the network interface level, not API calls that modify security group rules. Option D is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules and can detect drift, but it operates on a periodic or event-driven basis (typically minutes delay) and does not capture API calls in real-time; it relies on CloudTrail for change notifications.

159
MCQeasy

A security engineer needs to ensure that all API calls made in an AWS account are captured and retained for auditing purposes. The engineer must be able to query the logs for specific user activity over the past 90 days. Which AWS service should the engineer use to meet these requirements?

A.AWS CloudTrail
B.Amazon VPC Flow Logs
C.Amazon CloudWatch Logs
D.AWS Config
AnswerA

AWS CloudTrail is the native API auditing service: it records user activity and API calls across the account as CloudTrail events, capturing the identity, source IP, timestamp, request parameters, and response elements. These events can be delivered to Amazon S3 for long-term retention and queried with Athena, or sent to CloudWatch Logs for alerting. To fully meet an "all API calls" requirement, both management and data events must be enabled across all regions.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity, source IP, request parameters, and response elements. By default, CloudTrail stores event history for the last 90 days, which can be queried via the Event History console or API, meeting the requirement to query logs for specific user activity over the past 90 days without additional configuration.

Exam trap

The trap here is that candidates may confuse CloudTrail's default 90-day Event History with the need to create a trail and store logs in S3, but the question explicitly states 'captured and retained for auditing purposes' and 'query the logs for specific user activity over the past 90 days,' which is exactly what the built-in Event History provides without additional configuration.

How to eliminate wrong answers

Option B is wrong because Amazon VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) at the network interface level, not API calls or user activity, so they cannot be used to audit API-level actions. Option C is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files from various sources (e.g., applications, AWS services), but it does not natively capture all AWS API calls; CloudTrail logs must be explicitly sent to CloudWatch Logs for that purpose, and the requirement is for a service that directly captures and retains API calls, not a downstream log destination. Option D is wrong because AWS Config evaluates and records resource configuration changes and compliance, not API calls; it tracks the state of resources over time but does not capture the API requests that caused those changes.

160
MCQmedium

A security engineer is investigating a potential security incident involving an EC2 instance that was used to launch an outbound DDoS attack. The engineer needs to determine the source of the attack and the commands executed on the instance. Which logs should be analyzed?

A.VPC Flow Logs and Network ACL logs
B.EC2 instance OS logs (e.g., /var/log/secure) and CloudTrail logs for API calls that launched the instance
C.S3 server access logs and CloudWatch Logs
D.AWS CloudTrail and AWS Config history
AnswerB

This is correct because the two data sources complement each other: EC2 OS logs (e.g., /var/log/secure on Linux, or Windows Event Logs) record interactive logins, sudo usage, and command execution on the guest OS, while CloudTrail logs the RunInstances API call, identifying the IAM principal, source IP, and timestamp of instance launch. Together they give you both the actor who created the instance and the subsequent commands run within it, enabling a full forensic timeline of the security incident.

Why this answer

The EC2 instance's OS logs (e.g., auditd logs, bash history) contain the exact commands executed and user authentication events, which are essential for identifying the source and actions of the attacker. CloudTrail logs for API calls that launched the instance provide the identity of the principal (IAM user/role), source IP, and the time the instance was created, linking the instance to the initiating entity. Together, these logs allow the engineer to trace both the operational commands on the instance and the administrative actions that created it.

Exam trap

The trap here is that candidates assume VPC Flow Logs or CloudTrail alone are sufficient, but they fail to recognize that OS-level logs are required to see actual commands executed on the instance, which CloudTrail never captures.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log OS-level commands or API calls; Network ACL logs do not exist as a separate AWS service (Network ACLs themselves generate no logs). Option C is wrong because S3 server access logs record requests made to an S3 bucket, not EC2 instance activity or API calls; CloudWatch Logs can store logs but are a destination, not a source of the specific logs needed (OS logs and CloudTrail). Option D is wrong because AWS CloudTrail logs API calls (including instance launches) but does not capture OS-level commands executed inside the instance; AWS Config history records resource configuration changes over time, not command execution or API call details.

161
MCQeasy

A company uses Amazon GuardDuty to monitor for malicious activity in their AWS account. The security team receives a GuardDuty finding that indicates an EC2 instance is communicating with a known cryptocurrency mining pool. The team needs to investigate the finding and determine which security group rules allowed the outbound traffic. The EC2 instance is in a VPC with a single security group attached. Which AWS service should the security team use to review the outbound traffic details?

A.AWS CloudTrail
B.VPC Flow Logs
C.AWS Config
D.Amazon GuardDuty
AnswerB

VPC Flow Logs capture metadata about every IP traffic flow accepted or rejected by a VPC network interface, including source/destination IP, source/destination port, protocol, packets, and bytes transferred. By enabling these logs for the subnets or ENIs and publishing to CloudWatch Logs or S3, you can query for outbound traffic to suspicious IP addresses, unusual ports, or high data transfer volumes. This raw flow-level data is exactly what is needed to supplement a GuardDuty finding and trace which EC2 instance initiated the malicious connection.

Why this answer

VPC Flow Logs capture IP traffic metadata — including source/destination IP, ports, protocol, and ACCEPT/REJECT action — for network interfaces in a VPC. Reviewing flow logs for the EC2 instance's ENI reveals which outbound traffic was allowed and, combined with the security group rules, identifies the rule that permitted the connection to the mining pool.

Exam trap

SCS-C02 often tests the distinction between CloudTrail (API activity) and VPC Flow Logs (network traffic) — candidates pick CloudTrail because it is the default 'audit' answer, but it cannot show packet-level outbound connections.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity (who called which AWS API), not network packet flows — it cannot show outbound traffic to an external IP. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not network traffic. Option D is wrong because GuardDuty is the detection service that generated the finding; it does not provide the granular network flow details needed to identify the specific security group rule.

162
MCQeasy

A company wants to detect and alert on suspicious IAM user behavior, such as accessing services that are not typically used. Which AWS service provides prebuilt anomaly detection for IAM users?

A.AWS Trusted Advisor
B.AWS CloudTrail
C.Amazon GuardDuty
D.Amazon Inspector
AnswerC

Amazon GuardDuty is the correct answer because it is a managed threat detection service that combines machine learning, anomaly detection, and threat intelligence to monitor suspicious activity across your AWS environment. Specifically, it consumes CloudTrail management events to profile each IAM user's normal behavior—typical IP addresses, geographic locations, login times, and API call frequency—and then flags deviations as findings like 'Unusual IAM User Login' or 'Impossible Travel' activity. When a finding is generated, GuardDuty automatically emits an event to Amazon EventBridge, which you can pipe to SNS, Lambda, or Security Hub to trigger near-real-time alerts and automated responses. This provides exactly the detect-and-alert capability the company needs without requiring them to build custom analytics.

Why this answer

Amazon GuardDuty is the correct answer because it is a threat detection service that uses machine learning and anomaly detection to identify suspicious IAM user behavior, such as accessing services not typically used. It analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs to establish baselines and generate findings for unusual API calls or access patterns. This prebuilt capability directly addresses the requirement for detecting atypical IAM activity without manual configuration.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, assuming that because CloudTrail records API calls, it can also detect anomalies, but it lacks the machine learning engine required for prebuilt anomaly detection.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor is a service that provides best-practice recommendations for cost optimization, performance, security, and fault tolerance, but it does not perform real-time anomaly detection or monitor IAM user behavior. Option B is wrong because AWS CloudTrail is a logging service that records API activity for auditing and compliance, but it lacks built-in anomaly detection; it requires integration with other services like GuardDuty or third-party tools to identify suspicious behavior. Option D is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not IAM user behavior or API call anomalies.

163
MCQhard

A company has a multi-account AWS Organization with 50 accounts. The security team wants to monitor for unauthorized IAM role assumption across all accounts. They have enabled AWS CloudTrail in all accounts and are delivering logs to a central S3 bucket in the security account. They also have Amazon GuardDuty enabled in all accounts. The security team wants a centralized dashboard to visualize cross-account role assumption events. They have limited budget and want to use existing services. What should they do?

A.Use Amazon Athena to query CloudTrail logs in S3 and visualize with Amazon QuickSight.
B.Use AWS Config aggregator to view cross-account IAM role creation.
C.Use Amazon CloudWatch Logs Insights to query logs from the central S3 bucket.
D.Use Amazon Elasticsearch Service to index CloudTrail logs from S3 and visualize with Kibana.
AnswerA

Amazon Athena can query CloudTrail logs directly in Amazon S3 using standard SQL, without requiring any ingestion or ETL step. When all accounts in the organization deliver CloudTrail logs to a centralized S3 bucket, Athena can run cross-account queries over the entire set of log files. Amazon QuickSight connects to Athena to build interactive dashboards from those results, and the serverless pay-per-query pricing makes this a cost-effective analysis solution.

Why this answer

Amazon Athena can query CloudTrail logs stored in S3 using standard SQL, and Amazon QuickSight can create visualizations from Athena query results. This leverages existing services without additional cost for Amazon QuickSight (pay-per-session pricing) and minimal cost for Athena (based on data scanned). Option B is incorrect because AWS Config aggregator provides a view of resource configuration across accounts, not API call analysis.

Option C is incorrect because CloudWatch Logs Insights cannot directly query logs stored in S3; it requires logs to be in CloudWatch Logs. Option D is incorrect because Amazon Elasticsearch Service incurs additional costs and complexity, which the company wants to avoid.

164
MCQmedium

A company uses AWS CloudTrail and wants to ensure that any modification to the trail itself is detected immediately. What should be done?

A.Configure Amazon GuardDuty to monitor for trail modifications
B.Enable CloudTrail Insights to detect unusual activity
C.Create a CloudWatch Events rule that matches the StopLogging or UpdateTrail API calls and sends an alert
D.Enable S3 event notifications on the trail's S3 bucket
AnswerC

The correct solution is a CloudWatch Events rule (now Amazon EventBridge) that matches the management events CloudTrail emits for the StopLogging, UpdateTrail, or DeleteTrail API calls, using an event pattern with source 'aws.cloudtrail' and eventName in the list. When such a call occurs, the rule triggers an SNS topic or Lambda function to notify security teams in near real-time. This works because CloudTrail delivers every management event to CloudWatch Events as a default integration, including the very call that disables logging.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can be configured with a rule that matches specific API calls like StopLogging or UpdateTrail via CloudTrail. When such an API call is made, the rule triggers an action such as sending an SNS notification or invoking a Lambda function, enabling immediate detection of trail modifications. This approach directly monitors the control plane operations that alter the trail's configuration.

Exam trap

The trap here is that candidates often confuse monitoring the trail's log files (S3 events) with monitoring the trail's configuration (CloudTrail API calls), leading them to choose Option D instead of the correct CloudWatch Events approach.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide real-time alerting on specific API calls like UpdateTrail; it focuses on threat intelligence rather than configuration change monitoring. Option B is wrong because CloudTrail Insights identifies unusual API activity and write management events, but it is designed for anomaly detection over time, not immediate alerting on specific trail modifications. Option D is wrong because S3 event notifications on the trail's S3 bucket would only detect changes to the log files stored in the bucket, not modifications to the trail configuration itself (e.g., disabling logging or changing the trail's settings).

165
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centralize VPC Flow Logs from all accounts into a single S3 bucket in the security account. The flow logs are created in the member accounts and sent to the centralized bucket. However, the security team notices that flow logs from some member accounts are not being delivered. What is the most likely cause?

A.The member accounts need an IAM role with permissions to write to the centralized bucket.
B.CloudTrail must be enabled in each member account before VPC Flow Logs can be sent to a centralized bucket.
C.The S3 bucket policy does not grant write permissions to the member accounts.
D.VPC Flow Logs cannot be aggregated across multiple AWS accounts.
AnswerC

The most direct reason the flow logs fail is that the S3 bucket policy is missing an explicit Allow that lets the delivering VPC Flow Logs service write objects into the bucket. For cross-account delivery, the policy needs a statement with Principal as vpc-flow-logs.amazonaws.com (or the aggregated log delivery principal) and Action s3:PutObject on the destination prefix such as arn:aws:s3:::central-bucket/AWSLogs/<member-account-id>/*. Without this resource-based grant, S3 denies the write even if the member account has full IAM permissions.

Why this answer

VPC Flow Logs are delivered to an S3 bucket using the flow log publisher's IAM role, but the destination bucket must also have a bucket policy that explicitly grants the necessary permissions (e.g., s3:PutObject) to the member accounts' log delivery service. Without this policy, the S3 bucket will reject write requests from member accounts, causing flow logs to fail silently.

Exam trap

The trap here is that candidates often assume an IAM role in the member account is required (Option A), but AWS actually uses resource-based policies (S3 bucket policy) for cross-account VPC Flow Log delivery, not IAM roles.

How to eliminate wrong answers

Option A is wrong because member accounts do not need an IAM role with write permissions to the centralized bucket; instead, the flow log delivery uses the VPC Flow Logs service principal (delivery.logs.amazonaws.com) and relies on the S3 bucket policy to grant cross-account access. Option B is wrong because CloudTrail is not a prerequisite for VPC Flow Logs; flow logs operate independently and can be sent to S3 without CloudTrail being enabled. Option D is wrong because VPC Flow Logs can indeed be aggregated across multiple AWS accounts by using a centralized S3 bucket with appropriate bucket policies and resource-based policies.

166
MCQmedium

A security team needs to be alerted when an IAM user generates a console login failure. Which combination of AWS services should be used to meet this requirement?

A.CloudTrail and Amazon S3
B.CloudTrail, Amazon CloudWatch Logs, and CloudWatch Alarms
C.AWS Config and Amazon SNS
D.Amazon GuardDuty and AWS Lambda
AnswerB

The correct architecture is CloudTrail for recording console login events, CloudWatch Logs as the destination for those CloudTrail events, and a CloudWatch Logs metric filter that looks for IAM console sign-in failures (e.g., MFA denied or incorrect password). The metric filter increments a CloudWatch metric, and a CloudWatch Alarm on that metric triggers an Amazon SNS notification, delivering a near-real-time alert when a defined threshold (like 1 failure) is breached.

Why this answer

CloudTrail captures IAM console login failures as CloudTrail events, which can be streamed to CloudWatch Logs. A CloudWatch Alarm can then be configured to trigger on a metric filter that matches the specific 'ConsoleLogin' event with a 'Failure' status, enabling real-time alerting via Amazon SNS.

Exam trap

The trap here is that candidates may think CloudTrail alone is sufficient for alerting, but CloudTrail only logs events; it requires integration with CloudWatch Logs and Alarms to generate notifications, and options like GuardDuty or Config are often mistakenly chosen because they sound security-related but do not directly address the specific login failure alerting requirement.

