Courseiva

CCNA Threat Detection and Incident Response Questions

75 of 215 questions · Page 2/3 · Threat Detection and Incident Response · Answers revealed

76
MCQhard

A company runs a web application on an Auto Scaling group of EC2 instances behind an Application Load Balancer. The application stores user session data in an ElastiCache Redis cluster. The security team receives an alert from GuardDuty that one of the EC2 instances is communicating with a known command-and-control (C2) IP address. The instance ID is i-0a1b2c3d4e5f. The security engineer needs to contain the threat immediately while preserving the instance for forensic analysis. Which course of action should the security engineer take?

A.Apply a new security group that denies all inbound and outbound traffic to the instance.
B.Remove the security group from the Auto Scaling group to isolate the instance.
C.Terminate the EC2 instance immediately to stop the communication.
D.Create an AMI of the instance for forensic analysis and then terminate the instance.
AnswerA

Applying a new security group that denies all inbound and outbound traffic immediately severs the instance's network path at the hypervisor, cutting off the C2 server connection without killing the process or losing memory artifacts. Because security group changes are applied instantly across the VPC, this containment step is faster than OS-level firewall rules and avoids tipping off the attacker. The instance remains powered on, allowing you to capture a memory dump and disk image for forensic analysis before any restoration or termination.

Why this answer

Applying a new security group that denies all inbound and outbound traffic immediately stops the C2 communication at the network layer without destroying the instance. This preserves the instance for forensic analysis (e.g., memory dump, disk imaging) while containing the threat. The security group acts as a virtual firewall, and changing it is a non-destructive, reversible action that can be applied directly to the instance even if it is part of an Auto Scaling group.

Exam trap

The trap here is that candidates often choose to terminate the instance (Option C) thinking it is the fastest containment, but they overlook the critical requirement to preserve the instance for forensic analysis, which termination destroys.

How to eliminate wrong answers

Option B is wrong because removing the security group from the Auto Scaling group does not isolate the instance; the instance retains its existing security group(s) and continues to communicate. Option C is wrong because terminating the instance destroys the forensic evidence (e.g., volatile memory, running processes, disk state) and prevents further analysis. Option D is wrong because creating an AMI takes time and does not immediately stop the C2 communication; the instance remains active and can continue exfiltrating data or receiving commands during the AMI creation process.

77
MCQhard

A security engineer is configuring AWS CloudWatch Logs to monitor for suspicious activity. They want to create a metric filter that detects when an IAM user calls the `iam:CreateAccessKey` API. The engineer writes the following filter pattern: `{ ($.eventName = "CreateAccessKey") }`. After testing, the filter does not trigger. What is the most likely reason?

A.The filter pattern syntax is incorrect; it should use square brackets.
B.The metric filter is not associated with the correct log group.
C.CloudWatch Logs does not support metric filters for CloudTrail logs.
D.The filter pattern does not include the eventSource field, so it might match events from other services.
AnswerB

The most likely cause is that the metric filter is attached to a different log group than the one receiving the CloudTrail CreateAccessKey events. Metric filters evaluate only log data that arrives in the specific log group they are configured on; if the CloudTrail trail streams to another log group in another account or region, or the filter is created under the wrong log group name, the pattern never sees the relevant events. Verify the trail's destination log group and that the filter is assigned there.

Why this answer

The filter pattern `{ ($.eventName = "CreateAccessKey") }` is syntactically correct and will match any CloudTrail event with eventName CreateAccessKey, regardless of service. The most likely reason the filter does not trigger is that the metric filter is not associated with the correct log group, or the log group does not contain CloudTrail events from IAM. A missing eventSource field does not prevent the filter from working; it would simply match events from any service, which could cause false positives, but not a failure to trigger.

Exam trap

Candidates often focus on filter pattern syntax or missing fields when the filter doesn't trigger, but the most common cause is misconfiguration of the metric filter's association to the log group. Always verify the log group contains the expected CloudTrail events and that the metric filter is correctly linked.

How to eliminate wrong answers

Option A is wrong because the filter pattern syntax `{ ($.eventName = "CreateAccessKey") }` is correct for CloudWatch Logs metric filters; square brackets are not used in metric filter patterns (they are used in CloudWatch Logs Insights queries). Option B is wrong because the question states the filter does not trigger after testing, implying it was associated with a log group, and the issue is with the pattern itself, not the association. Option C is wrong because CloudWatch Logs fully supports metric filters for CloudTrail logs, which is a common use case for monitoring API activity.

78
MCQmedium

During an incident response, a security engineer needs to preserve the state of an EC2 instance's root volume for forensic analysis. The instance is still running. Which action should be taken to ensure the data is preserved without altering it?

A.Stop the instance and then create an AMI.
B.Create a snapshot of the root volume.
C.Use dd if=/dev/xvda over SSH to copy the volume.
D.Detach the root volume and attach it to a forensics instance.
AnswerB

A snapshot is a point-in-time, crash-consistent copy of the EBS root volume that preserves the current on-disk state without stopping or detaching the instance. Taking a snapshot is the standard forensic first step because it is non-intrusive, does not trigger shutdown scripts, and keeps the original volume intact for later analysis while the snapshot can be inspected on a separate examination instance.

Why this answer

Creating a snapshot of the root volume is the correct action because it captures a point-in-time, crash-consistent copy of the volume's data without requiring the instance to be stopped or the volume to be detached. This preserves the current state of the running instance for forensic analysis while ensuring the data is not altered by the snapshot process itself, as AWS snapshots are read-only and do not modify the source volume.

Exam trap

The trap here is that candidates may think stopping the instance (Option A) is necessary to ensure data consistency, but they overlook that stopping alters the system state and that a snapshot of a running instance is still a valid, unaltered point-in-time copy for forensic purposes.

How to eliminate wrong answers

Option A is wrong because stopping the instance changes its state (e.g., flushes memory, stops processes) and may alter or lose volatile data that is critical for forensic analysis; creating an AMI from a stopped instance also introduces additional metadata and is not a direct, unaltered copy of the root volume. Option C is wrong because using dd over SSH to copy the root device (/dev/xvda) while the instance is running will result in an inconsistent copy due to ongoing writes, and it modifies the source volume by reading it, potentially triggering forensic concerns about data integrity and chain of custody. Option D is wrong because detaching the root volume from a running instance forces an immediate stop of the instance (since the root volume is required for operation), which alters the system state and may cause data loss or corruption; attaching it to a forensics instance then introduces the risk of write operations to the volume.

79
MCQmedium

A security engineer is setting up automated incident response for a compromised EC2 instance. The engineer wants to isolate the instance immediately upon detection of a GuardDuty finding. Which AWS service can be used to automatically trigger a Lambda function that modifies the instance's security group?

A.AWS Step Functions
B.Amazon Inspector
C.Amazon CloudWatch Events
D.AWS Config
AnswerC

Amazon CloudWatch Events (also known as Amazon EventBridge) is the native service that GuardDuty uses to emit findings as events. You create an event rule with a pattern that matches fields like the finding type or severity, and set a Lambda function as the target. This rule can invoke Lambda in near real time whenever a qualifying GuardDuty finding is generated, making it the correct foundational service for automated incident response.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can be configured with a rule that matches specific GuardDuty finding events. When a finding is detected, the rule triggers a Lambda function that can modify the EC2 instance's security group to isolate it, for example by removing all inbound rules or replacing the group with a restrictive one. This provides the automated, event-driven response required.

Exam trap

The trap here is that candidates may confuse Amazon Inspector (a vulnerability scanner) with GuardDuty (a threat detection service), or assume AWS Config's compliance rules can react to security findings, when in fact only CloudWatch Events/EventBridge provides the direct event-driven trigger for GuardDuty findings.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service that coordinates multiple AWS services, but it is not directly triggered by GuardDuty findings; it would require an intermediary like CloudWatch Events to start the workflow. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposure, not a real-time event trigger for incident response actions. Option D is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking changes, but it cannot directly trigger a Lambda function in response to a GuardDuty finding; it uses rules that evaluate configuration changes, not security findings.

80
MCQhard

A company uses AWS CloudTrail to log all API calls. During an incident investigation, the security team needs to identify who deleted an S3 bucket. CloudTrail logs are stored in a centralized S3 bucket with server-side encryption using AWS KMS. Which additional step is required to ensure the CloudTrail logs can be queried quickly for this investigation?