How to eliminate wrong answers

Option A is wrong because Amazon S3 alone cannot generate alerts; it is a storage service and lacks native alerting capabilities. Option C is wrong because AWS Config is designed for resource compliance and configuration tracking, not for monitoring real-time API events like login failures. Option D is wrong because Amazon GuardDuty focuses on threat detection using DNS, VPC flow logs, and CloudTrail management events, but it does not provide direct alerting for IAM console login failures without additional custom Lambda logic, and it is not the standard recommended combination for this specific requirement.

167
MCQmedium

A security team needs to monitor for failed login attempts to an EC2 instance running Linux. The team wants to send a real-time alert when more than 10 failed SSH attempts occur within 5 minutes. Which solution is the most efficient?

A.Install the CloudWatch Logs agent on the EC2 instance to stream /var/log/secure to CloudWatch Logs. Create a metric filter for 'Failed password' and set a CloudWatch alarm.
B.Enable VPC Flow Logs and filter for SSH traffic to detect failed attempts.
C.Configure the EC2 instance to write failed attempts to a file in S3 and use S3 events to trigger a Lambda function for alerting.
D.Enable Amazon GuardDuty and create a custom threat list for failed SSH attempts.
AnswerA

Streaming /var/log/secure to CloudWatch Logs via the CloudWatch Logs agent enables real-time ingestion of OS-level authentication events. A metric filter with pattern 'Failed password' converts each matching log line into a metric value, and a CloudWatch alarm evaluates the metric over a chosen period to alert on anomalous login failures. This is the standard pattern for Linux SSH login monitoring because the agent is natively supported and the filter operates on the actual log content.

Why this answer

The CloudWatch Logs agent can stream /var/log/secure (which logs SSH authentication events) to CloudWatch Logs. A metric filter on the 'Failed password' pattern counts failed SSH attempts, and a CloudWatch alarm with a threshold of 10 within a 5-minute period triggers a real-time alert. This is the most efficient solution as it directly monitors the specific log source for SSH failures without additional overhead.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (network-level) with application-level logs (e.g., /var/log/secure), assuming flow logs can detect failed SSH attempts when they only show connection attempts, not authentication success or failure.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture network metadata (e.g., source/destination IP, port, protocol) but do not log application-level authentication outcomes like 'Failed password'; they cannot distinguish between successful and failed SSH logins. Option C is wrong because writing failed attempts to a file in S3 introduces latency and complexity (e.g., S3 events are not real-time, and Lambda invocation adds delay), making it less efficient than direct CloudWatch monitoring. Option D is wrong because Amazon GuardDuty uses machine learning and threat intelligence to detect suspicious behavior, but it does not natively support custom threat lists for failed SSH attempts; custom threat lists are for known malicious IPs, not for counting failed logins.

168
MCQhard

A security engineer has attached the above IAM policy to a role used by an application to write logs to an S3 bucket. However, the application is unable to write logs. What is the MOST likely reason?

A.The Effect is set to Allow, which is too permissive.
B.The application does not set the x-amz-acl header to bucket-owner-full-control on PutObject requests.
C.The policy does not allow server-side encryption.
D.The resource ARN is incorrect; it should be arn:aws:s3:::my-log-bucket/*.
AnswerB

The application is failing because the IAM policy includes a Condition key s3:x-amz-acl with StringEquals bucket-owner-full-control. For S3 to allow a PutObject call, the request must carry an x-amz-acl header matching that exact value; if the header is absent or different, S3 treats the condition as unmet and denies the request. IAM permissions alone don't bypass S3's request-level parameter checks. The application must explicitly set the header in each PutObject request.

Why this answer

When an IAM policy grants PutObject access to an S3 bucket, the application must also include the `x-amz-acl: bucket-owner-full-control` header in its PutObject requests to ensure the bucket owner retains full control over the uploaded objects. Without this header, the object is owned by the writer (the role), and the bucket owner cannot manage it, causing the write to fail due to access control mismatches, especially in cross-account scenarios or when the bucket policy enforces specific ACLs.

Exam trap

The trap here is that candidates often focus on IAM policy syntax errors (like ARN format or missing actions) and overlook the requirement for specific request headers (like ACLs) that are enforced by the bucket policy or S3 default settings, not by the IAM policy itself.

How to eliminate wrong answers

Option A is wrong because setting the Effect to Allow is standard for granting permissions; the issue is not about permissiveness but about missing required headers. Option C is wrong because the policy does not need to explicitly allow server-side encryption; S3 supports default encryption at the bucket level, and the policy shown does not deny encryption-related actions. Option D is wrong because the resource ARN `arn:aws:s3:::my-log-bucket/*` is correct for granting access to objects within the bucket; the error is not due to the ARN format but due to missing ACL headers.

169
MCQmedium

A company has a requirement to retain CloudTrail logs for 7 years for compliance. The logs are stored in an S3 bucket. The security team needs to ensure that logs are not deleted before the retention period ends, even by users with full S3 permissions. Which action should be taken?

A.Enable MFA Delete on the bucket and require MFA for all delete operations.
B.Enable S3 Object Lock in Compliance mode on the bucket with a retention period of 7 years.
C.Enable S3 Versioning and set a lifecycle policy to expire noncurrent versions after 7 years.
D.Create a bucket policy that denies s3:DeleteObject for all users.
AnswerB

Compliance mode prevents any user, including the root account, from overwriting or deleting locked object versions until the retention period expires. This directly satisfies the requirement that logs survive seven years despite users holding full S3 permissions.

Why this answer

S3 Object Lock in Compliance mode prevents any user, including the root user, from overwriting or deleting objects until the retention period expires. This meets the requirement to retain CloudTrail logs for 7 years, even against users with full S3 permissions, because Compliance mode cannot be bypassed or removed by any user.

Exam trap

The trap here is that candidates often choose MFA Delete (Option A) because it adds security, but they overlook that MFA Delete does not prevent deletion by authorized users who have MFA devices, whereas Object Lock in Compliance mode provides true immutability against all users.

How to eliminate wrong answers

Option A is wrong because MFA Delete only adds an extra authentication factor for delete operations but does not prevent deletion by users who have MFA credentials, so it cannot guarantee retention against all users. Option C is wrong because versioning with a lifecycle policy only expires noncurrent versions after 7 years, but current versions can still be deleted immediately by users with s3:DeleteObject permission, and lifecycle policies do not prevent direct deletion. Option D is wrong because a bucket policy that denies s3:DeleteObject for all users can be overridden by an explicit allow in an IAM policy or by the root user, and it does not protect against accidental or malicious deletion by users with full permissions who can modify the policy itself.

170
MCQeasy

A company wants to centralize security logs from multiple AWS accounts into a single S3 bucket. The logging accounts (e.g., security, production) each have their own CloudTrail trails. Which configuration is required to allow cross-account log delivery?

A.Create an IAM role in the destination account with write permissions and allow CloudTrail in source accounts to assume that role.
B.Use a customer-managed KMS key in the destination account and share it with the source accounts.
C.Create an S3 bucket policy in the destination account that allows the CloudTrail service principal to write objects.
D.Configure S3 bucket ACLs to grant write access to the source account IDs.
AnswerC

A bucket policy in the destination account is the only mechanism CloudTrail uses to authorize cross-account log delivery, so the policy must allow the CloudTrail service principal (cloudtrail.amazonaws.com) to perform s3:PutObject and s3:GetBucketAcl on the bucket. For additional security, restrict the policy with aws:SourceAccount or aws:SourceArn to a specific source account, and when SSE-KMS is enabled, also include kms:GenerateDataKey and kms:Decrypt in the policy.

Why this answer

CloudTrail cross-account log delivery requires the destination S3 bucket to have a bucket policy that explicitly grants the CloudTrail service principal (`cloudtrail.amazonaws.com`) permission to write objects (e.g., `s3:PutObject`). This allows CloudTrail in any source account to deliver logs directly to the bucket without needing IAM roles or shared credentials, as the service principal authenticates on behalf of the source account.

Exam trap

The trap here is that candidates often assume cross-account access requires an IAM role (Option A) or shared encryption keys (Option B), but AWS services like CloudTrail use service principals and bucket policies for cross-account log delivery, not IAM roles or ACLs.

How to eliminate wrong answers

Option A is wrong because CloudTrail does not assume an IAM role in the destination account; it uses the source account's CloudTrail service principal to write logs, and the bucket policy must grant access to that principal, not an IAM role. Option B is wrong because while a customer-managed KMS key can be used for encryption, it is not required for cross-account log delivery; the core requirement is the bucket policy, and sharing a KMS key alone does not enable CloudTrail to write logs. Option D is wrong because S3 bucket ACLs are not supported for granting cross-account write access to the CloudTrail service principal; bucket ACLs are legacy and cannot grant permissions to AWS service principals, only to AWS accounts or canonical user IDs.

171
MCQhard

A company uses Amazon S3 to store sensitive data. The security team needs to be alerted when an S3 bucket policy is changed to allow public access. Which combination of services should be used to meet this requirement?

A.AWS CloudTrail and Amazon Simple Notification Service (SNS)
B.S3 server access logs and Amazon Athena
C.AWS Trusted Advisor and Amazon Simple Notification Service (SNS)
D.AWS Config with AWS Lambda and Amazon Simple Notification Service (SNS)
AnswerD

AWS Config can continuously record configuration changes to an S3 bucket policy and evaluate those changes against a managed or custom rule. When a PutBucketPolicy event occurs, AWS Config marks the configuration item as changed and invokes a custom Lambda function, which can in turn publish a message to an SNS topic to notify security teams. This design provides real-time detection and alerting because the Lambda function is triggered by the configuration change, not by a periodic scan.

Why this answer

AWS Config can monitor S3 bucket policies for changes that grant public access using a managed rule like 's3-bucket-public-read-prohibited' or a custom Lambda function. When a noncompliant change is detected, AWS Config can invoke an AWS Lambda function to evaluate the policy and publish a notification to Amazon SNS, alerting the security team. This combination provides real-time, policy-driven monitoring and alerting for public access changes.

Exam trap

The trap here is that candidates often choose AWS CloudTrail (Option A) because it logs API calls like PutBucketPolicy, but they overlook that CloudTrail alone cannot evaluate the policy content for public access or trigger alerts without additional services like EventBridge and Lambda, whereas AWS Config is purpose-built for continuous compliance monitoring and alerting.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail logs API calls but does not evaluate bucket policies for public access or trigger alerts directly; it would require additional services like Amazon EventBridge and Lambda to filter and act on specific events, making it less direct than AWS Config. Option B is wrong because S3 server access logs record object-level requests (e.g., GET, PUT) and are not designed to monitor or alert on bucket policy changes; Athena is used for querying logs, not for real-time alerting. Option C is wrong because AWS Trusted Advisor checks for publicly accessible S3 buckets but only provides periodic checks (not real-time) and does not trigger alerts via SNS automatically for policy changes; it requires manual review or custom automation.

172
MCQhard

A company uses Amazon S3 to store sensitive data. The security team wants to detect when objects are made publicly accessible. Which combination of services provides the MOST comprehensive detection with minimal false positives?

A.Enable S3 Block Public Access at the account level and use AWS Config rules to detect public ACLs and bucket policies.
B.Use Amazon Macie to scan S3 buckets for publicly accessible objects.
C.Enable CloudTrail data events for S3 and create a CloudWatch Events rule for PutBucketAcl calls.
D.Enable Amazon GuardDuty and review the S3 findings for public access.
AnswerA

S3 Block Public Access at the account level is a preventive control that overrides any bucket policy or ACL that would grant public access, while AWS Config managed rules such as s3-bucket-public-read-prohibited and s3-bucket-policy-not-more-permissive provide continuous detective monitoring. Together they address both the existence of public ACLs and public bucket policies, which are the two primary vectors for accidental public exposure. This combination satisfies the security requirement without relying on noisy event monitoring or unrelated threat-detection tools.

Why this answer

S3 Block Public Access at the account level provides a preventive control that denies all public access, while AWS Config rules (e.g., s3-bucket-public-read-prohibited, s3-bucket-policy-not-more-permissive) continuously evaluate and detect any public ACLs or bucket policies that would allow public access. This combination ensures comprehensive detection with minimal false positives because Config rules are deterministic and based on explicit policy evaluation, not on heuristic or behavioral analysis.

Exam trap

The trap here is that candidates often choose CloudTrail-based detection (Option C) thinking it captures all public access changes, but they overlook that bucket policies can grant public access without triggering a PutBucketAcl call, and that CloudTrail data events may not be enabled or may miss existing misconfigurations.

How to eliminate wrong answers

Option B is wrong because Amazon Macie is designed to discover sensitive data (e.g., PII, credentials) using machine learning and pattern matching, not to detect public access configurations; it may generate false positives for public objects that do not contain sensitive data. Option C is wrong because CloudTrail data events for S3 and a CloudWatch Events rule for PutBucketAcl calls only capture API calls that change ACLs, but they miss public access granted via bucket policies (PutBucketPolicy) and do not detect existing public objects or changes made outside of CloudTrail logging. Option D is wrong because Amazon GuardDuty uses threat intelligence and anomaly detection to identify suspicious activity (e.g., unusual data access patterns), not to directly detect public access configurations; its S3 findings are behavioral and may produce false positives or miss misconfigurations that are not actively exploited.

173
MCQhard

A company stores sensitive data in Amazon S3 and wants to detect and alert on any public read access to objects. Which combination of services provides the most comprehensive solution?

A.Enable VPC Flow Logs and analyze for S3 traffic
B.Use AWS Config rules to check for public bucket policies and alert via SNS
C.Enable S3 server access logging and use Amazon Athena to query logs, with CloudWatch Events to alert on specific patterns
D.Enable S3 event notifications for all object-level events and send to Amazon SNS
AnswerC

S3 server access logging produces detailed log records containing the requester, bucket name, object key, action string (e.g., REST.GET.OBJECT), and response status for each API call. Querying these logs with Amazon Athena lets you filter for the 'Anonymous' requester and identify specific objects being read publicly. A scheduled Athena query orchestrated via CloudWatch Events (now Amazon EventBridge) can publish findings to SNS or Lambda, enabling alerting on suspicious read patterns.

Why this answer

S3 server access logs capture detailed records of all requests made to a bucket, including the requester, bucket name, request time, action, and response status. By using Amazon Athena to query these logs and CloudWatch Events to trigger alerts on patterns indicating public read access (e.g., a specific HTTP method like GET from an anonymous principal), you can detect and alert on unauthorized public reads comprehensively. This combination provides granular, queryable logging with event-driven alerting, covering both current and historical access patterns.

Exam trap

The trap here is that candidates often confuse S3 event notifications (which only cover write/delete events) with server access logs (which cover all operations including reads), leading them to choose Option D, which cannot detect read access at all.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) but do not log S3 object-level operations like GetObject; they cannot identify public read access to S3 objects. Option B is wrong because AWS Config rules can check for public bucket policies (e.g., a policy allowing Principal: '*') but cannot detect actual public read access events—they only evaluate static configuration, not runtime access patterns. Option D is wrong because S3 event notifications for object-level events (e.g., s3:ObjectCreated) do not include read events like GetObject; they only trigger on write or delete operations, so they cannot detect public read access.

174
Multi-Selecthard

Which THREE AWS services can be used to detect and alert on suspicious network traffic patterns? (Choose three.)

Select 3 answers
A.AWS Network Firewall
B.Amazon VPC Flow Logs
C.AWS Systems Manager
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersA, B, E

AWS Network Firewall is a managed stateful firewall that performs packet-level inspection on all traffic traversing a VPC using a Suricata-compatible engine. It supports both intrusion detection (IDS) and intrusion prevention (IPS) modes, with managed or custom rule groups that match against packet signatures, domain lists, and port/protocol patterns. When a stateful rule fires, the service can emit alert logs to Amazon S3, CloudWatch Logs, or Kinesis Data Firehose, making it an AWS-native service that directly detects and alerts on suspicious network traffic.

Why this answer

AWS Network Firewall is correct because it is a managed firewall service that can inspect network traffic at the VPC level using stateful and stateless rules. It can detect suspicious patterns such as port scans, malicious IP addresses, or protocol anomalies and generate alerts via Amazon CloudWatch metrics and logs, enabling real-time notification of suspicious network traffic.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (API logging) with network traffic monitoring, or assume AWS Systems Manager has security detection capabilities, when in fact neither service inspects network packet flows or traffic patterns.

175
Multi-Selectmedium

A security engineer is implementing centralized logging across multiple AWS accounts. Which TWO actions should the engineer take to ensure logs are securely stored and immutable? (Choose TWO.)

Select 2 answers
A.Enable S3 Transfer Acceleration on the bucket
B.Use AWS KMS with a customer managed key for encryption
C.Enable S3 Object Lock on the destination bucket
D.Enable CloudTrail log file validation
E.Enable MFA Delete on the bucket
AnswersB, C

AWS KMS customer managed keys encrypt logs at rest with granular key policies and audit trails via CloudTrail. This satisfies the secure storage constraint by ensuring only authorised principals can decrypt, and key revocation instantly blocks access.

Why this answer

Using AWS KMS with a customer managed key (CMK) for encryption ensures that the security engineer has full control over the encryption keys, including key rotation, access policies, and the ability to disable or revoke the key. This prevents unauthorized decryption of logs, even by AWS, and is a critical component of securing log data at rest. Option C is correct because enabling S3 Object Lock on the destination bucket enforces a write-once-read-many (WORM) model, preventing logs from being deleted or overwritten for a specified retention period, which ensures immutability and compliance with regulatory requirements.

Exam trap

The trap here is that candidates often confuse CloudTrail log file validation (which only detects tampering) with immutability (which prevents tampering), or they mistakenly think MFA Delete provides the same WORM protection as S3 Object Lock.

176
Multi-Selectmedium

A security engineer is configuring logging for an application running on Amazon EC2 instances. The engineer needs to capture both operating system-level logs and application logs. Which TWO services can be used together to achieve this? (Choose two.)

Select 2 answers
A.AWS CloudTrail
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.Amazon CloudWatch agent
E.Amazon Inspector
AnswersC, D

Amazon CloudWatch Logs is the managed destination where log data is stored, monitored, and queried; it centralizes log events from EC2, Lambda, and on-premises sources into log groups and log streams. When the CloudWatch agent publishes log records to this service, you can search them with Logs Insights, alarm on error patterns, and export them to S3 for long-term retention.

Why this answer

Amazon CloudWatch Logs is the correct service because it provides a centralized location to store, monitor, and access log files from your EC2 instances. The Amazon CloudWatch agent is the correct companion service because it is specifically designed to collect both operating system-level logs (e.g., syslog, Windows Event Log) and application logs from EC2 instances and send them to CloudWatch Logs. Together, they fulfill the requirement of capturing both OS and application logs.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs AWS API calls) with the CloudWatch agent (which collects OS and application logs), leading them to select CloudTrail instead of the CloudWatch agent for internal instance logging.

177
MCQhard

A security team notices that an S3 bucket containing sensitive data has been repeatedly accessed from an IP address outside the company's network. They need to set up a real-time alert when such access occurs. Which combination of services should they use?

A.VPC Flow Logs and Amazon QuickSight
B.AWS Config and Amazon SNS
C.CloudWatch Logs Insights and Amazon SES
D.Amazon GuardDuty and Amazon EventBridge
AnswerD

Amazon GuardDuty is a threat-detection service that continuously analyzes S3 data-plane events from CloudTrail, using anomaly detection and threat intelligence to identify patterns like unusual object access or credential abuse. When a finding is generated, GuardDuty emits it as an event to the default event bus, where Amazon EventBridge rules can filter on severity or finding type and trigger Lambda, SNS, or other targets for immediate alerting. This pair combines detection and event-driven response, making it the appropriate real-time security monitoring solution for the sensitive S3 bucket.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity, including unusual API calls and unauthorized access patterns from external IPs. When GuardDuty detects such access to an S3 bucket, it can generate findings that are sent to Amazon EventBridge, which then triggers a real-time alert (e.g., via SNS or Lambda). This combination provides immediate, automated notification of the suspicious access without requiring custom log parsing.

Exam trap

The trap here is that candidates often confuse AWS Config (which monitors configuration drift) with GuardDuty (which monitors actual access events), or they assume CloudWatch Logs Insights can provide real-time alerts when it is actually a query-based analysis tool with no native push alerting.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata at the VPC level, not S3 data plane API calls, and Amazon QuickSight is a business intelligence tool for visualization, not real-time alerting. Option B is wrong because AWS Config tracks resource configuration changes and compliance, not real-time data access events; Amazon SNS can send notifications but requires a proper event source, and Config rules are not designed for per-request S3 access monitoring. Option C is wrong because CloudWatch Logs Insights is a query tool for analyzing log data, not a real-time alerting mechanism, and Amazon SES is an email sending service that cannot directly ingest or process S3 access logs for alerting.

178
MCQmedium

A security engineer manages a VPC with a fleet of Amazon EC2 instances running behind an Application Load Balancer. The engineer needs to capture, in near real time, metadata about all IP traffic entering and leaving the network interfaces in the VPC, including source and destination IP, ports, and protocol, and then store the records in Amazon S3 for later analysis. Which solution meets these requirements with the LEAST operational overhead?

A.Install the CloudWatch agent on each EC2 instance and configure it to collect network traffic metrics and send them to CloudWatch Logs.
B.Enable VPC Flow Logs at the VPC level with a destination of Amazon S3 and the default format.
C.Deploy a third-party network monitoring appliance on an EC2 instance and mirror all VPC traffic to it using AWS PrivateLink.
D.Enable AWS CloudTrail data events on the network interfaces and deliver the logs to Amazon S3.
AnswerB

VPC Flow Logs capture IP traffic metadata for network interfaces in a VPC, including source/destination IP, ports, and protocol. Publishing directly to Amazon S3 requires no agent installation or additional pipeline, making it the lowest-overhead solution. The default format already includes the required fields, and flow logs can be created at the VPC, subnet, or ENI level.

Why this answer

VPC Flow Logs are the native AWS feature for capturing IP traffic metadata for network interfaces in a VPC. Publishing directly to Amazon S3 avoids the need for agents or custom pipelines and provides the required fields in the default format. The other options either capture the wrong type of data or introduce unnecessary complexity.

Exam trap

The trap here is assuming that CloudTrail or the CloudWatch agent can capture network traffic metadata, when only VPC Flow Logs provide that specific IP-level detail.

179
MCQhard

A security engineer runs the CLI command above to investigate a console login event. The output shows: {"type":"Root","principalId":"123456789012","arn":"arn:aws:iam::123456789012:root"}. What does this indicate?

A.A federated user performed the console login.
B.An AWS service performed the console login.
C.An IAM user in the account performed the console login.
D.The AWS account root user performed the console login.
AnswerD

The root user is the only IAM principal that CloudTrail identifies with userIdentity.type equal to Root, and its ARN is always arn:aws:iam::123456789012:root with no session context or userName. The presence of a login event with this type proves the AWS account root user directly authenticated using the account's email and password (plus any MFA), bypassing any identity provider or IAM role. This is exactly what the CloudTrail event indicates.

Why this answer

The output shows `"type":"Root"` and `"arn":"arn:aws:iam::123456789012:root"`, which are the exact identifiers AWS CloudTrail uses to record an action performed by the AWS account root user. The root user is the account owner with full administrative access, and its principal ARN always ends with `:root`. This confirms that the console login was performed by the root user, not by any other identity.

Exam trap

The trap here is that candidates may confuse the `:root` suffix in the ARN with an IAM user named 'root', but AWS reserves the `:root` ARN exclusively for the account root user, and any IAM user would have a distinct ARN with a username after `:user/`.

How to eliminate wrong answers

Option A is wrong because a federated user would have a `type` of `FederatedUser` or `AssumedRole` in the CloudTrail event, not `Root`. Option B is wrong because an AWS service performs actions using an IAM role or service-linked role, which would appear with a `type` of `AssumedRole` or `AWSAccount`, not `Root`. Option C is wrong because an IAM user would have a `type` of `IAMUser` and an ARN like `arn:aws:iam::123456789012:user/username`, not `arn:aws:iam::123456789012:root`.

180
MCQeasy

A security team needs to detect unauthorized API calls made from a compromised IAM user. Which AWS service should be used to monitor and alert on specific API activities?

A.AWS CloudTrail
B.AWS Config
C.Amazon GuardDuty
D.VPC Flow Logs
AnswerA

AWS CloudTrail is the correct choice because it is the native AWS service that records API activity in your account, capturing who made the call, from which source IP, what action was invoked, and when it occurred. For unauthorized API call detection, you can enable CloudTrail across all regions, turn on data events for sensitive services like S3 or Lambda, and use CloudTrail Lake or integration with Amazon EventBridge to trigger real-time alerts on specific unauthorized actions. Unlike configuration state or network flow data, CloudTrail delivers a complete audit trail of every management and data-plane API call.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including those from IAM users, and delivers event history for auditing. By enabling CloudTrail trails with management event logging and configuring Amazon CloudWatch alarms or EventBridge rules on specific API actions (e.g., `iam:CreateUser`, `ec2:AuthorizeSecurityGroupIngress`), the security team can detect and alert on unauthorized API activities from a compromised IAM user.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which logs API calls), or they assume GuardDuty's threat detection covers all API-level monitoring, but GuardDuty does not provide per-API-call logging or allow custom alerting on specific actions like `iam:CreateAccessKey`.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it evaluates resource configurations against desired policies and tracks configuration changes, not API call activities; it cannot log or alert on specific API actions like `iam:CreateAccessKey`. Option C (Amazon GuardDuty) is wrong because it uses threat intelligence and anomaly detection to identify malicious behavior (e.g., unusual network traffic, compromised credentials) but does not provide granular, per-API-call logging or allow alerting on specific API actions; it focuses on broader threat detection rather than auditing individual API calls. Option D (VPC Flow Logs) is wrong because it captures metadata about IP traffic within VPCs (e.g., source/destination IP, ports, protocol) and has no visibility into AWS API calls made by IAM users; it operates at the network layer, not the control plane.

181
Multi-Selecteasy

A security engineer needs to ensure that all changes to IAM policies in an AWS account are logged and that the logs are immutable and cannot be deleted by any user, including the root user. Which actions should the engineer take? (Choose two.)

Select 2 answers
A.Enable default encryption with AWS KMS on the bucket.
B.Enable AWS CloudTrail to log IAM events.
C.Enable S3 Versioning on the bucket.
D.Enable multi-factor authentication (MFA) delete on the S3 bucket.
E.Enable S3 Object Lock in compliance mode on the bucket.
AnswersB, E

CloudTrail records every IAM API call, including policy changes, capturing the who, what, when and source IP. This satisfies the logging half of the requirement; immutability is delivered separately by S3 Object Lock in compliance mode.

Why this answer

AWS CloudTrail is the service specifically designed to log all API activity, including IAM policy changes. By enabling CloudTrail with management event logging, all IAM CreatePolicy, PutPolicy, DeletePolicy, and similar actions are recorded in a log file delivered to an S3 bucket. This provides an authoritative audit trail of who made the change, when, and from which source IP.

Option E is correct because S3 Object Lock in compliance mode prevents any user, including the root user, from overwriting or deleting objects for the specified retention period. This ensures the log files are immutable and cannot be tampered with or deleted, fulfilling the requirement that logs cannot be deleted by any user.

Exam trap

The trap here is that candidates often confuse S3 Versioning (which provides object recovery but not immutability) with S3 Object Lock (which provides true WORM immutability), and they may also overlook that MFA Delete still allows deletion by an authorized user with MFA, not preventing root from ultimately deleting logs.

182
MCQhard

A company uses AWS Organizations and wants to centralize security logs from all member accounts into a single S3 bucket in the management account. The bucket policy allows only the management account's root user to write objects. However, logs are not being delivered from member accounts. What is the MOST likely cause?

A.S3 Transfer Acceleration is not enabled.
B.VPC endpoints are not configured for the logging service.
C.The S3 bucket uses an AWS KMS key, and the key policy does not grant decrypt permissions to the logging service.
D.The bucket policy denies write access to all principals except the management account's root user, preventing cross-account writes.
AnswerD

To centralize security logs in a management account bucket, the bucket policy must explicitly allow the logging service principal, such as cloudtrail.amazonaws.com, to write objects on behalf of member accounts. If the bucket policy denies s3:PutObject to all principals except the management account root user, every delivery attempt from a member account is a cross-account write and is denied. Service principals are not the root user and never inherit the account root's permissions, so this restrictive bucket policy exactly prevents central log delivery.

Why this answer

The bucket policy explicitly restricts write access to only the management account's root user. For cross-account log delivery from member accounts, the policy must grant write permissions to the logging service (e.g., AWS CloudTrail or AWS Config) in each member account. Without such permissions, the service cannot write objects to the bucket, causing log delivery to fail.

Exam trap

The trap here is that candidates often overlook that the bucket policy's explicit denial to all principals except the management account root user also blocks the logging service's cross-account write attempts, even though the service is not a user but an AWS service principal.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a feature for speeding up uploads over long distances and has no bearing on cross-account write permissions for logging services. Option B is wrong because VPC endpoints are used for private connectivity within a VPC and are not required for logging services to deliver logs to an S3 bucket; the issue is a permissions problem, not a network connectivity one. Option C is wrong because while KMS key policies can affect decryption, the logging service needs encrypt permissions (kms:GenerateDataKey and kms:Encrypt) to write objects, not decrypt; furthermore, the question states logs are not being delivered, which points to a write permission failure, not a decryption issue.

183
MCQeasy

A security engineer needs to ensure that all S3 buckets in an AWS account have server access logging enabled. Which AWS service should be used to continuously monitor for compliance?