A.Enable CloudTrail Lake
B.Stream logs to CloudWatch Logs and use CloudWatch Logs Insights
C.Use Amazon Athena with a table defined over the S3 bucket
D.Enable Amazon GuardDuty
AnswerC

Amazon Athena can query CloudTrail logs stored in S3 by defining a table over the bucket using the CloudTrail SerDe, with columns matching the JSON event structure and partitions for date/hour. The table is either created manually via a DDL statement or automatically by the 'Create Athena table' option in the CloudTrail console. Athena then runs standard SQL directly on the compressed log objects without moving or transforming the data, making it the simplest serverless way to search all API calls.

Why this answer

Amazon Athena allows you to query CloudTrail logs directly in S3 using standard SQL without needing to move or transform the data. Since the logs are already in a centralized S3 bucket, defining a table over that location enables fast, ad-hoc queries to identify the specific DeleteBucket event, including who performed it and when. This approach is cost-effective and avoids additional streaming or storage costs.

Exam trap

The trap here is that candidates often assume CloudTrail logs must be streamed to CloudWatch Logs for querying, but Athena provides a more direct and cost-effective solution for querying historical logs stored in S3 without additional streaming overhead.

How to eliminate wrong answers

Option A is wrong because CloudTrail Lake is a managed data lake for CloudTrail logs that requires ingesting logs into a separate event data store, which adds cost and complexity; it is not necessary for querying existing logs in S3. Option B is wrong because streaming logs to CloudWatch Logs incurs additional costs and latency, and CloudWatch Logs Insights is designed for real-time monitoring of operational metrics, not for deep forensic analysis of historical S3 bucket deletions. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for anomalies, but it does not provide a direct query interface to search for specific historical events like who deleted an S3 bucket.

81
MCQeasy

A security engineer is investigating a potential data breach. The engineer needs to identify which IAM user accessed a specific S3 object and when. Which AWS service should the engineer use?

A.AWS Config
B.Amazon S3 server access logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the correct answer because it is the only service that records API activity as data events for S3, and by default (when data events are enabled) it captures the exact IAM user principal, source IP address, user agent, request parameters, and timestamp for actions like GetObject and PutObject. This enables the security engineer to create a complete audit trail of who accessed a specific S3 object and when, which is precisely what is needed in a breach investigation. CloudTrail also integrates with CloudWatch Logs for alerting and can deliver to a separate S3 bucket or a security data lake, but its core value here is the user-level accountability it provides for object-level operations.

Why this answer

AWS CloudTrail is the correct service because it records API activity for all AWS services, including S3 object-level operations such as GetObject, PutObject, and DeleteObject. By enabling data events on the specific S3 bucket, CloudTrail logs the IAM user, source IP, timestamp, and the exact object key accessed, providing the precise identity and time needed for breach investigation.

Exam trap

The trap here is that candidates confuse S3 server access logs (which show HTTP-level requests but lack IAM user identity) with CloudTrail (which captures the full IAM user context via the AWS API), leading them to incorrectly select Amazon S3 server access logs.

How to eliminate wrong answers

Option A is wrong because AWS Config evaluates resource configurations and compliance rules, not API-level access logs; it cannot show which user accessed a specific S3 object or when. Option B is wrong because Amazon S3 server access logs record HTTP requests to the bucket at the object level, but they log the requester's AWS account ID or anonymous identifier, not the IAM user ARN, making it impossible to tie the access to a specific IAM user. Option D is wrong because Amazon CloudWatch Logs is a centralized log storage and monitoring service, not a source of API activity logs; it can ingest CloudTrail logs but does not generate the access records itself.

82
MCQeasy

A security engineer notices that an IAM role used by an EC2 instance is generating a large number of API calls to an S3 bucket that is not part of the company's account. Which AWS service should be used to detect and alert on this suspicious activity?

A.AWS CloudTrail
B.Amazon Inspector
C.AWS Config
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty continuously analyses CloudTrail management and S3 data events, VPC Flow Logs and DNS logs using threat intelligence and machine learning to surface anomalous behaviour. It specifically detects EC2 instance credential compromise and calls to unrecognised or malicious S3 buckets, satisfying the requirement to detect and alert on this suspicious cross-account activity.

Why this answer

Amazon GuardDuty is the correct service because it uses machine learning and anomaly detection to analyze AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs. It can detect unusual API calls, such as an EC2 instance role making a high volume of requests to an S3 bucket outside the company's account, which is a classic indicator of compromised credentials or data exfiltration. GuardDuty generates findings and can integrate with Amazon CloudWatch Events to trigger alerts or automated remediation.

Exam trap

The trap here is that candidates often confuse CloudTrail (which logs the activity) with GuardDuty (which analyzes and alerts on the activity), leading them to select CloudTrail because they think logging alone is sufficient for detection, but GuardDuty is the service specifically designed for threat detection and alerting.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail is a logging service that records API calls, but it does not perform real-time detection, analysis, or alerting on suspicious activity; it only provides raw logs that require separate monitoring and analysis. Option B is wrong because Amazon Inspector is a vulnerability management service that assesses EC2 instances for software vulnerabilities and unintended network exposure, not for detecting anomalous API call patterns or cross-account data access. Option C is wrong because AWS Config is a resource inventory and compliance service that evaluates resource configurations against rules, but it does not analyze API call patterns or detect anomalous behavior like unusual S3 access from an IAM role.

83
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team wants to centralize threat detection across all accounts. They enable Amazon GuardDuty in the management account and intend to use delegated administrator functionality. However, they find that GuardDuty is not detecting threats in member accounts. What is the most likely cause?

A.GuardDuty requires an S3 bucket in each account to store findings.
B.GuardDuty is not enabled in the member accounts. The security team must invite member accounts or use the delegated administrator to enable GuardDuty in all accounts.
C.GuardDuty only monitors the management account's resources, not member accounts.
D.GuardDuty does not support delegated administrator for AWS Organizations.
AnswerB

The correct issue is that GuardDuty has not been enabled for the member accounts. When you set up AWS Organizations, you still need to explicitly enable GuardDuty in the management account and then either send email invitations to each member account or, preferably, designate a delegated administrator who can use the `EnableOrganizationAdminAccount` API to activate GuardDuty for every account in the organization. Without this explicit step, member accounts remain unmonitored and cannot produce GuardDuty findings.

Why this answer

Amazon GuardDuty must be enabled in each member account to detect threats in those accounts. When using the delegated administrator model, the security team can enable GuardDuty across all accounts programmatically via the delegated administrator API, but they must explicitly perform this action. Simply enabling GuardDuty in the management account does not automatically activate it in member accounts, which is why no threats are detected in those accounts.

Exam trap

The trap here is that candidates assume enabling GuardDuty in the management account automatically propagates to all member accounts, but AWS requires an explicit delegated administrator action to enable the service across the organization.

How to eliminate wrong answers

Option A is wrong because GuardDuty does not require an S3 bucket in each account to store findings; findings are stored centrally in the GuardDuty service and can be exported to a single S3 bucket if configured. Option C is wrong because GuardDuty, when properly enabled via delegated administrator, monitors resources across all member accounts, not just the management account. Option D is wrong because GuardDuty fully supports delegated administrator for AWS Organizations, allowing a designated account to manage GuardDuty across the organization.

84
MCQmedium

During a security incident, a forensic investigator needs to capture the memory of a running EC2 instance without shutting it down. Which AWS feature should be used?

A.Amazon CloudWatch agent
B.EC2 Rescue for Linux or Systems Manager Run Command with a memory dump script
C.AWS CloudTrail
D.Amazon EBS snapshot
AnswerB

EC2 Rescue for Linux includes diagnostic modules that can trigger a memory dump, and AWS Systems Manager Run Command can execute a memory-dump script on the target instance; both operate inside the guest OS to copy volatile memory while the instance remains running. By writing the output to an EBS volume or Amazon S3, they preserve process, kernel, and network state for forensic analysis. This is the correct option because no AWS control-plane API can read guest RAM directly.

Why this answer

EC2 Rescue for Linux (via Systems Manager Run Command) includes a built-in script that can capture a full memory dump from a running EC2 instance without requiring a shutdown. This is essential for forensic analysis to preserve volatile data like running processes, network connections, and kernel structures. The script leverages the Linux 'vmcore' or 'LiME' (Linux Memory Extractor) tool to safely extract memory contents while the instance remains operational.

Exam trap

The trap here is that candidates often confuse capturing volatile memory with taking a disk snapshot (Option D), not realizing that memory is stored in RAM and is not preserved by EBS snapshots, which only capture persistent storage.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Agent is designed for collecting metrics, logs, and performance data, not for capturing raw memory dumps; it cannot access or dump physical memory. Option C is wrong because AWS CloudTrail records API activity and management events, not the volatile memory state of an EC2 instance; it provides no mechanism for memory acquisition. Option D is wrong because an Amazon EBS snapshot captures the persistent disk state (block-level storage), not the contents of RAM; memory is volatile and not stored on EBS volumes.

85
Multi-Selecthard

Which TWO steps should a security engineer take when responding to a confirmed security incident involving a compromised EC2 instance? (Choose 2.)

Select 2 answers
A.Reimage the instance from a clean AMI immediately
B.Delete all CloudTrail logs related to the instance
C.Isolate the instance by changing its security group to deny all traffic
D.Take a snapshot of the instance's EBS volumes for forensic analysis
E.Immediately terminate the instance to stop the attack
AnswersC, D

Replacing the instance's security group with one that denies all inbound and outbound traffic severs command-and-control and exfiltration channels while preserving the instance's memory and disk state for investigation, satisfying containment without terminating evidence needed for the incident response.

Why this answer

Option C is correct because isolating the compromised EC2 instance by replacing its security group with one that denies all inbound and outbound traffic is the standard containment step that stops lateral movement and command-and-control communication while preserving the instance's volatile state for investigation. Option D is correct because taking EBS snapshots of the instance's volumes captures a point-in-time, read-only copy of the disk that can be mounted on a separate forensic workstation for evidence preservation and analysis without altering the original data. Option A is not appropriate as a first response because reimaging destroys volatile evidence and should only occur after containment and forensic capture are complete.

Option B is wrong because deleting CloudTrail logs is log tampering that destroys the audit trail needed for the investigation. Option E is wrong because terminating the instance shuts it down and can destroy volatile memory and instance-store data before evidence is collected.

Exam trap

The trap here is that candidates often confuse 'immediate termination' (Option E) with containment, but AWS incident response frameworks emphasize preserving evidence and isolating rather than destroying the instance, as termination eliminates the ability to perform memory forensics and root cause analysis.

86
MCQeasy

A company uses Amazon GuardDuty and receives a finding of type 'Backdoor:EC2/C&CActivity.B!DNS' for an EC2 instance. What does this finding indicate?

A.The instance is being targeted by an SSH brute force attack.
B.The instance is communicating with a known command and control server.
C.The instance is exfiltrating data to an S3 bucket.
D.The instance is being used in a DDoS attack.
AnswerB

The `C&CActivity` threat purpose denotes confirmed command-and-control traffic, and the `!DNS` suffix specifies the DNS protocol as the detection vector. This satisfies the stem's requirement to interpret the finding type: GuardDuty has observed the instance resolving a domain attributed to a known C&C server.

Why this answer

The finding 'Backdoor:EC2/C&CActivity.B!DNS' indicates that GuardDuty has detected DNS queries from the EC2 instance to a domain associated with known command and control (C&C) infrastructure. This is based on GuardDuty's threat intelligence feeds that map DNS request patterns to known malicious domains, signaling that the instance may be compromised and communicating with an attacker's server.

Exam trap

The trap here is that candidates may confuse 'Backdoor:EC2/C&CActivity.B!DNS' with generic network anomalies or other attack types, but the key differentiator is the DNS-specific indicator that pinpoints communication with a known command and control server, not the attack vector or data exfiltration method.

How to eliminate wrong answers

Option A is wrong because SSH brute force attacks are detected by GuardDuty findings such as 'UnauthorizedAccess:EC2/SSHBruteForce', not by DNS-based C&C activity. Option C is wrong because data exfiltration to an S3 bucket would typically be detected by findings like 'Policy:IAMUser/RootCredentialUsage' or S3-specific findings, not by DNS query analysis for C&C domains. Option D is wrong because DDoS attack participation is indicated by findings such as 'Backdoor:EC2/DenialOfService' or 'Behavior:EC2/NetworkOutboundDenialOfService', which analyze traffic volume and patterns, not DNS queries to C&C servers.

87
MCQeasy

A security team wants to automatically revoke public access to an S3 bucket when Amazon GuardDuty detects a suspicious API call from a known malicious IP address. Which AWS service should be used to orchestrate this automated response?

A.AWS Config
B.AWS Lambda
C.AWS Systems Manager Automation
D.AWS CloudTrail
AnswerC

AWS Systems Manager Automation is a managed workflow service that can execute runbooks against AWS resources; the AWS-DisableS3BucketPublicRead runbook removes public-read ACLs or otherwise strips public access from S3 buckets. The runbook runs under an IAM execution role and can be invoked automatically by AWS Config rules or Amazon EventBridge, giving a fully automated, auditable remediation path. Unlike a custom Lambda function, this service is purpose-built for remediation and requires no custom code.

Why this answer

AWS Systems Manager Automation is the correct service because it provides a runbook-based orchestration framework that can be triggered by Amazon EventBridge events from GuardDuty findings. It can execute predefined automation documents (e.g., AWS-DisableS3BucketPublicReadWrite) to modify S3 bucket policies and revoke public access without requiring custom code, making it ideal for automated incident response workflows.

Exam trap

The trap here is that candidates often choose AWS Lambda as the default for any automation task, overlooking that AWS Systems Manager Automation is the purpose-built service for orchestrated, runbook-based incident response with built-in approval and rollback capabilities.

How to eliminate wrong answers

Option A is wrong because AWS Config is a compliance and resource auditing service that evaluates resource configurations against rules, but it cannot directly execute remediation actions like revoking S3 bucket public access; it can only trigger Lambda functions or Systems Manager Automation for remediation. Option B is wrong because while AWS Lambda can be used to revoke public access, it is not a dedicated orchestration service; it requires custom code and manual integration with EventBridge and GuardDuty, whereas Systems Manager Automation provides a managed, runbook-based approach with built-in error handling and approval workflows. Option D is wrong because AWS CloudTrail is a logging service that records API calls, but it cannot execute any automated response actions; it only provides the audit trail that GuardDuty uses for detection.

88
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team receives an alert from Amazon GuardDuty that one of the EC2 instances is generating outbound traffic to a known command-and-control (C2) IP address. The instance is part of an Auto Scaling group (ASG) with a minimum of 2 and maximum of 10 instances. The security incident response playbook instructs the team to isolate the compromised instance without affecting the application's availability. The team needs to preserve the instance for forensic analysis. Which action should the team take first?

A.Terminate the compromised EC2 instance and allow the ASG to launch a replacement.
B.Detach the EBS root volume from the instance and attach it to a forensic instance.
C.Shut down the instance from within the OS using AWS Systems Manager Run Command.
D.Remove the instance from the ALB target group and attach a security group that denies all traffic.
AnswerD

Deregistering the instance from the ALB target group immediately stops new application traffic from reaching it, while replacing its security group membership with a quarantine security group that contains no allow rules imposes an implicit deny-all at the network interface. This blocks lateral movement, outbound command-and-control traffic, and further exfiltration while the instance continues to run, preserving volatile memory and EBS volumes for forensic capture. It is the correct first step because it is rapid, reversible, and evidence-preserving.

Why this answer

Removing the instance from the ALB target group immediately stops new traffic from reaching the application, while attaching a security group that denies all traffic (e.g., a custom security group with no inbound/outbound rules) effectively isolates the instance at the network layer. This preserves the instance for forensic analysis and does not affect application availability, as the ASG will not automatically terminate the instance (since it is still running and healthy from the ASG's perspective). The ALB will continue to route traffic to the remaining healthy instances in the target group, maintaining service continuity.

Exam trap

The trap here is that candidates may think terminating the instance (Option A) is the fastest way to stop the threat, but they overlook the requirement to preserve the instance for forensic analysis and the need to maintain application availability by not triggering an ASG replacement prematurely.

How to eliminate wrong answers

Option A is wrong because terminating the instance would destroy the forensic evidence (e.g., memory, disk, logs) and the ASG would launch a replacement, but the immediate isolation step should be network-level, not termination. Option B is wrong because detaching the EBS root volume requires the instance to be stopped first, which would take the instance out of service and potentially trigger an ASG replacement, and it does not address the immediate need to stop outbound C2 traffic. Option C is wrong because shutting down the instance from within the OS using Systems Manager Run Command would stop the instance, causing the ASG to launch a replacement (since the instance count drops below the minimum), and it does not preserve the instance for forensic analysis (the instance is stopped, not isolated).

89
MCQmedium

A company has an AWS Lambda function that processes sensitive data. The security team wants to ensure that any errors or suspicious behavior are immediately investigated. Which combination of services should be used to send real-time notifications for anomalous function executions?