A.AWS Config
B.Amazon GuardDuty
C.AWS IAM Access Analyzer
D.AWS CloudTrail
AnswerA

AWS Config is the correct choice because it is a configuration assessment service that continuously records S3 bucket configurations and evaluates them against managed rules such as s3-bucket-logging-enabled. When server access logging is disabled, the rule marks the bucket as noncompliant, and you can automate remediation with SSM documents or custom Lambda functions. AWS Config provides a compliance history, so you can see exactly when a bucket fell out of compliance, which is essential for audit evidence.

Why this answer

AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations against desired policies. You can create an AWS Config rule, such as the managed rule 's3-bucket-server-access-logging-enabled', which will automatically check all S3 buckets in your account and report any that do not have server access logging enabled, flagging them as noncompliant. This allows for ongoing, automated compliance auditing without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config with AWS CloudTrail, mistakenly thinking that CloudTrail's logging of API calls can be used to continuously monitor compliance, but CloudTrail only records events and does not evaluate the current state of resources against a desired configuration.

How to eliminate wrong answers

Option B (Amazon GuardDuty) is wrong because GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events to identify malicious activity; it does not evaluate resource configurations for compliance with logging requirements. Option C (AWS IAM Access Analyzer) is wrong because it focuses on identifying resources shared with external entities by analyzing resource-based policies (e.g., S3 bucket policies), not on verifying whether server access logging is enabled. Option D (AWS CloudTrail) is wrong because CloudTrail records API calls made in your account for auditing and governance, but it does not continuously monitor the configuration state of S3 buckets to enforce compliance with logging settings.

184
MCQhard

A security team wants to centrally collect and analyze VPC Flow Logs from multiple AWS accounts for security monitoring. Which solution is MOST scalable and cost-effective?

A.Aggregate logs in an EC2 instance running an ELK stack.
B.Use Amazon Kinesis Data Firehose to stream logs to an S3 bucket and process with AWS Lambda.
C.Configure VPC Flow Logs to send to a centralized CloudWatch Logs account using cross-account subscriptions.
D.Use AWS Organizations to centralize logging by delivering VPC Flow Logs to a centralized S3 bucket and query with Amazon Athena.
AnswerD

AWS Organizations centralises log delivery across accounts into one S3 bucket, avoiding per-account pipelines. Athena queries that bucket serverlessly, paying only per query, which satisfies the scalability and cost-effectiveness constraints for multi-account VPC Flow Log analysis.

Why this answer

Using AWS Organizations to centrally deliver VPC Flow Logs to a centralized S3 bucket, then querying with Amazon Athena, is both scalable and cost-effective. S3 provides durable, low-cost storage for large volumes of log data, and Athena allows serverless, pay-per-query analysis without provisioning infrastructure. This approach avoids the operational overhead of managing EC2 instances or streaming pipelines, and scales seamlessly as log volume grows.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing a streaming or real-time processing service (like Kinesis or CloudWatch Logs) when the requirement is for cost-effective batch analysis, not real-time alerting.

How to eliminate wrong answers

Option A is wrong because running an ELK stack on an EC2 instance introduces significant operational overhead, requires manual scaling, and incurs costs for compute and storage even when idle, making it less scalable and cost-effective than serverless alternatives. Option B is wrong because Amazon Kinesis Data Firehose to S3 with Lambda processing adds unnecessary complexity and cost for a use case that can be served by direct S3 delivery and Athena queries, and Firehose is optimized for streaming ingestion, not batch log analysis. Option C is wrong because cross-account CloudWatch Logs subscriptions require managing subscription filters and IAM roles across accounts, and CloudWatch Logs costs are higher per GB ingested and stored compared to S3, making it less cost-effective for high-volume VPC Flow Logs.

185
MCQeasy

A security engineer needs to capture all API calls made to AWS services for forensic analysis. Which AWS service should be used to store these logs durably and cost-effectively for long-term retention?

A.VPC Flow Logs
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail records every API call across AWS services as management and data events, satisfying the requirement to capture all API activity. Delivering these trails to Amazon S3 provides durable, low-cost long-term retention for forensic analysis, unlike CloudWatch Logs, which is pricier for bulk storage.

Why this answer

AWS CloudTrail is the correct service because it captures all API calls made to AWS services, including the identity of the caller, time of the call, source IP address, and request parameters. It stores these logs durably in Amazon S3, which provides cost-effective long-term retention for forensic analysis. CloudTrail is specifically designed for auditing and monitoring API activity across an AWS environment.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), leading them to select Config when the question explicitly asks for capturing API calls.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) at the VPC level, not API calls to AWS services. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (including CloudTrail, VPC Flow Logs, and DNS logs) for malicious activity, but it does not natively store or capture raw API call logs for long-term retention. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not capture API calls; it focuses on resource state history, not the API actions that caused changes.

186
Multi-Selectmedium

Which TWO actions should a security engineer take to ensure that CloudTrail logs are protected from unauthorized deletion? (Choose two.)

Select 2 answers
A.Attach an S3 bucket policy that denies s3:DeleteObject to all principals except the CloudTrail service principal.
B.Enable S3 versioning on the log bucket.
C.Enable S3 default encryption with SSE-S3.
D.Configure CloudTrail to send logs to CloudWatch Logs.
E.Enable S3 MFA Delete on the log bucket.
AnswersA, E

This bucket policy uses an explicit Deny for s3:DeleteObject scoped to all principals except the CloudTrail service principal (with conditions like aws:SourceArn to prevent misuse), which prevents any IAM user, role, or AWS account from deleting log objects. Because an explicit Deny overrides all Allows, this enforces immutability of the logs while still allowing CloudTrail to write new objects. This is a direct and robust control for preserving audit log integrity.

Why this answer

Attaching an S3 bucket policy that denies s3:DeleteObject to all principals except the CloudTrail service principal prevents any user or role (including root) from deleting log files, while still allowing CloudTrail to write logs. This ensures that even if an attacker gains administrative access, they cannot delete the logs, preserving their integrity for forensic analysis.

Exam trap

The trap here is that candidates often confuse data protection mechanisms (encryption, versioning) with deletion prevention, leading them to select options like B or C instead of recognizing that only explicit deny policies and MFA Delete directly block deletion actions.

187
MCQhard

A company has enabled AWS CloudTrail in all accounts and regions, with log file validation enabled. The security team needs to verify that a specific log file has not been modified since it was delivered. Which action should be taken?

A.Query the log files using Amazon CloudWatch Logs Insights.
B.Enable S3 server-side encryption with AWS KMS (SSE-KMS) on the CloudTrail bucket.
C.Enable S3 Object Lock on the bucket to prevent modifications.
D.Use the AWS CLI `validate-logs` command with the digest file from the S3 bucket.
AnswerD

The `aws cloudtrail validate-logs` command implements CloudTrail's integrity validation by reading the digest files delivered to the S3 bucket. Each digest file contains the SHA-256 hash of the log files and a digital signature generated with AWS's private key; the CLI retrieves the corresponding public key from AWS, verifies the signature, and then recomputes the hash of each log file to compare against the digest. This process cryptographically confirms that log files were not altered or removed during delivery, providing a tamper-evident chain from the moment CloudTrail wrote the file.

Why this answer

CloudTrail log file validation creates a hash of each log file and stores it in a digest file. To verify that a specific log file has not been altered since delivery, you must use the AWS CLI `validate-logs` command, which compares the hash in the digest file against the current hash of the log file. This command also validates the digital signature of the digest file itself, ensuring end-to-end integrity.

Exam trap

The trap here is that candidates confuse data integrity verification (hash comparison) with data protection mechanisms like encryption or object lock, which prevent or obscure modification but do not prove that a file has remained unchanged since its creation.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights is used for querying and analyzing log data, not for cryptographic integrity verification of individual log files. Option B is wrong because SSE-KMS encrypts data at rest but does not provide any mechanism to detect or prevent modification of log files after delivery. Option C is wrong because S3 Object Lock prevents deletion or overwrite of objects during a retention period, but it does not verify the integrity of already-delivered log files or detect modifications made before the lock was applied.

188
MCQmedium

A security engineer needs to detect when an EC2 instance is terminated in an AWS account. The solution must provide near-real-time notification. Which combination of services should be used?

A.VPC Flow Logs and Amazon CloudWatch Logs
B.AWS CloudTrail and Amazon EventBridge
C.AWS Config and Amazon SNS
D.Amazon CloudWatch Alarms and Amazon SNS
AnswerB

AWS CloudTrail is the correct service here because it records management events as API calls, including the TerminateInstances action, with details such as the IAM principal, source IP, and request parameters. Amazon EventBridge can consume CloudTrail API events through a rule that matches source=aws.ec2 and eventName=TerminateInstances, then trigger an SNS topic or Lambda function within seconds. This gives a near-real-time, audit-ready detection path that is directly tied to the API request that caused the termination.

Why this answer

AWS CloudTrail captures API calls, including TerminateInstances, as management events. Amazon EventBridge can filter these events in near real-time and trigger a notification action (e.g., via SNS or Lambda). This combination provides immediate detection of EC2 termination without polling or delays.

Exam trap

The trap here is that candidates often confuse CloudWatch Alarms (which monitor metrics) with event-driven services like EventBridge, failing to recognize that EC2 termination is an API event, not a metric change, and thus requires CloudTrail as the event source.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) and are not designed to detect EC2 instance lifecycle events like termination; they lack the API-level visibility needed. Option C is wrong because AWS Config evaluates resource configuration changes against rules and typically delivers results with a delay (minutes to hours), not near-real-time, and it is not optimized for event-driven notification of a single termination action. Option D is wrong because CloudWatch Alarms monitor metric thresholds (e.g., CPU utilization) and cannot directly detect the termination of an EC2 instance; they would require a custom metric or a proxy signal, which adds latency and complexity.

189
MCQhard

An organization wants to detect and alert on the use of root user credentials in their AWS accounts. They have multiple accounts managed via AWS Organizations. What is the most efficient way to centralize this monitoring?

A.Create an AWS CloudTrail trail in each account and aggregate logs to a central S3 bucket.
B.Use IAM Access Analyzer to find resources shared with external entities.
C.Use AWS Config rules to detect root user usage in each account.
D.Enable Amazon GuardDuty in the management account and use the delegated administrator feature.
AnswerD

Enabling GuardDuty in the management account and designating a delegated administrator lets one account manage GuardDuty for all member accounts in the organization, aggregating findings centrally. GuardDuty uses integrated threat intelligence and anomaly detection to analyze CloudTrail management events, VPC flow logs, and DNS logs, generating a specific finding type when root user credentials are used anomalously, such as 'UnauthorizedAccess:IAMUser/RootCredentialUsage'. This provides cross-account visibility and built-in detection without needing to build custom log-analysis pipelines in each account.

Why this answer

Amazon GuardDuty, when enabled in the management account with a delegated administrator, can centrally monitor and detect suspicious activity—including root user credential usage—across all member accounts in AWS Organizations. This approach eliminates the need to configure per-account monitoring and provides a single pane of glass for security alerts, making it the most efficient centralized solution.

Exam trap

The trap here is that candidates often assume CloudTrail or AWS Config are sufficient for monitoring root user usage, but they overlook GuardDuty's purpose-built, centralized detection capability for security events like root credential usage across multi-account environments.

How to eliminate wrong answers

Option A is wrong because while aggregating CloudTrail logs to a central S3 bucket enables log storage, it does not provide built-in alerting or detection for root user usage; you would need additional services (e.g., Amazon Athena, Lambda) to parse and alert on root activity, which is less efficient than GuardDuty's native detection. Option B is wrong because IAM Access Analyzer is designed to identify resources shared with external entities (e.g., S3 buckets, KMS keys) and does not monitor or alert on root user credential usage. Option C is wrong because AWS Config rules can evaluate resource configurations but cannot directly detect root user login events; root usage is an API call event, not a configuration state, and Config lacks native real-time alerting for such activity.

190
Multi-Selecthard

A company wants to monitor for unauthorized API calls in real-time. The solution must meet the following requirements: - Detect calls that fail authentication (AccessDenied). - Detect calls that use a revoked IAM role. - Provide a centralized view across multiple accounts. Which THREE services should be used together to implement this solution? (Choose three.)

Select 3 answers
A.AWS Organizations
B.AWS CloudTrail
C.AWS IAM Access Analyzer
D.Amazon CloudWatch Logs
E.AWS Config
AnswersA, B, D

AWS Organizations is the correct answer because it lets you create a single organization trail in CloudTrail that captures API activity for every member account, including new accounts as they join. By aggregating all trails centrally, you gain a complete audit baseline and can enforce a trail that member accounts cannot disable or modify, preventing gaps in monitoring. This makes Organizations essential for managing and protecting your organization-wide API monitoring infrastructure.

Why this answer

AWS Organizations is correct because it enables centralized management of multiple AWS accounts, allowing the solution to aggregate CloudTrail logs from all accounts into a single CloudWatch Logs group. This centralization is essential for real-time monitoring of unauthorized API calls across the entire organization, as CloudTrail logs record all API activity including AccessDenied errors and actions taken by revoked IAM roles.

Exam trap

The trap here is that candidates often confuse AWS IAM Access Analyzer with CloudTrail for monitoring API calls, but Access Analyzer only analyzes resource policies for external access, not real-time API activity or authentication failures.

191
MCQhard

A company wants to monitor AWS API calls for suspicious activity and automatically remediate by revoking IAM roles in real time. Which combination of services should be used?

A.AWS CloudTrail and Amazon Inspector
B.AWS CloudTrail and AWS Config
C.Amazon GuardDuty and AWS Config
D.Amazon CloudWatch Events and AWS Lambda
AnswerD

By creating a CloudWatch Events rule with an event pattern matching specific AWS API calls recorded by CloudTrail, organizations can invoke a Lambda function in real time to conduct security actions such as revoking IAM roles, deleting access keys, or restricting permissions. This event-driven model delivers immediate, automated remediation of suspicious API activity, satisfying the requirement.

Why this answer

The combination of Amazon CloudWatch Events and AWS Lambda enables real-time monitoring and automated remediation of AWS API calls. CloudWatch Events can capture API calls from AWS CloudTrail (or other sources) and trigger a Lambda function to revoke IAM roles based on suspicious activity patterns, providing the required real-time response.

Exam trap

The trap here is that candidates may confuse AWS Config's compliance evaluation with real-time event-driven remediation, or assume GuardDuty alone provides automated remediation, when in fact both require CloudWatch Events and Lambda for the actual automated response.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposures, not a real-time API monitoring or remediation service. Option B is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, not designed for real-time API call monitoring or automated IAM role revocation. Option C is wrong because while Amazon GuardDuty can detect suspicious API activity, AWS Config is not the appropriate service for real-time remediation; GuardDuty findings typically trigger CloudWatch Events or Lambda for automated response, not AWS Config.

192
MCQhard

A company is using Amazon Macie to discover sensitive data in S3. The security team wants to be notified when Macie finds a high-severity alert. Which integration should be used?

A.Configure Macie to store findings in an S3 bucket and enable S3 event notifications.
B.Integrate Macie with AWS Security Hub and create a custom action to send to SNS.
C.Create an Amazon EventBridge rule that matches Macie findings and targets an SNS topic.
D.Configure Macie to send findings to CloudWatch Logs and create a metric filter.
AnswerC

Macie automatically publishes every finding to Amazon EventBridge as a 'Macie Finding' event on the default event bus. An EventBridge rule with an event pattern matching source 'aws.macie' and detail-type 'Macie Finding' can route to an SNS topic in near real time. This is the native integration path, requiring no additional services, custom code, or intermediate storage.

Why this answer

Amazon EventBridge can directly capture Macie findings (which are emitted as events) and route them to an SNS topic for notification. This is the native, event-driven integration that requires no intermediate storage or custom actions, making it the simplest and most reliable approach for real-time alerting on high-severity findings.

Exam trap

The trap here is that candidates often assume Macie findings must go through Security Hub or CloudWatch first, but EventBridge is the native event bus for all AWS services including Macie, and it directly supports SNS as a target without custom actions.

How to eliminate wrong answers

Option A is wrong because Macie does not natively store findings in an S3 bucket; findings are stored in Macie itself or can be exported via a separate process, and S3 event notifications would not trigger on Macie findings directly. Option B is wrong because while Macie integrates with Security Hub, creating a custom action in Security Hub to send to SNS adds unnecessary complexity and latency; EventBridge is the direct integration point for Macie events. Option D is wrong because Macie does not send findings to CloudWatch Logs natively; you would need a custom solution to forward them, and metric filters are for log pattern matching, not for triggering notifications on structured findings.

193
Drag & Dropmedium

Drag and drop the steps to set up AWS Shield Advanced with automatic application layer DDoS mitigation in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Shield Advanced requires subscription first, then resource protection, WAF integration, mitigation rule, and health-based detection.

194
MCQmedium

A security engineer notices that CloudTrail logs for a production account are not being delivered to the S3 bucket. The bucket policy allows CloudTrail to write objects. What is the MOST likely cause?

A.The S3 bucket does not have versioning enabled.
B.The S3 bucket uses SSE-KMS encryption.
C.The bucket policy does not grant s3:GetBucketAcl to CloudTrail.
D.The S3 bucket contains existing objects before CloudTrail delivery started.
AnswerC

CloudTrail does not merely write objects; it first calls s3:GetBucketAcl to confirm it is allowed to deliver to that bucket and to verify bucket ownership. A bucket policy that omits s3:GetBucketAcl causes CloudTrail's initial validation to fail, and delivery is not set up even though the s3:PutObject action may be allowed. This access check is distinct from an S3 write permission, which is why the correct fix is to add an ACL-read allowance, not just PutObject.

Why this answer

CloudTrail requires the `s3:GetBucketAcl` permission on the destination S3 bucket to verify that the bucket policy grants CloudTrail the necessary write access. Without this permission, CloudTrail cannot confirm its ability to deliver logs, even if the bucket policy explicitly allows `s3:PutObject`. This is a prerequisite check performed by CloudTrail before any log delivery occurs.

Exam trap

The trap here is that candidates assume the only permission needed for CloudTrail to deliver logs is `s3:PutObject`, overlooking the prerequisite `s3:GetBucketAcl` permission that CloudTrail requires to validate the bucket policy before any log delivery can start.

How to eliminate wrong answers

Option A is wrong because S3 versioning is not required for CloudTrail log delivery; it is an optional feature for preserving object versions. Option B is wrong because SSE-KMS encryption is supported by CloudTrail as long as the necessary KMS key permissions (kms:GenerateDataKey and kms:Decrypt) are granted to the CloudTrail service principal; the bucket policy allowing CloudTrail to write objects does not preclude SSE-KMS. Option D is wrong because the presence of existing objects in the S3 bucket does not prevent CloudTrail from delivering new log files; CloudTrail only needs write access and does not require an empty bucket.

195
Multi-Selecthard

A security engineer is designing a logging strategy for a multi-account environment. The engineer needs to ensure that all API activity across accounts is logged and that logs are immutable and centrally accessible. Which THREE actions should the engineer take?

Select 3 answers
A.Stream logs to CloudWatch Logs for real-time monitoring.
B.Create an AWS CloudTrail organization trail that logs to a central S3 bucket.
C.Enable S3 Object Lock in Compliance mode on the central bucket.
D.Enable VPC Flow Logs in all accounts and send to the central bucket.
E.Grant the central bucket policy to allow only the CloudTrail service to write logs.
AnswersB, C, E

An organization trail in the management account is the only single configuration that captures management events from every account within the AWS Organization, including member accounts, and delivers them to a designated central S3 bucket. This avoids needing to deploy separate trails per account, centralizes the audit source of record, and is the appropriate backbone for the logging strategy described in the scenario.

Why this answer

AWS CloudTrail organization trails automatically aggregate API activity from all member accounts in an AWS Organizations setup, delivering log files to a single, centrally managed S3 bucket. This eliminates the need to configure individual trails per account, ensuring comprehensive and centralized logging of all API calls across the multi-account environment.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (network-level) with CloudTrail (API-level) logging, or they assume CloudWatch Logs alone provides immutability, when in fact only S3 Object Lock in Compliance mode guarantees write-once-read-many (WORM) protection for audit logs.

196
MCQhard

A security engineer needs to analyze VPC Flow Logs to identify traffic to a known malicious IP address. The logs are stored in Amazon S3. Which approach is the most cost-effective for querying the logs?

A.Use Amazon Athena to query the logs in S3
B.Load the logs into an Amazon Redshift cluster
C.Use Amazon EMR to run Spark jobs
D.Use Amazon QuickSight to connect to S3
AnswerA

Amazon Athena is the correct choice because it is a serverless, interactive query service that uses standard SQL to query data directly from S3, paying only for the data scanned. VPC Flow Logs stored in S3 can be queried immediately by creating a table in the AWS Glue Data Catalog, with no infrastructure to provision or manage. Athena is optimized for ad-hoc, cost-effective analysis, and its per-query pricing makes it ideal for the intermittent, investigative queries a security engineer typically runs. Partitioning the S3 flow log data by date and using columnar formats further reduces cost and query time.

Why this answer

Amazon Athena is the most cost-effective option because it is a serverless query service that allows you to run SQL queries directly on data stored in S3, including VPC Flow Logs, without needing to load or transform the data. You pay only for the data scanned per query, and with partitioning (e.g., by date or region), you can minimize costs by scanning only relevant log files. This avoids the overhead of provisioning clusters or managing infrastructure, making it ideal for ad-hoc analysis of malicious IP traffic.

Exam trap

The trap here is that candidates may assume loading data into a dedicated database (Redshift) or using a big data framework (EMR) is necessary for analysis, overlooking Athena’s serverless, pay-per-query model that is purpose-built for querying data directly in S3 without data movement.

How to eliminate wrong answers

Option B is wrong because Amazon Redshift is a fully managed data warehouse designed for complex analytical workloads on structured data; loading VPC Flow Logs into Redshift incurs significant storage and compute costs, and requires ETL processes, making it far less cost-effective for simple querying of logs in S3. Option C is wrong because Amazon EMR with Spark jobs introduces overhead for cluster provisioning, management, and per-hour compute costs, which is overkill for querying logs for a single IP address; it is better suited for large-scale data processing and transformation, not ad-hoc SQL queries. Option D is wrong because Amazon QuickSight is a business intelligence visualization tool, not a query engine; while it can connect to S3 via Athena or other sources, it cannot directly query S3 data and would require additional services, increasing complexity and cost.

197
MCQhard

A company's security team is investigating a potential security incident. They have enabled CloudTrail and CloudWatch Logs. They want to receive real-time alerts when an IAM user creates a new access key. Which combination of services should be used to achieve this?

A.AWS Config rules with an SNS topic
B.Amazon GuardDuty with an SNS topic
C.CloudTrail with CloudWatch Logs, metric filter, alarm, and SNS topic
D.CloudTrail with Lambda function invocation
AnswerC

This is the correct end-to-end solution: AWS CloudTrail records every management API call and delivers those logs to a CloudWatch Logs log group. A CloudWatch Logs metric filter is then created with a pattern that matches the specific event, for example the eventName or a user identity, and the filter publishes a metric value each time a matching event occurs. A CloudWatch alarm can then monitor that metric with a defined threshold, and when triggered, it sends a notification to an SNS topic, enabling real-time alerting for the exact API call of interest.

Why this answer

CloudTrail logs API calls like CreateAccessKey to CloudWatch Logs. A metric filter on the event name 'CreateAccessKey' triggers a CloudWatch alarm that publishes to an SNS topic, enabling real-time notifications. This is the standard AWS architecture for real-time alerting on specific IAM actions.

Exam trap

The trap here is that candidates confuse AWS Config (which monitors configuration changes) with CloudTrail (which records API calls), or assume GuardDuty covers all security events, but GuardDuty does not provide granular, custom alerts on specific IAM actions like access key creation.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource configuration compliance, not real-time API call events; they detect drift over time, not instant actions like access key creation. Option B is wrong because Amazon GuardDuty focuses on threat detection (e.g., anomalous API behavior, compromised credentials) and does not natively trigger on specific IAM user actions like CreateAccessKey; it requires additional integration. Option D is wrong because while CloudTrail can invoke a Lambda function via EventBridge, the combination of CloudTrail with Lambda alone lacks the metric filter and alarm mechanism for real-time alerting; it requires additional setup to trigger notifications.

198
MCQmedium

A security engineer is investigating a potential data exfiltration incident. They see that an EC2 instance with an IAM role is making API calls to S3 to download objects. The IAM role has an S3 bucket policy that allows access from that role. However, CloudTrail logs show that the calls are being made from an IP address outside the company's network. What is the most likely explanation?

A.The IAM role credentials were stolen and are being used from an external machine.
B.The EC2 instance has a public IP and the calls are originating from the instance itself.
C.CloudTrail is logging the IP address of the AWS service endpoint, not the client.
D.The S3 bucket policy allows public access.
AnswerA

The CloudTrail event shows the calls were made using the IAM role's temporary credentials but with a sourceIP address that does not match the EC2 instance's IP. Because the role's credentials are obtainable from the instance metadata service (IMDS), if an attacker gains access (e.g., via SSRF) they can extract the credentials and replay them from an external machine, making CloudTrail log that external source IP. This is a classic credential exfiltration scenario, and it explains why the identity is the role while the network origin is elsewhere.

Why this answer

The CloudTrail logs show the API calls originating from an IP address outside the company's network, which indicates that the IAM role credentials (temporary security credentials from the instance metadata) have been compromised and are being used from an external machine. The S3 bucket policy allows access from the IAM role, but the source IP in the logs is external, confirming the credentials are being used outside the EC2 instance.

Exam trap

The trap here is that candidates may assume the external IP is due to a NAT gateway or AWS service endpoint, but CloudTrail always logs the actual client IP, not the service endpoint IP.

How to eliminate wrong answers

Option B is wrong because if the EC2 instance has a public IP and the calls originate from the instance itself, the source IP in CloudTrail would be the instance's public IP or the NAT gateway IP, not an IP outside the company's network. Option C is wrong because CloudTrail logs the source IP address of the client making the API call, not the AWS service endpoint IP; this is a fundamental behavior of CloudTrail logging. Option D is wrong because the S3 bucket policy allows access from the IAM role, not public access; a public access policy would allow anonymous requests, but the logs show the calls are made with the IAM role's credentials, not anonymously.

199
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all CloudTrail trails are enabled in all accounts and log to a central S3 bucket. What is the MOST efficient way to enforce this?

A.Use AWS Lambda to check each account and enable CloudTrail if missing.
B.Use AWS Config aggregator to verify compliance and send alerts.
C.Create a service control policy (SCP) that requires CloudTrail.
D.Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts.
AnswerD

CloudFormation StackSets, especially when backed by service-managed permissions, let you deploy the same CloudTrail stack to every account or OU in AWS Organizations from a single template. StackSets create, update, and delete resources in parallel across specified accounts and regions, and they can automatically add new accounts when they join the organization. This gives you a consistent, auditable, and repeatable way to ensure each account has a configured CloudTrail trail, unlike the other options that either merely report or cannot provision resources.

Why this answer

AWS CloudFormation StackSets allows you to deploy a CloudTrail template across multiple accounts and Regions from a single management account, ensuring all accounts have a trail configured to log to the central S3 bucket. This approach is the most efficient as it automates deployment, enforces consistent configuration, and scales across the entire organization without requiring per-account manual intervention or custom scripting.

Exam trap

The trap here is that candidates often confuse SCPs with proactive enforcement tools, but SCPs only deny or allow actions and cannot create or enable resources, making them unsuitable for requiring a specific service configuration like CloudTrail.

How to eliminate wrong answers

Option A is wrong because using AWS Lambda to check each account and enable CloudTrail is reactive, inefficient, and does not enforce compliance proactively; it requires custom code, permissions, and ongoing maintenance, and it cannot prevent accounts from disabling the trail. Option B is wrong because AWS Config aggregator can verify compliance and send alerts, but it does not enforce or remediate the missing CloudTrail configuration; it only provides visibility and notifications, leaving the actual enforcement to other services. Option C is wrong because a service control policy (SCP) cannot require or enable CloudTrail; SCPs only restrict permissions (deny actions) and cannot create resources or enforce positive configurations like enabling a trail.

200
MCQhard

A company uses AWS Organizations with multiple accounts. They want to centralize logging of all API calls across all accounts and store them in a single S3 bucket. Which configuration should be used?

A.Use AWS Config to record API calls across all accounts
B.Create a separate CloudTrail trail in each account and aggregate logs using Amazon Athena
C.Create an organization trail in the management account
D.Enable VPC Flow Logs in each account and send to a central S3 bucket
AnswerC

An organization trail created in the management account automatically logs API activity across every account in AWS Organizations into one S3 bucket, satisfying the centralisation requirement. Account-level trails would need separate configuration per account and would not aggregate automatically.

Why this answer

AWS Organizations allows you to create an organization trail in the management account that automatically logs API calls for all member accounts. This centralizes CloudTrail logs into a single S3 bucket without needing to configure individual trails per account, ensuring complete coverage and simplified management.

Exam trap

The trap here is that candidates often confuse AWS Config (which records configuration changes) with CloudTrail (which records API calls), or they think VPC Flow Logs can substitute for API logging, leading them to select options that do not meet the requirement for centralized API call logging.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes, not API calls; it does not capture the detailed API activity that CloudTrail provides. Option B is wrong because while separate trails per account can send logs to a central bucket, this approach is redundant and harder to manage compared to an organization trail, and Athena is a query service, not a logging aggregation service. Option D is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols), not API calls; they are used for network analysis, not API activity logging.

201
Multi-Selectmedium

A security engineer is designing a logging solution for an application that runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The engineer needs to capture and store the following logs for analysis: (1) HTTP request logs from the ALB, (2) operating system logs from the EC2 instances, and (3) network traffic logs for the VPC. Which combination of AWS services should the engineer use? (Choose three.)