A.CloudWatch Logs and SNS
B.CloudTrail and SNS
C.AWS Config and SQS
D.Amazon Detective and SES
AnswerA

Lambda function execution output is written to CloudWatch Logs, so a metric filter can parse log events for patterns such as 'ERROR' or 'AccessDenied' and drive a CloudWatch alarm. The alarm then publishes to an SNS topic, delivering real-time notifications to operators. This is the native, low-latency monitoring path for Lambda function behavior and is ideal for sensitive-data processing failures.

Why this answer

CloudWatch Logs can capture Lambda function execution logs, and a CloudWatch Logs metric filter can be configured to detect patterns indicative of errors or suspicious behavior (e.g., 'ERROR', 'Exception', or custom anomaly patterns). When the metric filter triggers a CloudWatch alarm, it can publish a message directly to an Amazon SNS topic, which then sends real-time notifications (e.g., email, SMS, or HTTP endpoint) to the security team for immediate investigation.

Exam trap

The trap here is that candidates often confuse CloudTrail (which logs API calls) with CloudWatch Logs (which captures application-level execution output), leading them to choose CloudTrail for real-time error monitoring when it is actually designed for auditing and compliance, not for triggering on application errors.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API calls and management events (e.g., who invoked the Lambda function), not the function's execution logs or error output; it cannot trigger real-time notifications based on anomalous function behavior. Option C is wrong because AWS Config is designed for resource configuration compliance and change tracking, not for monitoring real-time execution errors or suspicious behavior; SQS is a message queue that requires a separate consumer to process notifications, adding latency and complexity. Option D is wrong because Amazon Detective is a post-incident investigation service that analyzes historical data to identify root causes of security findings, not a real-time notification service; SES is an email-sending service that requires custom integration and does not natively trigger from Lambda execution anomalies.

90
MCQhard

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB) in a VPC. The security team uses Amazon GuardDuty and has enabled Amazon Detective. Recently, GuardDuty raised a 'Recon:EC2/PortProbeUnprotectedPort' finding for one of the instances. The security engineer verified that the ALB security group only allows inbound HTTP/HTTPS from the internet. However, the finding indicates that the instance is receiving probes on port 22 (SSH). Further investigation with Detective shows that the probes originate from multiple IP addresses and are reaching the instance's private IP address. The engineer suspects that the SSH port is exposed despite the security group configuration. What is the MOST likely cause of this exposure?

A.The EC2 instance's security group allows inbound SSH from 0.0.0.0/0.
B.VPC Flow Logs are misconfigured and are inadvertently forwarding traffic to the instance.
C.AWS Shield Advanced is causing false positives by marking legitimate traffic as probes.
D.The ALB security group has an inbound rule that allows SSH from the internet.
AnswerA

The EC2 instance's security group explicitly permits inbound SSH on port 22 from 0.0.0.0/0. This means the instance is reachable directly from the internet on its own public or elastic IP, completely bypassing the ALB. GuardDuty detects the resulting SSH brute-force attempts from external sources, so this is the root cause despite the ALB fronting web traffic.

Why this answer

The GuardDuty finding 'Recon:EC2/PortProbeUnprotectedPort' indicates that an EC2 instance is receiving unsolicited probes on a port that should not be publicly accessible. Since the ALB security group only allows HTTP/HTTPS from the internet, but the probes are reaching the instance's private IP on port 22 (SSH), the most likely cause is that the instance's own security group has an inbound rule allowing SSH from 0.0.0.0/0. This bypasses the ALB's security group because the instance's security group is evaluated independently for direct traffic to the instance's private IP, and if it permits SSH from anywhere, the probes will reach the instance.

Exam trap

The trap here is that candidates assume the ALB's security group fully protects the backend instances, forgetting that instances have their own security groups that are evaluated independently for direct traffic to their private IPs.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs are a monitoring feature that captures metadata about IP traffic; they do not forward or route traffic to instances, so misconfiguration cannot cause exposure. Option C is wrong because AWS Shield Advanced is a DDoS protection service that does not generate false positives for port probes; GuardDuty findings are independent of Shield, and Shield does not mark legitimate traffic as probes. Option D is wrong because the ALB security group only allows HTTP/HTTPS from the internet, and even if it allowed SSH, that would only affect traffic to the ALB, not directly to the instance's private IP; the probes are reaching the instance directly, not through the ALB.

91
Multi-Selecthard

A security engineer is investigating a security incident where an EC2 instance was used to launch an outbound denial-of-service (DoS) attack. The engineer needs to collect forensic evidence. Which THREE actions should the engineer take? (Choose three.)

Select 3 answers
A.Reboot the instance to clear any malicious processes.
B.Delete the CloudTrail logs that show the instance's API calls.
C.Create an Amazon EBS snapshot of the instance's root volume.
D.Capture the instance's memory using a tool like LiME or Amazon EC2 instance memory capture.
E.Terminate the instance to stop the attack immediately.
AnswersC, D, E

Creating an EBS snapshot of the root volume captures the disk state at a single point in time, including compromised binaries, log files, user artifacts, and any persistence mechanisms the attacker installed. Unlike live acquisition, a snapshot allows offline analysis on a separate instance without altering the original evidence. It also provides a recoverable copy in case the instance is later terminated for containment.

Why this answer

Creating an Amazon EBS snapshot preserves persistent data for offline analysis. Option D is correct because capturing memory preserves volatile evidence. Option E is correct because after collecting forensic evidence, terminating the instance stops the attack immediately and prevents further damage.

Options A and B are incorrect because they destroy evidence (reboot clears memory, deletion removes logs).

Exam trap

A common pitfall is selecting options like rebooting (A) or deleting logs (B) which destroy evidence. While terminating (E) is a valid containment step, it must be done after evidence is collected via snapshot (C) and memory capture (D). The three correct actions are C, D, and E.

92
Multi-Selectmedium

Which THREE actions should be taken when preparing an incident response plan for AWS?

Select 3 answers
A.Enable AWS CloudTrail in all regions.
B.Share the AWS account root user password with the incident response team.
C.Automate incident response using AWS Systems Manager Automation runbooks.
D.Disable VPC Flow Logs to reduce log volume.
E.Create IAM roles with limited permissions for incident responders.
AnswersA, C, E

Enabling CloudTrail in all regions ensures a complete, auditable record of all AWS API activity, including management events, across every region, which is essential for reconstructing the timeline of an incident, identifying compromised credentials or unusual actions, and meeting forensic and compliance requirements. Without multi-region trails, actions in unmonitored regions can go undetected, leaving gaps in the investigation. CloudTrail is a foundational security service that should be enabled by default as part of incident response preparation.

Why this answer

AWS CloudTrail must be enabled in all regions to ensure that all API calls across the entire AWS infrastructure are logged. This provides a comprehensive audit trail essential for forensic investigation and identifying the scope of a security incident. Without multi-region CloudTrail, an attacker could operate in an unmonitored region, leaving no trace for incident responders.

Exam trap

The trap here is that candidates may think sharing the root password is acceptable for emergency access, but AWS explicitly prohibits this and recommends using IAM roles with break-glass procedures instead.

93
MCQmedium

A security engineer notices suspicious API calls from an EC2 instance that has an IAM role attached. The engineer wants to quickly determine if the instance's credentials have been compromised and are being used from an external IP address. What is the most efficient way to detect this?

A.Check VPC Flow Logs for traffic from the instance to unusual destinations.
B.Review AWS CloudTrail logs for the instance's IAM role and look for source IP addresses outside the VPC.
C.Enable Amazon GuardDuty and look for the finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration'.
D.Use IAM Access Analyzer to review the trust policy of the instance's IAM role.
AnswerC

Amazon GuardDuty is the correct choice because it automatically monitors CloudTrail events, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to detect anomalies. The specific finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' is designed to identify when EC2 instance role credentials are being used from an external source or in an unusual pattern, indicating exfiltration. This automated detection provides real-time alerts, which is far more effective than manual analysis for this type of security incident.

Why this answer

Amazon GuardDuty's finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' is specifically designed to detect when EC2 instance credentials (from an IAM role) are being used from an external IP address. GuardDuty analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to identify anomalous API calls where the source IP is outside the VPC, indicating credential exfiltration. This is the most efficient method as it provides a pre-built, automated detection without manual log analysis.

Exam trap

The trap here is that candidates assume manual log analysis (CloudTrail or VPC Flow Logs) is the fastest approach, but GuardDuty provides automated, real-time detection specifically for this exfiltration pattern, making it the most efficient choice.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only show network traffic (IP addresses, ports, protocols) but do not include IAM role or API call details, so they cannot directly confirm credential misuse from an external IP. Option B is wrong because while CloudTrail logs can show source IP addresses, manually reviewing them for the IAM role's API calls is not the most efficient method; it requires filtering and correlation, whereas GuardDuty automates this detection. Option D is wrong because IAM Access Analyzer reviews resource-based policies for unintended access (e.g., trust policies), not for detecting active credential compromise or external usage of instance credentials.

94
MCQhard

A company uses Amazon Detective to investigate security findings. The security team is analyzing a GuardDuty finding of type 'Backdoor:EC2/C&CActivity.B!DNS' for an EC2 instance. The team wants to use Detective to understand the full scope of the incident, including which other resources the instance communicated with and any IAM roles used. However, when the team opens the finding in Detective, they see no network activity data for the instance. The instance is in a VPC with VPC Flow Logs enabled, and Flow Logs are being published to CloudWatch Logs. What should the team do to enable Detective to display the network activity?

A.Re-enable the GuardDuty finding in Amazon Detective.
B.Enable GuardDuty EKS Audit Logs monitoring.
C.Ensure that VPC Flow Logs are enabled for the VPC and are being published to Amazon CloudWatch Logs in the same account and Region as Detective.
D.Install the Amazon Detective agent on the EC2 instance.
AnswerC

Amazon Detective relies on VPC Flow Logs to populate the network activity details on a finding, such as source/destination IPs, ports, and protocol. For those flow logs to be ingested, they must be enabled for the relevant VPC and published to Amazon CloudWatch Logs in the same AWS account and Region as the Detective graph. Without this configuration, Detective can still show the GuardDuty finding and some API activity, but the network path section will be empty—so enabling VPC Flow Logs is the correct fix.

Why this answer

Amazon Detective ingests VPC Flow Logs from CloudWatch Logs to generate network activity visualizations for EC2 instances. Even though VPC Flow Logs are enabled and published to CloudWatch Logs, Detective requires that the logs are in the same AWS account and Region as the Detective behavior graph. If the logs are in a different account or Region, Detective cannot access them, resulting in no network activity data being displayed for the instance.

Exam trap

The trap here is that candidates assume simply enabling VPC Flow Logs and publishing to CloudWatch Logs is sufficient, but they overlook the requirement that the logs must be in the same AWS account and Region as the Detective behavior graph for ingestion to occur.

How to eliminate wrong answers

Option A is wrong because re-enabling the GuardDuty finding in Detective does not affect the ingestion of VPC Flow Logs; Detective automatically ingests findings from GuardDuty when the integration is enabled, and the issue is with missing network data, not the finding itself. Option B is wrong because GuardDuty EKS Audit Logs monitoring is specific to Amazon EKS clusters and has no relevance to EC2 instance network activity or VPC Flow Logs. Option D is wrong because Amazon Detective does not require or use an agent on EC2 instances; it relies on existing data sources like VPC Flow Logs, GuardDuty findings, and CloudTrail logs, and installing an agent would not enable network activity visualization.

95
Multi-Selectmedium

A company wants to use AWS services to detect and respond to a potential DDoS attack on their web application hosted on EC2 instances behind an Application Load Balancer (ALB). Which TWO AWS services should the company use for detection and mitigation?

Select 2 answers
A.AWS WAF
B.AWS Shield Advanced
C.Amazon Route 53
D.Amazon CloudFront
E.Amazon GuardDuty
AnswersA, B

AWS WAF is a web application firewall that can detect and respond to application-layer DDoS attacks by creating rate-based rules that automatically block or rate-limit requests from a single IP address once a configured threshold is exceeded. It also supports custom rules for HTTP inspection, making it a direct, policy-driven tool for DDoS mitigation. WAF integrates with CloudFront, Application Load Balancer, and API Gateway to enforce these rules in real time at the edge or ingestion point.

Why this answer

AWS WAF is correct because it allows you to create web access control lists (web ACLs) to filter and monitor HTTP/HTTPS requests to your Application Load Balancer. By defining rate-based rules, you can automatically block IP addresses that exceed a threshold of requests per 5-minute window, mitigating layer 7 DDoS attacks such as HTTP floods or SQL injection attempts.

Exam trap

The trap here is that candidates often confuse AWS Shield Advanced (which provides network-layer DDoS detection and mitigation) with AWS WAF (which provides application-layer filtering), but the question requires both detection and mitigation, and Shield Advanced alone does not offer the granular application-layer rule customization that WAF provides for an ALB-based web application.

96
MCQeasy

A company wants to automatically trigger a Lambda function when a new security finding is generated in AWS Security Hub. Which service should be used to invoke the Lambda function?

A.Amazon Simple Notification Service (SNS)
B.AWS Security Hub itself
C.Amazon EventBridge
D.AWS CloudTrail
AnswerC

Amazon EventBridge is the correct answer because Security Hub natively publishes all findings and finding updates to the default event bus as events such as 'Security Hub Findings - Imported'. A rule can use an event pattern to filter on compliance status, severity, or finding type and target a Lambda function, which EventBridge then invokes asynchronously. This is the standard event-driven integration designed for automating responses to Security Hub findings.

Why this answer

Amazon EventBridge is the correct service because AWS Security Hub automatically sends all findings to the default EventBridge bus as events. You can create an EventBridge rule that matches the 'Security Hub Findings - Imported' event pattern and targets a Lambda function for invocation. This is the native, recommended integration for event-driven responses to Security Hub findings.

Exam trap

The trap here is that candidates may think Security Hub can directly invoke Lambda or that SNS is the primary integration, but AWS explicitly designed EventBridge as the central event bus for all Security Hub findings to enable flexible, rule-based routing.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub notification service that can be used as a target for EventBridge rules, but it is not the service that directly invokes Lambda in response to Security Hub findings; SNS would require a separate subscription and does not natively parse Security Hub event patterns. Option B is wrong because AWS Security Hub itself does not invoke Lambda functions directly; it only generates findings and sends them to EventBridge, CloudWatch, or S3 via integrations. Option D is wrong because AWS CloudTrail records API calls for auditing and does not provide real-time event-driven invocation of Lambda functions based on Security Hub findings.

97
Multi-Selecteasy

A security engineer needs to detect and respond to suspicious activity on an Amazon RDS database. Which TWO services can be used together to monitor database activity and trigger automated remediation?

Select 2 answers
A.Amazon Detective
B.Amazon RDS Enhanced Monitoring
C.AWS Lambda
D.Amazon RDS Performance Insights
E.Amazon GuardDuty
AnswersC, E

AWS Lambda is the correct answer because it is a serverless compute service that can be triggered by security events via Amazon EventBridge (e.g., a GuardDuty finding) and execute automated response actions. A Lambda function can revoke IAM credentials, modify security groups, terminate instances, or quarantine an RDS instance, turning detection signals into immediate remediation without manual intervention.

Why this answer

AWS Lambda is correct because it can be triggered by Amazon RDS database activity streams (e.g., via Amazon RDS for MySQL or PostgreSQL) or by Amazon CloudWatch Events/EventBridge rules that detect suspicious database events (such as failed login attempts or unusual query patterns). Lambda functions can then execute automated remediation actions, such as revoking database access, rotating credentials, or isolating the database instance. This enables a serverless, event-driven response to threats without manual intervention.

Exam trap

The trap here is that candidates often confuse monitoring services (Enhanced Monitoring, Performance Insights) with security detection and response services, or they overlook that GuardDuty alone cannot perform automated remediation—it requires a compute service like Lambda to execute the response actions.

98
MCQeasy

A security analyst is reviewing AWS CloudTrail logs and notices a series of API calls from an unfamiliar IAM user. The calls include CreateUser, AttachUserPolicy, and CreateAccessKey. The analyst wants to quickly determine if this activity is anomalous and receive real-time alerts. Which AWS service should the analyst use to achieve this with minimal configuration?

A.Amazon GuardDuty
B.AWS Config
C.Amazon Detective
D.AWS Security Hub
AnswerA

GuardDuty continuously monitors CloudTrail management events and uses machine learning and threat intelligence to detect anomalous IAM behavior, such as unusual user creation or policy attachment. It generates findings in near real-time with minimal setup, requiring only that GuardDuty be enabled. This directly addresses the analyst's need for quick anomaly detection and alerts.

Why this answer

Amazon GuardDuty is the correct service because it automatically analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to detect anomalous behavior, including suspicious IAM activity. It requires no additional infrastructure and generates findings in near real-time. Security Hub and Detective are for aggregation and investigation, while AWS Config focuses on configuration compliance.