Select 3 answers
A.Enable access logging on the ALB and store logs in an S3 bucket.
B.Enable VPC Flow Logs to capture network traffic metadata.
C.Enable S3 server access logging for the application's S3 buckets.
D.Enable AWS CloudTrail to capture API calls.
E.Install the CloudWatch Logs agent on EC2 instances to send OS logs to CloudWatch Logs.
AnswersA, B, E

ALB access logging is the correct choice because it records detailed HTTP request data—method, URI, requester IP, user agent, latency, and the ALB's response code—for every request the load balancer processes. Since an ALB sits in front of the application's EC2 or container targets, enabling this access log and delivering it to an S3 bucket directly captures the application-level request telemetry needed to analyze client traffic patterns, troubleshoot HTTP errors, and support security investigations.

Why this answer

ALB access logging captures detailed HTTP request data (method, URI, status code, user agent, etc.) and can be directly configured to store logs in an S3 bucket without additional agents or infrastructure. This satisfies the requirement for HTTP request logs from the ALB.

Exam trap

The trap here is that candidates often confuse CloudTrail with VPC Flow Logs or ALB access logs, not realizing CloudTrail only captures management plane API calls, not data plane logs like HTTP requests or network traffic.

202
MCQmedium

A company has an S3 bucket that stores sensitive data. The bucket policy allows access only from a specific VPC endpoint. The security team notices that an object was accessed from an IP address outside the allowed VPC. CloudTrail logs show that the access was made using temporary credentials from an assumed role. The role was assumed by an EC2 instance in the allowed VPC. What is the MOST likely reason the access was allowed despite the bucket policy restriction?

A.The bucket policy does not require encryption in transit.
B.The bucket policy allows access from the VPC endpoint, and the request was made through that endpoint.
C.The bucket policy has a syntax error that makes it ineffective.
D.The IAM role used by the EC2 instance has permissions that override the bucket policy.
AnswerB

When a request is sent to S3 through a VPC gateway endpoint, the bucket policy can explicitly allow it using the aws:sourceVpce condition key, which matches the endpoint ID rather than the client's IP address. Because the policy authorizes that specific endpoint, every request routed through it satisfies the policy, regardless of the source IP. This means an IP-based restriction intended for other sources is effectively bypassed, so this option correctly identifies the root cause.

Why this answer

The bucket policy uses the aws:SourceVpce condition to restrict access to a specific VPC endpoint. When the EC2 instance in the allowed VPC makes a request, it goes through the VPC endpoint, satisfying the condition. Even though the source IP address appears to be outside the VPC (the VPC endpoint's public IP), the policy evaluates based on the VPC endpoint, not the source IP.

Therefore, the request was allowed. Option A is incorrect because encryption in transit is not related to the access restriction. Option C is incorrect because there is no evidence of a syntax error.

Option D is incorrect because IAM permissions cannot override a bucket policy that explicitly denies access; the bucket policy allowed the access because the condition was met.

203
MCQmedium

A security engineer needs to monitor for unauthorized changes to IAM roles and policies in an AWS account. The engineer wants to receive an email notification whenever an IAM policy is attached to a role. Which AWS services should be combined to achieve this?

A.Amazon GuardDuty and Amazon Simple Email Service (SES)
B.AWS CloudTrail and Amazon CloudWatch Events (Amazon EventBridge)
C.AWS Config and Amazon Simple Notification Service (SNS)
D.Amazon Inspector and Amazon CloudWatch Logs
AnswerB

AWS CloudTrail is the correct source because it records management events such as an IAM policy modification, capturing the requesting principal, event time, and source IP. Amazon CloudWatch Events (now Amazon EventBridge) can define an event pattern that matches the specific CloudTrail event name and source, then targets an SNS topic to notify the security team. Together they provide near-real-time, API-level monitoring and alerting for unauthorized changes.

Why this answer

AWS CloudTrail logs all API calls, including AttachRolePolicy, and CloudWatch Events (EventBridge) can filter for that specific event and trigger an action such as sending an email via SNS. This combination allows real-time monitoring and notification for unauthorized IAM policy attachments to roles.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation and SNS notifications with real-time event-driven monitoring, but Config evaluates resources on a periodic or change-triggered basis rather than capturing every API call instantly like CloudTrail and EventBridge do.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail events for malicious activity, but it does not directly trigger email notifications for specific IAM API calls; it would require additional services like EventBridge and SNS. Option C is wrong because AWS Config is a configuration compliance service that evaluates resource configurations against rules, but it does not provide real-time event-driven notifications for API calls like AttachRolePolicy; it can trigger SNS notifications only after a configuration change is detected, which is not immediate. Option D is wrong because Amazon Inspector is a vulnerability assessment service for EC2 instances and container workloads, not for monitoring IAM policy changes; CloudWatch Logs can store logs but cannot trigger email notifications without additional services like EventBridge and SNS.

204
MCQmedium

A company runs a multi-tier web application on AWS. The application consists of an Application Load Balancer (ALB), a fleet of EC2 instances in an Auto Scaling group, and an RDS MySQL database. The security team wants to monitor for SQL injection attempts. They have enabled AWS WAF on the ALB and are logging all requests. The security engineer needs to analyze the WAF logs to identify if any SQL injection attacks have been attempted. The logs are stored in an S3 bucket. The engineer needs to query the logs for patterns like 'SELECT * FROM' or 'DROP TABLE' in the URI. Which service should the engineer use to perform this analysis?

A.Amazon Kinesis Data Analytics
B.Amazon QuickSight
C.CloudWatch Logs Insights
D.Amazon Athena
AnswerD

Amazon Athena is a serverless, interactive query service that runs standard SQL directly against structured, semistructured, or unstructured data stored in Amazon S3. For AWS WAF logs, which are JSON objects, you can define a table in the AWS Glue Data Catalog and query them with Athena using partitions by date, with no servers or clusters to provision. It is the natural fit for analyzing WAF log files in S3.

Why this answer

Amazon Athena is a serverless interactive query service that can query data directly from S3 using standard SQL, making it ideal for analyzing WAF logs stored in S3. The engineer can run SQL queries with LIKE clauses to search for patterns like 'SELECT * FROM' or 'DROP TABLE' in the URI field. Athena integrates natively with S3 and requires no infrastructure management.

Exam trap

SCS-C02 often tests the distinction between services that query S3 data (Athena) versus services that process streams (Kinesis) or visualize data (QuickSight), so candidates must match the tool to the data location and query need.

How to eliminate wrong answers

Option A is wrong because Kinesis Data Analytics is for real-time stream processing, not ad-hoc querying of historical logs in S3. Option B is wrong because QuickSight is a business intelligence visualization tool, not a log query engine. Option C is wrong because CloudWatch Logs Insights queries CloudWatch Logs, not S3-stored WAF logs.

205
Multi-Selectmedium

A security team is designing a logging solution for a multi-account AWS environment using AWS Organizations. They need to collect CloudTrail logs, VPC Flow Logs, and DNS logs from all accounts. Which TWO services can be used to centralize this logging?

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail (Organization Trail)
C.AWS Config
D.Amazon GuardDuty
E.Amazon S3
AnswersA, E

Amazon CloudWatch Logs is incorrect because it primarily serves as a destination for log streams within individual AWS accounts, providing real-time monitoring and analysis capabilities. While CloudTrail, VPC Flow Logs, and DNS logs can be directed to CloudWatch Logs, it lacks a native, managed mechanism to centrally *collect and aggregate* these log types *from multiple accounts* within an AWS Organizations structure into a single logging account. It is tempting because CloudWatch Logs is a core log management service, ideal for operational visibility, metric extraction, and alerting on logs *per account*, or for smaller-scale log storage.

Why this answer

Amazon CloudWatch Logs (A) is correct because it can serve as a centralized log repository where log groups from multiple accounts stream CloudTrail, VPC Flow Logs, and Route 53 DNS query logs via subscription filters and cross-account log sharing, enabling a single security account to aggregate and query all log data. Amazon S3 (E) is correct because it is the standard centralized destination for CloudTrail log file delivery (including organization trails), VPC Flow Logs (delivered to S3 buckets), and Route 53 DNS query logs, with cross-account bucket policies and AWS Organizations allowing all member accounts to write into a central logging bucket. AWS CloudTrail (Organization Trail) (B) is not correct here because it only captures CloudTrail API activity across accounts, not VPC Flow Logs or DNS logs, so it cannot centralize all three log types.

AWS Config (C) is not correct because it records resource configuration changes and compliance state, not CloudTrail, VPC Flow Log, or DNS log data. Amazon GuardDuty (D) is not correct because it is a threat-detection service that consumes logs to generate findings, not a service for centralizing and storing the raw logs themselves.

Exam trap

Candidates may mistakenly choose CloudTrail (Organization Trail) because it centralizes CloudTrail logs, but it does not apply to the other log types. The correct central aggregation services are CloudWatch Logs and S3.

206
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to centrally monitor all API calls made in the member accounts. The team wants to ensure that all CloudTrail logs are delivered to a centralized S3 bucket in the management account. Which configuration should the security team implement?

A.Configure CloudWatch cross-account subscription to send logs from member accounts to the management account.
B.Enable CloudTrail in each member account and configure each trail to deliver logs to the same S3 bucket.
C.Create an organization trail in the management account with the S3 bucket in the management account.
D.Use Amazon S3 replication to copy logs from member account buckets to the management account bucket.
AnswerC

An organization trail is created only in the management account (or delegated administrator) and automatically applies to all accounts in the AWS organization, with no per-account setup required. It records management events across all accounts, including AWS Organizations control-plane operations like CreateAccount and AttachPolicy, and delivers the aggregated logs to a single S3 bucket in the management account. This is the correct way to centrally collect CloudTrail logs for governance and compliance.

Why this answer

AWS Organizations supports creating an organization trail in the management account that automatically applies to all member accounts. This ensures that all API calls from every account in the organization are logged and delivered to a centralized S3 bucket in the management account without needing to configure individual trails or manage cross-account permissions manually.

Exam trap

The trap here is that candidates often think they need to configure CloudTrail in each member account individually (Option B) or use S3 replication (Option D), missing the fact that AWS Organizations provides a native, centralized organization trail feature that automatically applies to all accounts.

How to eliminate wrong answers

Option A is wrong because CloudWatch cross-account subscription is designed for streaming log data to a central account for real-time monitoring, not for delivering CloudTrail logs to an S3 bucket; CloudTrail logs are stored in S3, not CloudWatch Logs by default. Option B is wrong because while it would technically deliver logs to the same S3 bucket, it requires manual configuration in each member account, does not leverage the centralized management capabilities of AWS Organizations, and can lead to permission issues or inconsistent configurations. Option D is wrong because S3 replication copies objects between buckets after they are written, but it introduces complexity, additional costs, and potential delays; it does not provide a native, centralized way to ensure all CloudTrail logs are delivered directly to the management account bucket without first storing them in member account buckets.

207
Multi-Selecteasy

A security engineer needs to collect and analyze operating system logs from EC2 instances. Which TWO services are required?

Select 2 answers
A.Amazon VPC Flow Logs
B.AWS Config
C.Amazon CloudWatch Logs
D.Amazon CloudWatch Agent
E.AWS CloudTrail
AnswersC, D

Amazon CloudWatch Logs is the correct central service for storing, monitoring, and analyzing OS logs collected from EC2 instances. It receives log data forwarded by the CloudWatch agent and organizes it into log groups and log streams, enabling real-time searching, metric filters, alarms, and querying with Logs Insights. Once OS logs are ingested, the engineer can use CloudWatch Logs to correlate events across instances, build dashboards, and set automated alerts, making it the core analysis platform for the collected logs.

Why this answer

Amazon CloudWatch Logs is the service that stores, monitors, and accesses operating system logs from EC2 instances. However, to collect and send those logs to CloudWatch Logs, you must install and configure the Amazon CloudWatch Agent on the EC2 instances. The CloudWatch Agent can collect logs from the OS (e.g., /var/log/syslog, /var/log/messages, Windows Event Log) and forward them to CloudWatch Logs for analysis.

Exam trap

The trap here is that candidates often confuse Amazon CloudWatch Logs (the destination service) with the CloudWatch Agent (the collection mechanism), thinking that CloudWatch Logs alone can pull logs from EC2 instances without needing an agent installed on the OS.

208
Multi-Selectmedium

Which THREE actions can be performed using AWS CloudTrail to enhance security monitoring?

Select 3 answers
A.Monitor SSH login attempts to EC2 instances.
B.Detect unauthorized API calls by analyzing CloudTrail logs.
C.Monitor changes to S3 bucket policies.
D.Capture all network traffic to and from EC2 instances.
E.Track changes to IAM user permissions.
AnswersB, C, E

CloudTrail delivers a record of every AWS API call, capturing the requesting principal, source IP, user agent, and request parameters, regardless of whether the call succeeded or was denied. Security teams can analyze these logs to detect unauthorized attempts, such as AccessDenied errors, calls from unexpected identities or regions, or anomalous API patterns. This detective capability is often combined with Amazon GuardDuty or Athena queries to surface suspicious activity that would otherwise go unnoticed.

Why this answer

AWS CloudTrail records API activity in your AWS account, including calls to IAM, S3, and other services. By analyzing CloudTrail logs, you can detect unauthorized API calls (Option B) because every API call is logged with details such as the identity, source IP, and timestamp, enabling security monitoring and alerting on suspicious actions.

Exam trap

The trap here is that candidates often confuse CloudTrail's scope with OS-level or network-level monitoring, mistakenly thinking it can capture SSH logins or network traffic, when in fact it only records AWS API calls.

209
MCQeasy

A security engineer needs to monitor AWS account activity for suspicious API calls, such as disabling AWS CloudTrail or deleting an AWS Config recorder. The engineer wants to receive near-real-time alerts when such events occur. Which AWS service should the engineer use to meet these requirements?

A.Amazon CloudWatch Events (now Amazon EventBridge)
B.AWS CloudTrail Insights
C.Amazon GuardDuty
D.AWS Security Hub
AnswerA

Amazon EventBridge can match events from AWS CloudTrail and trigger alerts via Amazon SNS or other targets. You can create a rule that matches specific API calls like StopLogging or DeleteConfigurationRecorder and sends a notification. This provides near-real-time alerts for the specified events.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) can monitor AWS CloudTrail logs for specific API calls and trigger alerts in near real-time. By creating an event rule that matches events like StopLogging or DeleteConfigurationRecorder, the engineer can receive immediate notifications. This directly meets the requirement.

Exam trap

The trap here is confusing threat detection services like GuardDuty with event-driven monitoring services like EventBridge.

210
MCQmedium

A security engineer is reviewing AWS CloudTrail logs and notices a large number of DeleteBucket API calls from an unfamiliar IAM role. The engineer wants to automatically notify the security team when similar suspicious API activity occurs in the future. The notification must be sent within minutes and should include details such as the IAM role and the bucket name. Which solution should the engineer implement?