Exam trap

The trap here is confusing services that aggregate or investigate findings with the service that actually performs the initial anomaly detection.

99
MCQeasy

A security engineer is investigating a potential data exfiltration from an S3 bucket. Which AWS service should be used to analyze the VPC Flow Logs for the S3 bucket's endpoint?

A.Amazon Macie
B.Amazon Inspector
C.Amazon GuardDuty
D.Amazon Detective
AnswerD

Amazon Detective is purpose-built for security investigation: it ingests VPC Flow Logs, AWS CloudTrail, and EKS audit logs and automatically builds an interactive graph of network traffic, resource interactions, and IAM identities. You can expand a suspected instance to view all of its inbound/outbound connections, the aggregate bytes transferred per peer, and the API actions performed around each flow, which directly answers whether and how data exfiltration occurred. This interactive, multi-source correlation is exactly what the other options lack.

Why this answer

Amazon Detective is the correct service because it can ingest and analyze VPC Flow Logs, including those for a VPC endpoint used to access an S3 bucket. Detective uses machine learning, statistical analysis, and graph theory to identify the root cause of suspicious network traffic patterns, such as unusual data volumes or connections to external IPs, which are indicative of data exfiltration.

Exam trap

The trap here is that candidates confuse Amazon GuardDuty's alerting capability with Amazon Detective's investigative analysis, forgetting that GuardDuty generates findings but Detective is needed for deep forensic analysis of VPC Flow Logs to understand the full scope of an incident.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data stored in S3 buckets, but it does not analyze VPC Flow Logs or network traffic. Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not for analyzing VPC Flow Logs. Option C is wrong because Amazon GuardDuty is a threat detection service that can monitor VPC Flow Logs for malicious activity, but it is a continuous monitoring and alerting service, not an investigative tool for deep analysis of historical flow log data; Detective is designed for post-breach root-cause analysis.

100
MCQeasy

A security engineer needs to ensure that all API calls in an AWS account are logged for incident response. Which AWS service should be enabled?

A.Amazon GuardDuty
B.VPC Flow Logs
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the only service that directly records AWS API activity as first-class audit log events. When enabled, it captures the identity of the caller (IAM user or role), the source IP address, the requested action, request parameters, and the response returned by the service, for both management events and (when configured) data events. These logs can be delivered to Amazon S3 and CloudWatch Logs, and the trail can be multi-region and organization-wide, making CloudTrail the authoritative record of every API call for incident response and governance. Unlike anomaly-detection services such as GuardDuty, CloudTrail does not infer or analyze behavior—it simply logs each call exactly as it occurred.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity of the caller, the time of the call, the source IP address, and the request parameters. This logging is essential for incident response to reconstruct events and identify unauthorized or malicious activity.

Exam trap

The trap here is that candidates confuse AWS Config with CloudTrail because both deal with 'logging' and 'compliance,' but Config tracks resource state changes over time, not the API calls that caused those changes.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (like CloudTrail, VPC Flow Logs, and DNS logs) for malicious activity, but it does not itself generate or store API call logs. Option B is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) at the elastic network interface level, not API calls to AWS services. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not log API calls; it relies on CloudTrail for API history.

101
MCQhard

A company's incident response team is using AWS Systems Manager to run commands on EC2 instances for forensic analysis. The team needs to ensure that the commands are run with minimal latency and that the results are stored securely. Which Systems Manager capability should the team use?

A.AWS Systems Manager Automation
B.AWS Systems Manager Session Manager
C.AWS Systems Manager Patch Manager
D.AWS Systems Manager Run Command
AnswerD

AWS Systems Manager Run Command is the correct choice because it executes an arbitrary command (shell or PowerShell) on one or more managed instances through the SSM Agent and can immediately write the output to Amazon S3. It supports tag-based targeting, returns status and response details, and offers low latency—critical for incident response. Storing the output to S3 provides a persistent and auditable record for later analysis, while the same command can be fanned out to a fleet in parallel.

Why this answer

AWS Systems Manager Run Command is the correct capability because it allows the incident response team to execute commands on EC2 instances with minimal latency by using the SSM Agent to run scripts or commands directly, and it can store command output in Amazon S3 or CloudWatch Logs for secure, durable storage. This meets the requirement for low-latency execution and secure result storage without requiring interactive sessions or complex automation workflows.

Exam trap

The trap here is that candidates often confuse Session Manager (interactive access) with Run Command (non-interactive execution), assuming that 'minimal latency' implies a live session, but Run Command is actually faster for scripted tasks because it avoids session setup overhead and can target multiple instances in parallel.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Automation is designed for multi-step, automated workflows (e.g., patching, AMI creation) and introduces orchestration overhead, not optimized for low-latency ad-hoc command execution. Option B is wrong because AWS Systems Manager Session Manager provides interactive shell or port forwarding access, not a mechanism to run commands with minimal latency and store results securely; it is for live sessions, not scripted execution. Option C is wrong because AWS Systems Manager Patch Manager is specifically for automating OS patching, not for running arbitrary forensic commands or storing results.

102
MCQeasy

A security engineer is investigating a potential security incident involving an Amazon RDS database. The engineer needs to determine if someone attempted to access the database with incorrect credentials. Which AWS service should the engineer use to view authentication failures?

A.Amazon CloudWatch Logs
B.VPC Flow Logs
C.Amazon RDS database logs (error logs)
D.AWS CloudTrail
AnswerC

Amazon RDS database logs, specifically the error log, are the authoritative source for database-level authentication failure entries. For example, MySQL error logs record messages like 'Access denied for user 'alice'@'host' (using password: YES)' for each failed login, and PostgreSQL logs similarly capture 'FATAL: password authentication failed for user 'alice''. These logs are generated by the database engine itself and are accessible through the RDS console, the DescribeDBLogFiles API, or by streaming them to Amazon CloudWatch Logs. Because the question is about database authentication attempts, the RDS error log directly contains the required evidence.

Why this answer

Amazon RDS database error logs capture authentication failures, including attempts with incorrect credentials, because the database engine itself logs these events. For example, MySQL's error log records 'Access denied for user' messages, and PostgreSQL's log records 'FATAL: password authentication failed' entries. This makes RDS database logs the direct source for viewing authentication failures at the database level.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with database-level authentication logging, assuming CloudTrail captures all security events, but it does not log database engine authentication failures because those occur within the database session, not through the AWS API.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files, but it does not generate or capture database authentication failures by itself; it can only ingest logs from other sources like RDS database logs if configured. Option B is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log application-level authentication events such as database credential failures. Option D is wrong because AWS CloudTrail records API calls made to the AWS control plane (e.g., CreateDBInstance, ModifyDBInstance) and does not capture database engine-level authentication events like incorrect password attempts.

103
MCQeasy

Your company has a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The security team enabled AWS CloudTrail and Amazon GuardDuty. GuardDuty generates a finding 'Recon:EC2/PortProbeUnprotectedPort' for an EC2 instance that does not exist in the account. Upon investigation, you realize that the finding is triggered by a misconfigured Network Load Balancer (NLB) that is exposing a port to the internet. The NLB is used by the API Gateway. You need to reduce false positives for this specific finding. What should you do?

A.Change the NLB to an Application Load Balancer.
B.Enable AWS Shield Advanced to block the probes.
C.Disable GuardDuty for the account.
D.Create a suppression rule in GuardDuty to filter out findings for the NLB's public IP and port.
AnswerD

Create a GuardDuty suppression rule that filters findings based on the NLB's public IP address and port, which automatically excludes those matching findings from the Active findings view and from CloudWatch Events delivery. Suppression rules evaluate regex-based criteria on finding fields, so you can scope the rule to exactly this endpoint while all other GuardDuty detections remain fully active and visible. This is GuardDuty's intended mechanism for whitelisting known false positives and involves no infrastructure changes, additional cost, or loss of detection coverage.

Why this answer

GuardDuty suppression rules allow you to filter out findings that are known false positives based on specific criteria, such as the public IP and port of the NLB. Since the NLB is intentionally exposing a port for API Gateway, the port probe finding is expected behavior, not a real threat. Suppressing findings for that specific combination reduces noise without disabling GuardDuty for the entire account.

Exam trap

The trap here is that candidates may think changing the load balancer type or adding DDoS protection will stop the probes, but GuardDuty detects the probe activity itself, not the vulnerability—so only suppression rules can prevent the false positive without disabling the service.

How to eliminate wrong answers

Option A is wrong because changing the NLB to an Application Load Balancer does not address the root cause—the exposed port—and ALBs also have public IPs that can be probed, potentially generating similar findings. Option B is wrong because AWS Shield Advanced is a DDoS protection service that does not suppress or filter GuardDuty findings; it mitigates volumetric attacks but does not prevent port probe detections. Option C is wrong because disabling GuardDuty entirely would remove all threat detection capabilities for the account, which is an overreaction to a single false positive and violates security best practices.

104
Multi-Selecthard

Which TWO AWS services can be used to automatically block malicious IP addresses at the network perimeter? (Select TWO.)

Select 2 answers
A.Amazon Route 53
B.Security Groups
C.Network ACLs
D.AWS WAF
E.AWS Shield Advanced
AnswersC, D

Network ACLs (NACLs) are stateless, subnet-level firewalls that evaluate rules in ascending numeric order and support both allow and deny rules. To automatically block a specific IP, you can add a deny rule with a /32 source CIDR at the top of the NACL, but because NACLs are stateless you must also write a corresponding rule for the return traffic. This explicit-denying capability makes NACLs one of the correct answers.

Why this answer

Network ACLs (NACLs) are stateless virtual firewalls that operate at the subnet level in a VPC. They can be configured with inbound and outbound rules to explicitly deny traffic from specific IP addresses, effectively blocking malicious IPs at the network perimeter before they reach the instances.

Exam trap

The trap here is that candidates often confuse Security Groups with Network ACLs, thinking Security Groups can block traffic at the network perimeter, but Security Groups are instance-level and cannot block traffic before it enters the subnet.

105
MCQmedium

A security engineer is implementing automated incident response. The engineer wants to use AWS Lambda to automatically remediate GuardDuty findings. What is the recommended pattern to trigger the Lambda function?

A.Configure an Amazon EventBridge rule to match GuardDuty findings and invoke the Lambda function.
B.Subscribe the Lambda function to an SNS topic that GuardDuty publishes findings to.
C.Use CloudWatch Logs subscription filter to trigger Lambda on GuardDuty log entries.
D.Have the Lambda function poll the EC2 instance metadata for threat indicators.
AnswerA

EventBridge is GuardDuty's native event bus integration. GuardDuty automatically publishes each finding as an event to the default event bus, where a rule can match the detail-type 'GuardDuty Finding' and use Lambda as a target. The rule supports filtering by severity, account, or finding type, and Lambda receives the finding JSON directly, enabling precise, low-latency automated remediation. This is the architecturally supported pattern with built-in retry and optional dead-letter queues.

Why this answer

Amazon EventBridge is the recommended pattern because it natively integrates with AWS GuardDuty to receive all finding events in near real-time. By configuring an EventBridge rule that matches GuardDuty finding types (e.g., 'UnauthorizedAccess:EC2/SSHBruteForce'), you can directly invoke a Lambda function for automated remediation without polling or intermediate services. This pattern is serverless, event-driven, and follows AWS best practices for decoupled incident response.

Exam trap

The trap here is that candidates may assume GuardDuty uses SNS or CloudWatch Logs for output, similar to other AWS services, but GuardDuty exclusively emits findings as EventBridge events, making EventBridge the only native and recommended trigger pattern for Lambda remediation.

How to eliminate wrong answers

Option B is wrong because GuardDuty does not publish findings directly to SNS topics; it sends findings to EventBridge or can be configured to send to SNS via EventBridge, but direct subscription is not supported. Option C is wrong because GuardDuty does not write findings to CloudWatch Logs; findings are sent as events to EventBridge, not as log entries. Option D is wrong because EC2 instance metadata does not contain threat indicators from GuardDuty; it only provides instance-specific metadata like IP address or IAM role, and polling it would be an anti-pattern for event-driven remediation.

106
MCQeasy

A security analyst needs to detect and alert on suspicious API calls in real time. Which combination of AWS services should be used?

A.AWS CloudTrail, Amazon CloudWatch Logs, and Amazon EventBridge.
B.Amazon Inspector and AWS CloudTrail.
C.Amazon GuardDuty and AWS Lambda.
D.AWS Config and Amazon SNS.
AnswerA

CloudTrail records API activity, CloudWatch Logs stores those events, and EventBridge filters them in near real time to trigger alerts. This satisfies the requirement to detect suspicious API calls as they occur, rather than relying on periodic batch analysis or delayed log review.

Why this answer

AWS CloudTrail captures API calls and delivers log files to Amazon CloudWatch Logs, where you can define metric filters to detect suspicious patterns. Amazon EventBridge then consumes those filtered log events to trigger real-time alerts or automated remediation actions. This combination provides the end-to-end pipeline needed for real-time detection and alerting on API activity.

Exam trap

The trap here is that candidates often assume GuardDuty alone can provide real-time API call alerts, but GuardDuty findings are based on aggregated threat intelligence and behavioral analysis, not real-time per-API-call filtering, whereas CloudTrail plus CloudWatch Logs plus EventBridge gives you precise, real-time control over specific API actions.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and network exposure, not a real-time API call detection service. Option C is wrong because while Amazon GuardDuty can detect suspicious API activity using threat intelligence and anomaly detection, it does not natively provide real-time alerting on specific API calls; it generates findings that are typically evaluated asynchronously, and AWS Lambda alone cannot capture or filter API calls without a source like CloudTrail. Option D is wrong because AWS Config is a resource inventory and compliance service that tracks configuration changes, not API calls, and Amazon SNS is a notification service that requires a source of events (like CloudTrail and CloudWatch Logs) to deliver alerts.

107
MCQhard

During an incident response, a security engineer needs to capture a forensic image of an EC2 instance's root volume for analysis. The instance is running and cannot be stopped. What is the recommended approach to capture the volume without stopping the instance?

A.Use the dd command via AWS Systems Manager to create a raw image and store it in S3.
B.Detach the volume from the instance, create a snapshot, and then attach it to a forensic analysis instance.
C.Create a snapshot while the volume is attached to the instance.
D.Use AWS Systems Manager to run a command that copies the volume content to S3.
AnswerC

Creating a snapshot while the volume is attached is the correct approach because Amazon EBS snapshots are designed to be taken of in-use volumes without stopping the instance. The snapshot is crash-consistent (or file-system-consistent if the instance has the AWS backup agent or you freeze the filesystem), and it provides a point-in-time forensic copy that can later be analyzed by creating a new volume from the snapshot. This satisfies the incident response requirement to preserve evidence while keeping the instance running for continued investigation or memory acquisition.

Why this answer

The correct approach is to create a snapshot of the EBS root volume while it is still attached to the running instance (Option C). Snapshots can be taken of in-use volumes without stopping the instance, providing a point-in-time copy for forensic analysis. Option B is incorrect because you cannot detach the root volume of a running instance without first stopping it, which contradicts the requirement not to stop the instance.

Exam trap

Candidates often mistakenly believe that the root volume can be detached while the instance is running (Option B), or that a snapshot requires stopping the instance. In reality, snapshots of attached volumes are allowed and are the recommended method for capturing forensic images without downtime.

How to eliminate wrong answers

Option A is wrong because the dd command via AWS Systems Manager would require the volume to be unmounted or the instance to be stopped to avoid data corruption from concurrent writes, and storing a raw image in S3 is inefficient and not a standard forensic practice. Option C is wrong because creating a snapshot while the volume is attached is actually the correct first step, but the question asks for the full recommended approach to capture the volume for analysis, which includes using the snapshot to create a new volume and attach it to a forensic instance—not just taking the snapshot. Option D is wrong because AWS Systems Manager cannot directly copy volume content to S3 without first creating a snapshot or using a tool like dd, which would require the volume to be unmounted or the instance to be stopped to ensure consistency.

108
MCQeasy

A company uses AWS CloudTrail to log all API activity. The security team wants to ensure that any changes to CloudTrail configuration (e.g., disabling the trail, deleting the trail, modifying the log delivery) are detected immediately. They have created a CloudWatch Events rule to capture the event 'StopLogging' and send an SNS notification. During testing, the team stops the trail and does not receive the notification. The CloudWatch Events rule is configured with the correct event pattern. What should the team check?

A.Verify that the CloudTrail trail is logging management events.
B.Ensure that the event pattern includes the correct source and detail-type.
C.Confirm that the SNS topic subscription is confirmed.
D.Check the IAM role associated with the CloudWatch Events rule to ensure it has permissions to publish to the SNS topic.
AnswerD

CloudWatch Events rules that target an SNS topic must assume an IAM role that grants sns:Publish on that topic's ARN. Without that permission, the rule fails at execution time with an AccessDenied error, even though the event pattern matched and the rule appears to have fired. The correct fix is to verify the role's trust policy allows events.amazonaws.com to assume it and that the attached policy includes the exact sns:Publish action for the target topic.