A.Enable CloudTrail Insights and configure an Amazon CloudWatch alarm on the Insights metric to send notifications via Amazon SNS.
B.Use Amazon GuardDuty to monitor for S3 bucket deletion activity and configure GuardDuty findings to send notifications via Amazon SNS.
C.Configure AWS Config to record configuration changes for S3 buckets and use an AWS Config rule to trigger an Amazon SNS notification when a bucket is deleted.
D.Create an Amazon EventBridge rule that matches AWS API calls via CloudTrail, filter for the DeleteBucket event, and route the event to an Amazon SNS topic that notifies the security team.
AnswerD

EventBridge can match CloudTrail management events in near real time. By creating a rule that filters for DeleteBucket events, you can route the full event JSON to an SNS topic, which sends email or SMS to the security team. This provides rapid notification and includes details like the IAM role and bucket name in the event payload.

Why this answer

EventBridge can match CloudTrail management events and filter for specific API calls like DeleteBucket. Routing the event to SNS provides near real-time notification with the full event details, including the IAM role and bucket name. This is the most direct and low-latency solution for the requirement.

Exam trap

The trap here is thinking that GuardDuty or CloudTrail Insights will alert on specific API calls, when they are designed for anomaly detection rather than exact event matching.

211
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to analyze web request logs to identify potential SQL injection attacks. Which AWS service should be used to collect and analyze the ALB access logs?

A.VPC Flow Logs
B.AWS WAF
C.Amazon CloudWatch Logs Insights
D.Amazon Athena
AnswerD

Amazon Athena is the correct choice because it allows you to query ALB access logs directly in S3 using standard SQL without needing to load or transform the data. You can create an external table over the gzipped log files, then run SQL queries that look for SQL injection indicators such as 'OR 1=1', suspicious quotes, or UNION SELECT statements in the request and URL fields. This serverless, on-demand query engine is ideal for post-incident forensic analysis of historical access logs stored in S3.

Why this answer

Amazon Athena is the correct service because it allows you to query ALB access logs stored in Amazon S3 directly using standard SQL, without needing to load or transform the data. This makes it ideal for ad-hoc analysis of web request logs to identify patterns like SQL injection attempts, as you can run complex queries against the raw log data.

Exam trap

The trap here is that candidates often confuse AWS WAF's real-time blocking capability with the need for post-incident log analysis, leading them to choose WAF instead of recognizing that Athena is the appropriate service for querying stored ALB access logs.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not include application-layer details like HTTP request URIs or payloads needed to detect SQL injection. Option B is wrong because AWS WAF is a web application firewall that can block SQL injection attacks in real time, but it does not provide a mechanism to analyze historical ALB access logs; it operates on incoming traffic, not stored logs. Option C is wrong because Amazon CloudWatch Logs Insights is designed to query CloudWatch Logs, but ALB access logs are not automatically sent to CloudWatch Logs; they are delivered to S3, and CloudWatch Logs Insights cannot directly query S3 data without additional configuration like a subscription filter or Lambda.

212
MCQeasy

A company is required to retain CloudTrail logs for 7 years for compliance. Which solution meets this requirement with the LEAST operational overhead?

A.Store logs in CloudWatch Logs with a retention period of 7 years.
B.Configure CloudTrail to automatically delete logs older than 7 years.
C.Use an AWS Lambda function to delete logs older than 7 years.
D.Configure an S3 Lifecycle policy to transition logs to S3 Glacier Deep Archive after 90 days and expire after 7 years.
E.Export logs to AWS Snowball for offline archival.
AnswerD

S3 Glacier Deep Archive satisfies the seven-year retention mandate at the lowest storage cost, while the lifecycle policy automates both the transition and the expiry date. This removes manual intervention entirely, delivering the least operational overhead compared with custom archival pipelines or third-party tooling.

Why this answer

It uses an S3 Lifecycle policy to automatically transition CloudTrail logs to S3 Glacier Deep Archive after 90 days (reducing storage costs) and then expire (delete) the objects after 7 years, meeting the retention requirement with zero ongoing operational effort. This is the least operational overhead solution as it is fully automated within S3, requiring no custom code, manual intervention, or additional services.

Exam trap

The trap here is that candidates may think CloudTrail itself manages log retention (Option B) or that CloudWatch Logs is the simplest option (Option A), but AWS explicitly requires you to manage retention at the destination, and S3 Lifecycle policies are the native, automated, and lowest-overhead solution for long-term archival and deletion.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs has a maximum retention period of 10 years, but storing 7 years of CloudTrail logs in CloudWatch Logs incurs high ingestion and storage costs compared to S3, and requires manual or automated export for long-term archival, increasing operational overhead. Option B is wrong because CloudTrail does not have a built-in feature to automatically delete logs older than a specified period; log retention and deletion must be managed at the destination (e.g., S3 Lifecycle policies). Option C is wrong because using a Lambda function to delete logs older than 7 years introduces custom code, potential execution failures, and ongoing maintenance, which is higher operational overhead than a native S3 Lifecycle policy.

Option E is wrong because exporting logs to AWS Snowball for offline archival is designed for large-scale data transfer and physical shipping, not for routine 7-year retention, and it adds significant operational overhead and latency.

213
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team notices that some PutObject API calls are not appearing in the CloudTrail logs. The S3 bucket in question has server access logging enabled. What is the MOST likely reason for the missing CloudTrail events?

A.CloudTrail was not configured to log data events for S3.
B.Server access logs are interfering with CloudTrail.
C.The PutObject calls were made via the AWS Management Console.
D.The S3 bucket policy denies CloudTrail from logging.
AnswerA

CloudTrail trails capture management events by default, but S3 data events such as PutObject require explicit enablement through trail configuration. Without adding S3 object-level data events for the bucket (or a prefix), PutObject requests will not appear in the CloudTrail history.

Why this answer

CloudTrail logs are categorized into management events and data events. By default, CloudTrail only logs management events (e.g., CreateBucket, DeleteBucket). Data events, such as S3 object-level operations like PutObject, must be explicitly enabled in the CloudTrail trail configuration.

Since the security team sees missing PutObject calls, the most likely cause is that CloudTrail was not configured to log S3 data events.

Exam trap

The trap here is that candidates often confuse CloudTrail management events (which are logged by default) with data events (which require explicit configuration), leading them to overlook the need to enable S3 data event logging.

How to eliminate wrong answers

Option B is wrong because server access logs are separate from CloudTrail logs; they are stored in a different S3 bucket and do not interfere with CloudTrail's ability to capture API calls. Option C is wrong because PutObject calls made via the AWS Management Console still generate S3 API calls that CloudTrail can capture if data events are enabled; the console does not bypass CloudTrail logging. Option D is wrong because an S3 bucket policy that denies CloudTrail from logging would affect CloudTrail's ability to deliver log files to the bucket, not prevent CloudTrail from capturing the PutObject events themselves.

214
MCQmedium

A security analyst needs to review all failed SSH login attempts to an EC2 instance. Which combination will provide this information?

A.Use AWS Config to record EC2 instance configuration and check for security group changes.
B.Install the CloudWatch agent on the EC2 instance to collect /var/log/secure and stream to CloudWatch Logs.
C.Enable AWS CloudTrail and search for EC2-related events.
D.Enable VPC Flow Logs for the subnet and query the logs in CloudWatch Logs Insights for rejected traffic on port 22.
AnswerB

The CloudWatch agent (or unified agent) runs inside the EC2 instance and can tail local log files such as /var/log/secure on Amazon Linux/RHEL (or /var/log/auth.log on Ubuntu), streaming them to CloudWatch Logs. The sshd daemon writes entries like 'Failed password for ...' to this file for every failed authentication attempt. Reviewing the collected log group in CloudWatch Logs Insights, for example with a query filtering on 'Failed password', directly reveals the failed SSH login attempts and their source IPs.

Why this answer

The CloudWatch agent installed on the EC2 instance can collect OS-level logs such as /var/log/secure (on Linux), which contains detailed records of SSH authentication attempts, including failed logins. By streaming these logs to CloudWatch Logs, the analyst can query and review all failed SSH login attempts at the application layer. Options A, C, and D capture network-level metadata but do not provide information about authentication failures after a successful TCP connection.

Exam trap

The key pitfall is interpreting 'failed SSH login attempts' as network-level rejections rather than OS-level authentication failures. VPC Flow Logs show only accepted or rejected network traffic, not login outcomes. The correct approach is to collect system authentication logs via the CloudWatch agent.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes, not network traffic or login attempts; it cannot capture failed SSH login events. Option B is wrong because /var/log/secure logs successful and failed authentication attempts at the OS level, but the question asks for 'failed SSH login attempts' as seen from the network perspective, and the CloudWatch agent collects OS logs, not network-level rejected packets. Option C is wrong because AWS CloudTrail records API calls made to the AWS management plane, not network traffic or SSH login attempts to the EC2 instance itself.

215
MCQmedium

A company needs to centralize security logs from multiple AWS accounts and on-premises servers. The logs must be encrypted at rest and stored in a cost-effective manner. Which solution meets these requirements?

A.Use Amazon S3 Glacier with Vault Lock
B.Use Amazon S3 with server-side encryption (SSE-S3)
C.Use Amazon Kinesis Data Firehose to deliver logs to Amazon Redshift
D.Use Amazon CloudWatch Logs with KMS encryption
AnswerB

Amazon S3 with SSE-S3 is the correct choice because S3 provides a cost-effective, highly durable object store optimized for high-volume log ingestion and retention, and SSE-S3 automatically encrypts each object with strong AES-256 encryption managed by AWS. S3 integrates natively with CloudTrail, VPC Flow Logs, and AWS Config to centralize logs from multiple accounts, and it supports lifecycle policies that can later transition older logs to S3 Glacier for further cost reduction. The encrypted-at-rest capability satisfies compliance requirements without the operational overhead of managing customer keys.

Why this answer

Amazon S3 with server-side encryption (SSE-S3) meets the requirements because it provides encryption at rest using AES-256, is cost-effective for log storage, and can centralize logs from multiple AWS accounts and on-premises servers via S3 Cross-Account Access and the S3 API. SSE-S3 is fully managed by AWS, requiring no additional key management overhead, and S3's lifecycle policies can transition older logs to lower-cost tiers like S3 Glacier for further cost savings.

Exam trap

The trap here is that candidates often choose Amazon CloudWatch Logs with KMS encryption (Option D) because it seems like a natural fit for log management, but they overlook the cost implications and the requirement for cost-effective storage, which S3 with SSE-S3 addresses more efficiently.

How to eliminate wrong answers

Option A is wrong because Amazon S3 Glacier with Vault Lock is designed for long-term archival and compliance, not for active log ingestion and retrieval, and it lacks the flexibility for centralized log aggregation from multiple sources. Option C is wrong because Amazon Kinesis Data Firehose delivering to Amazon Redshift is optimized for real-time analytics and data warehousing, not for cost-effective long-term log storage, and Redshift is significantly more expensive per GB than S3 for storing raw logs. Option D is wrong because Amazon CloudWatch Logs with KMS encryption is a viable option for log storage but is generally more expensive than S3 for large volumes of logs, and it does not natively support direct ingestion from on-premises servers without additional agents or configurations.

216
MCQeasy

A security engineer wants to capture all DNS queries made by EC2 instances to detect potential data exfiltration. Which AWS service should be used to log the DNS requests?

A.Use Route 53 Resolver DNS Firewall with query logging
B.Use Amazon GuardDuty
C.Enable VPC Flow Logs
D.Enable AWS CloudTrail
AnswerA

Route 53 Resolver DNS Firewall query logging captures every DNS query that instances resolve through the Amazon-provided VPC resolver, publishing records to CloudWatch Logs, S3, or Kinesis Data Firehose. This satisfies the requirement to log all EC2 DNS requests for exfiltration detection, since instances use that resolver by default.

Why this answer

Route 53 Resolver DNS Firewall with query logging is the correct choice because it is specifically designed to log all DNS queries made by EC2 instances that use the Route 53 Resolver. This service captures the domain names being queried, the source IP, and the response, enabling detection of DNS-based data exfiltration (e.g., DNS tunneling). It integrates directly with the VPC's DNS resolver, ensuring all outbound DNS traffic from EC2 instances is logged without additional agents.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show IP-level metadata) with DNS query logs, not realizing that DNS exfiltration requires the actual domain names being queried, which only DNS-specific logging provides.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS logs from Route 53 Resolver DNS Firewall or other sources, but it does not itself capture or log raw DNS queries; it relies on existing logs. Option C is wrong because VPC Flow Logs capture metadata about IP traffic (source/destination IP, ports, protocol) but do not log the actual DNS query names or payloads, making them insufficient for detecting DNS exfiltration. Option D is wrong because AWS CloudTrail logs API calls to AWS services (e.g., Route 53 API calls) but does not capture the DNS queries made by EC2 instances to external domains.

217
Multi-Selecteasy

A company wants to monitor unauthorized API calls in their AWS account. Which TWO AWS services can provide real-time alerting on such events?

Select 2 answers
A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Trusted Advisor
E.Amazon Inspector
AnswersB, C

CloudTrail records every API call as a management event, capturing the identity, source IP and error code. Filtering for AccessDenied errors lets you detect unauthorised calls, and delivering trails to CloudWatch Logs enables real-time metric filters and alarms.

Why this answer

AWS CloudTrail (B) is correct because it records every API call made in the account as management and data events, and when combined with CloudWatch Logs metric filters and alarms it delivers real-time alerting on unauthorized or suspicious API activity. Amazon GuardDuty (C) is correct because it continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence and machine learning to detect anomalous or unauthorized API calls and generate findings in near real time. AWS Config (A) is not designed for real-time alerting on API calls; it evaluates resource configuration compliance and records configuration changes, not API invocation events.

AWS Trusted Advisor (D) provides periodic best-practice checks and recommendations, not real-time monitoring of API activity. Amazon Inspector (E) is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not API call monitoring.

Exam trap

Candidates often assume that only CloudTrail can monitor unauthorized API calls because it logs all API events, overlooking GuardDuty's ability to detect suspicious API activity through anomaly detection and threat intelligence. Both services can provide real-time alerting on unauthorized API calls, but via different mechanisms: CloudTrail via CloudWatch alarms on specific API error codes, and GuardDuty via findings based on unusual API patterns.

218
Multi-Selectmedium

A security team needs to monitor for unauthorized API calls in their AWS account. Which TWO services can provide real-time alerts for such events?

Select 2 answers
A.Amazon CloudWatch Logs Insights
B.AWS CloudTrail with Amazon CloudWatch Events
C.Amazon VPC Flow Logs
D.AWS Config
E.Amazon GuardDuty
AnswersB, E

AWS CloudTrail captures the complete audit trail of API calls made to your account, including the identity, time, source IP, and request parameters. By integrating CloudTrail with Amazon CloudWatch Events, you can create rules that match specific API events—such as unauthorized or denied actions—and trigger immediate alerts via SNS, Lambda, or other targets in real time. CloudTrail delivers each API event as a JSON object, and CloudWatch Events helps filter those objects by fields like `errorCode` or `userIdentity` to detect suspicious activity. This combination is the recommended native mechanism for monitoring and reacting to unauthorized API calls.

Why this answer

B is correct because AWS CloudTrail logs all API calls, and by integrating CloudTrail with Amazon CloudWatch Events (now Amazon EventBridge), you can create event rules that trigger real-time alerts (e.g., via SNS or Lambda) for unauthorized API calls. This combination provides the necessary logging and immediate notification capability for security monitoring.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs Insights (a query tool) with real-time alerting, or they mistakenly think VPC Flow Logs can monitor API calls because they capture all traffic, but they only capture network flows, not application-level API events.

219
MCQhard

A company uses AWS CloudTrail and wants to ensure that log files are encrypted at rest and that access to the logs is logged. Which combination of S3 features should be enabled on the destination bucket?

A.S3 Transfer Acceleration and default encryption
B.MFA Delete and versioning
C.Default encryption and server access logging
D.S3 Object Lock and versioning
AnswerC

Default encryption on the destination S3 bucket automatically applies server-side encryption (SSE-S3, SSE-KMS, or SSE-C) to every CloudTrail log object, satisfying the encryption-at-rest requirement. Server access logging captures detailed records of every request made to the bucket, including the source IP, requester, and operation, which provides the needed audit trail of access to those logs. Together, these features ensure the CloudTrail logs are protected and their access activity is observable.

Why this answer

Enabling default encryption on the S3 bucket ensures that all CloudTrail log files are encrypted at rest using SSE-S3 or SSE-KMS, satisfying the encryption requirement. Enabling server access logging on the same bucket creates detailed records of every request made to the bucket, including who accessed the logs and from where, thus logging access to the logs themselves. This combination directly addresses both requirements: encryption at rest and access logging.

Exam trap

The trap here is that candidates often confuse server access logging with CloudTrail itself, thinking CloudTrail already logs access to the S3 bucket, but CloudTrail logs API calls to the bucket (e.g., PutObject), while server access logging captures every HTTP request at the object level, including reads and anonymous requests.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a feature for speeding up uploads over long distances using edge locations; it does not provide encryption at rest or log access to the bucket. Option B is wrong because MFA Delete adds an extra authentication factor for deleting objects and versioning protects against accidental overwrites, but neither feature encrypts data at rest nor logs access to the logs. Option D is wrong because S3 Object Lock prevents objects from being deleted or overwritten for a fixed time, and versioning maintains multiple versions of objects, but neither provides encryption at rest or access logging.

220
MCQmedium

A security engineer is troubleshooting why CloudTrail is not delivering logs to an S3 bucket. The bucket policy allows CloudTrail to write objects, and the trail is configured with the correct bucket name. However, no log files appear. What is the most likely cause?

A.The S3 bucket has an S3 Object Lock configuration that prevents writes.
B.The S3 bucket is in a different AWS Region from the trail.
C.CloudTrail is not enabled in the AWS Region where the S3 bucket resides.
D.The S3 bucket uses AWS KMS server-side encryption (SSE-KMS) and the KMS key policy does not grant CloudTrail permission to use the key.
AnswerD

When a destination bucket uses SSE-KMS, CloudTrail must have permission to call kms:GenerateDataKey for encrypting each log file and kms:Decrypt for delivering or reading those files. If the KMS key policy does not explicitly grant CloudTrail these actions, PutObject requests to the bucket will fail even if the bucket policy is correct. CloudTrail’s role also needs the appropriate KMS permissions in the trail’s advanced settings, but the key policy is the critical constraint here.

Why this answer

When CloudTrail is configured to deliver logs to an S3 bucket that uses SSE-KMS, CloudTrail must have explicit permission to use the KMS key for encrypting the log files. Even if the bucket policy allows CloudTrail to write objects, the KMS key policy must grant the `kms:GenerateDataKey` and `kms:Decrypt` actions to the CloudTrail service principal. Without these permissions, CloudTrail cannot encrypt the logs, and delivery fails silently—no log files appear.

Exam trap

The trap here is that candidates often focus only on the S3 bucket policy and overlook the separate KMS key policy requirement, assuming that SSE-KMS encryption is transparent to CloudTrail.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock, when configured, prevents object deletion or overwrite, but it does not prevent initial writes; CloudTrail can still create new log objects. Option B is wrong because CloudTrail can deliver logs to an S3 bucket in a different AWS Region; cross-region delivery is supported and not a cause of failure. Option C is wrong because CloudTrail is enabled in the region where the trail is created, not necessarily where the S3 bucket resides; the trail's region determines logging, not the bucket's region.

221
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to centrally monitor and analyze all CloudTrail logs from all accounts. The logs must be stored in a centralized S3 bucket with encryption and access logging enabled. Additionally, the team needs to detect anomalous API activity across accounts using machine learning. Which combination of services meets these requirements?

A.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; AWS Config to monitor API activity; S3 server access logs enabled.
B.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; Amazon Macie to detect anomalous API activity; S3 server access logs enabled.
C.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; Amazon Detective to analyze API activity; S3 server access logs enabled.
D.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption and S3 server access logs; Amazon GuardDuty enabled in all accounts.
AnswerD

CloudTrail captures every API call across all accounts and delivers a tamper-evident log to the centralized S3 bucket, with default encryption protecting it at rest. Amazon GuardDuty, enabled in all accounts, continuously analyzes CloudTrail events along with VPC Flow Logs and DNS logs using machine learning and threat intelligence to detect anomalies such as compromised credentials or unusual API sequences. S3 server access logs provide object-level request logging for the centralized bucket itself. Together these components deliver both comprehensive API activity logging and proactive ML-based anomaly detection across the organization.

Why this answer

It combines AWS CloudTrail for centralized log delivery to an S3 bucket with default encryption and server access logs, and Amazon GuardDuty, which uses machine learning to detect anomalous API activity across accounts. GuardDuty analyzes CloudTrail management events, VPC flow logs, and DNS logs to identify suspicious behavior, meeting the requirement for ML-based anomaly detection.

Exam trap

The trap here is confusing Amazon Detective as a proactive detection service when it is actually a reactive investigation tool that relies on findings from GuardDuty, not a standalone ML-based anomaly detector for API activity.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration compliance service that monitors resource changes, not API activity anomalies, and it does not use machine learning for detection. Option B is wrong because Amazon Macie is designed for data security and privacy, focusing on sensitive data discovery in S3, not for detecting anomalous API activity across accounts. Option C is wrong because Amazon Detective is a post-incident investigation tool that analyzes existing findings from GuardDuty, not a real-time ML-based anomaly detection service for API activity.

222
MCQhard

Refer to the exhibit. A security engineer is reviewing a CloudTrail event. What security concern does this event raise?

A.The user is revoking a security group rule.
B.The event is not being logged by CloudTrail.
C.The user is using the AWS root account.
D.The user is opening SSH access to the world.
AnswerD

The AuthorizeSecurityGroupIngress call is adding a rule allowing TCP port 22 (SSH) from CIDR 0.0.0.0/0. A CIDR of 0.0.0.0/0 represents all possible IPv4 addresses, meaning any host on the internet can attempt to connect to port 22 on the associated instances. This effectively exposes SSH to the world, which is a critical security risk because it invites brute-force attacks and unauthorized access attempts.

Why this answer

The CloudTrail event shows an AuthorizeSecurityGroupIngress API call with a CidrIp of 0.0.0.0/0 for port 22 (SSH). This opens SSH access to the entire internet, which is a severe security risk because it exposes the instance to brute-force attacks, unauthorized access, and potential compromise. The correct answer is D because this action directly violates the principle of least privilege and is a common misconfiguration.

Exam trap

The trap here is that candidates may focus on the fact that the event is logged (Option B) or the user identity (Option C), but the core security concern is the overly permissive inbound rule that grants unrestricted SSH access.

How to eliminate wrong answers

Option A is wrong because the event is an AuthorizeSecurityGroupIngress call, which adds a rule, not a RevokeSecurityGroupIngress call, which would remove a rule. Option B is wrong because the event is already being logged by CloudTrail, as evidenced by the JSON record provided; CloudTrail logs all API calls by default unless explicitly excluded. Option C is wrong because the user identity in the event shows an ARN with 'user/Admin', indicating an IAM user, not the root account (which would have 'root' in the ARN).

223
MCQeasy

A security engineer is configuring a multi-account CloudTrail setup. The above bucket policy is attached to the central logging bucket. Despite the policy, CloudTrail in the member account (123456789012) cannot deliver logs. What is the MOST likely issue?

A.The Principal should be the CloudTrail service principal of the member account.
B.The condition s3:x-amz-acl is not required; CloudTrail does not set that ACL.
C.The Action should be s3:PutObjectAcl instead of s3:PutObject.
D.The resource ARN must include the source account ID in the path.
AnswerB

CloudTrail delivers log files via the S3 `PutObject` API, but it does not set the `x-amz-acl` request header or the `bucket-owner-full-control` canned ACL unless the trail is explicitly configured for that behavior. If the bucket policy uses a `StringEquals` condition on `s3:x-amz-acl`, every PutObject request from CloudTrail will not match the condition and is denied before the write can occur. Removing that condition allows the PutObject action to succeed; use a condition on `aws:SourceArn` or `aws:SourceAccount` instead to scope the trust.

Why this answer

CloudTrail does not set the s3:x-amz-acl condition key when delivering log files to S3. The bucket policy incorrectly includes this condition, which causes the S3 authorization to fail because the condition key is not present in the CloudTrail PutObject request. Removing the condition or adjusting the policy to not require it resolves the delivery failure.

Exam trap

The trap here is that candidates assume the condition s3:x-amz-acl is always required for CloudTrail delivery, but CloudTrail does not set this condition key by default; the policy must match the actual request attributes, and misconfiguring conditions is a common cause of silent delivery failures.

How to eliminate wrong answers

Option A is wrong because the Principal in a bucket policy for cross-account CloudTrail delivery must be the CloudTrail service principal (cloudtrail.amazonaws.com) of the member account, not the member account itself; however, the issue here is the condition key, not the principal. Option C is wrong because CloudTrail uses s3:PutObject to deliver logs, not s3:PutObjectAcl; the ACL is set via the x-amz-acl header in the PutObject request, not a separate API call. Option D is wrong because the resource ARN in a CloudTrail bucket policy does not require the source account ID in the path; the ARN format is arn:aws:s3:::bucket-name/optional-prefix/*, and the source account is identified via the Principal or condition keys like s3:SourceAccount.

224
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team notices that some expected log entries are missing for actions performed by an IAM role assumed by an EC2 instance. The instance has the required permissions. What is the MOST likely cause of the missing log entries?

A.The EC2 instance is in a VPC that has a VPC endpoint for CloudTrail, but the endpoint policy denies logging.
B.CloudTrail is not logging read-only API calls by default; the trail must be configured to log read events.
C.CloudTrail trail is not configured to log data events for EC2.
D.The IAM role used by the EC2 instance has a permissions boundary that excludes cloudtrail:PutLogEvents.
AnswerB

CloudTrail's management event selector controls whether read-only API calls are captured; if the trail is configured as 'Write-only', then actions like `ec2:DescribeInstances` are omitted. Even though the console default for a new trail is to log both read and write events, an existing trail may have been changed to write-only, and that setting is a common cause of missing read activity. To record these calls, the trail must be explicitly set to log 'Read' or 'All' management events.

Why this answer

CloudTrail logs management events by default, but the trail can be configured to log only write events or only read events. If the trail is set to log only write events, read-only API calls (such as Describe* or Get* actions) made by the IAM role will not be recorded. Since the missing log entries are likely read operations, the lack of read event logging would result in missing entries.

Option B correctly identifies this scenario.

Exam trap

The trap is to assume that missing logs are due to IAM permissions boundaries, when in fact CloudTrail logs all API calls regardless of the caller's permissions. Instead, the issue is often a misconfiguration of the trail's logging scope (e.g., read events not logged).

How to eliminate wrong answers

Option A is wrong because a VPC endpoint for CloudTrail is used to send log data from CloudTrail to S3, not to log API calls; the endpoint policy would affect delivery, not the logging of actions performed by the EC2 instance. Option B is wrong because CloudTrail logs all API calls (both read and write) by default when management events are enabled; read-only events are not excluded unless the trail is explicitly configured to log only write events. Option C is wrong because the missing log entries are for management API calls (e.g., EC2 actions), not data events (e.g., S3 object-level operations); data events are an additional configuration and are not required for logging standard EC2 API actions.

225
MCQhard

A security engineer needs to monitor AWS API calls for potential unauthorized access. The engineer wants to be alerted when a specific IAM user performs a high-risk action like deleting a CloudTrail trail. What is the MOST efficient way to achieve this?

A.Configure CloudTrail to send logs to CloudWatch Logs and create a metric filter with an alarm.
B.Enable VPC Flow Logs and analyze with Elasticsearch.
C.Use Amazon Athena to query CloudTrail logs daily for the action.
D.Enable Amazon GuardDuty with a custom threat list.
E.Create a CloudWatch Events rule that matches the API call and sends an SNS notification.
AnswerE

A CloudWatch Events rule (now Amazon EventBridge) can define an event pattern that matches the exact API call, because CloudTrail delivers all AWS API events as CloudWatch Events in near real-time. When the event matches, the rule triggers an SNS topic to send a notification. This provides immediate, event-driven alerting without the delay of log aggregation, querying, or metric filters.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can directly capture AWS API calls from CloudTrail in near real-time. By creating a rule that matches the specific API call (e.g., `DeleteTrail`) from a specific IAM user, you can trigger an SNS notification instantly without the latency or cost of log shipping, metric filters, or periodic queries. This is the most efficient method for real-time alerting on specific API actions.

Exam trap

The trap here is that candidates often default to CloudTrail + CloudWatch Logs + metric filters (Option A) because it's a common pattern, but they overlook that CloudWatch Events provides a simpler, lower-latency, and more cost-effective solution for real-time alerting on specific API calls without the overhead of log ingestion and metric evaluation.

How to eliminate wrong answers

Option A is wrong because while CloudTrail logs to CloudWatch Logs with a metric filter and alarm can work, it introduces unnecessary latency and complexity (log delivery, metric evaluation) compared to a direct CloudWatch Events rule, making it less efficient for real-time alerting. Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols), not AWS API calls like `DeleteTrail`, so they are completely irrelevant for monitoring IAM user actions. Option C is wrong because using Athena to query CloudTrail logs daily is a batch, retrospective approach that cannot provide real-time alerts; it is inefficient for immediate detection of unauthorized access.

Option D is wrong because Amazon GuardDuty with a custom threat list is designed to detect malicious activity based on threat intelligence and network anomalies, not to trigger alerts on specific API calls from a known IAM user; it does not natively support event-driven alerting for individual API actions.

← PreviousPage 3 of 4 · 250 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Logging and Monitoring questions.