Why this answer

CloudWatch Events rules require an IAM role with permissions to invoke the target (e.g., publish to SNS). Even if the event pattern matches and the SNS topic exists, without a properly configured IAM role that grants `sns:Publish` to the CloudWatch Events service, the rule cannot deliver the notification. This is a common misconfiguration that causes silent failures.

Exam trap

The trap here is that candidates assume the event pattern matching is the only requirement for delivery, overlooking the IAM permissions needed for the CloudWatch Events rule to invoke the SNS target.

How to eliminate wrong answers

Option A is wrong because the issue is about receiving a notification for the 'StopLogging' event, not about whether the trail logs management events; CloudTrail must log management events for the event to appear, but the team already captured the event pattern correctly, so this is not the immediate cause of the missing notification. Option B is wrong because the question states the CloudWatch Events rule is configured with the correct event pattern, so the source and detail-type are already correct; checking them again would not resolve the delivery failure. Option C is wrong because the SNS topic subscription confirmation is only relevant for email or HTTP endpoints; if the SNS topic is used as a CloudWatch Events target, the subscription is automatically confirmed by the service, so this is not the likely cause.

109
Multi-Selecthard

A security team is implementing automated response to AWS GuardDuty findings. Which THREE actions should be taken to ensure proper incident response?

Select 3 answers
A.Create an AWS Lambda function that automatically modifies the security group of the affected instance to block all traffic.
B.Tag the affected instance with a 'quarantine' tag for tracking.
C.Create a snapshot of the EBS volumes attached to the instance for forensic analysis.
D.Terminate the affected instance immediately to neutralize the threat.
E.Disable AWS CloudTrail to prevent further logging of malicious activity.
AnswersA, B, C

Automating a Lambda-based containment action via EventBridge when a GuardDuty finding is detected is the correct initial response because it lets you immediately revoke all inbound and outbound security group rules on the affected instance. This stops lateral movement and malicious traffic while leaving the instance running and its memory and disk state intact for later forensic collection. The Lambda function must have the appropriate IAM policy to describe and modify security groups, and it can also log the rule changes to CloudTrail for audit.

Why this answer

Isolating the affected instance by modifying its security group to block all traffic is a common containment strategy that stops malicious network activity without destroying evidence. This approach allows the security team to perform forensic analysis and remediation while preventing further compromise, aligning with AWS incident response best practices.

Exam trap

The trap here is that candidates may think immediate termination (Option D) is the fastest way to neutralize a threat, but AWS incident response frameworks emphasize containment and evidence preservation over destruction.

110
MCQhard

A security engineer is reviewing AWS CloudTrail logs and notices a large number of `DescribeInstances` API calls from a single IAM user in a short period. The engineer suspects a credential compromise. What is the most effective way to automatically revoke the compromised credentials and notify the security team?

A.Use AWS CloudTrail to automatically disable the IAM user's access keys.
B.Create an Amazon EventBridge rule that triggers an AWS Lambda function to revoke the keys and send an SNS notification.
C.Create an AWS Config rule that checks for excessive API calls and revokes keys.
D.Enable Amazon GuardDuty to automatically revoke compromised credentials.
AnswerB

Amazon EventBridge can match CloudTrail API events in near real-time using event patterns and then invoke an AWS Lambda function as a target. The Lambda function can call iam:UpdateAccessKey with Status=Inactive to revoke the compromised key(s), and it can also publish a message to an SNS topic to alert security personnel. This serverless pattern is a recommended, native AWS approach for automated incident response to suspicious IAM activity, making it the correct choice here.

Why this answer

It uses Amazon EventBridge to detect the anomalous DescribeInstances API calls (via CloudTrail as an event source), then triggers an AWS Lambda function to programmatically revoke the IAM user's access keys (using the `deactivate_access_key` or `delete_access_key` API), and sends an SNS notification to the security team. This provides an automated, near-real-time response to a suspected credential compromise without manual intervention.

Exam trap

The trap here is that candidates may think CloudTrail or GuardDuty can directly take remediation actions, but they are detection-only services that require integration with compute services like Lambda for automated response.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail is a logging service and does not have the capability to automatically disable IAM access keys; it only records API activity. Option C is wrong because AWS Config rules are designed for compliance and resource configuration auditing, not for real-time threat detection or automated revocation of credentials based on API call frequency. Option D is wrong because Amazon GuardDuty can detect suspicious activity (e.g., unusual API calls) but does not automatically revoke credentials; it generates findings that require a separate response mechanism (e.g., EventBridge + Lambda) to take action.

111
MCQmedium

A company uses a hybrid architecture with on-premises servers and AWS. The company uses AWS Site-to-Site VPN to connect to a VPC. The security team suspects that a VPN tunnel has been compromised and an attacker is intercepting traffic. The team needs to verify the integrity of the VPN connection. What is the MOST effective way to detect if traffic is being intercepted?

A.Monitor Amazon CloudWatch metrics for the VPN tunnel, such as tunnel state and data throughput.
B.Use AWS Config to check VPN configuration compliance.
C.Use a third-party network monitoring tool to perform deep packet inspection.
D.Enable VPC Flow Logs and analyze traffic patterns for unusual destinations.
AnswerA

Amazon CloudWatch publishes VPN tunnel metrics natively, including TunnelState (UP/DOWN) and DataTransferred. A sudden, unexplained tunnel flap, prolonged DOWN state, or throughput spike during an idle period can signal a renegotiation attack, a man-in-the-middle redirecting traffic to an unauthorized peer, or a compromised customer gateway. Because these metrics are captured from the AWS side of the IPsec tunnel and are continuously recorded, they can be compared against historical baselines to detect abnormal behavior that would indicate interception or tampering.

Why this answer

Monitoring Amazon CloudWatch metrics for the VPN tunnel, specifically the 'TunnelState' metric, directly indicates whether the tunnel is up or down. A compromised tunnel that is intercepting traffic would likely cause the tunnel to flap or drop unexpectedly, which CloudWatch can alert on. Additionally, abnormal data throughput patterns (e.g., sudden spikes or drops) can signal interception or rerouting of traffic, making this the most effective way to detect integrity issues without relying on traffic content.

Exam trap

The trap here is that candidates confuse configuration compliance (AWS Config) or traffic analysis (VPC Flow Logs) with active tunnel integrity verification, overlooking that CloudWatch metrics directly monitor the VPN tunnel's operational state and performance, which is the most reliable indicator of compromise without requiring decryption.

How to eliminate wrong answers

Option B is wrong because AWS Config checks configuration compliance (e.g., encryption settings, routing rules) but cannot detect active interception or compromise of a live VPN tunnel; it only validates static configuration. Option C is wrong because deep packet inspection (DPI) requires decrypting the VPN traffic, which is not possible without the VPN encryption keys; the attacker would also be encrypted, so DPI cannot distinguish legitimate from intercepted traffic. Option D is wrong because VPC Flow Logs capture metadata (IPs, ports, protocols) but not the content or integrity of the VPN tunnel; unusual destinations might indicate exfiltration but do not directly confirm tunnel interception, and flow logs cannot detect if traffic is being modified or replayed within the encrypted tunnel.

112
MCQeasy

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. What is the MOST efficient way to enable GuardDuty for all accounts?

A.Create a Lambda function that uses AWS Organizations API to enable GuardDuty in each account
B.Use AWS Service Catalog to provision GuardDuty across accounts
C.Manually enable GuardDuty in each member account
D.Enable GuardDuty in the management account and designate a delegated administrator to manage GuardDuty
AnswerD

GuardDuty is natively integrated with AWS Organizations, and the recommended practice is to enable it in the management account, then designate a delegated administrator account to centrally manage GuardDuty for all member accounts. The delegated administrator can configure detectors, manage findings, and send automated responses, while the management account retains full governance control. This approach automatically covers all existing and future accounts in the organization without requiring per-account manual steps, and it also enables centralized aggregation of findings.

Why this answer

AWS Organizations allows you to enable GuardDuty at the management account level and then designate a delegated administrator to manage GuardDuty across all member accounts. This approach is the most efficient as it eliminates the need for per-account manual or scripted enablement, leveraging the Organizations API to automatically enroll all existing and future accounts.

Exam trap

The trap here is that candidates may think a custom Lambda function or manual per-account setup is required, overlooking the built-in delegated administrator feature that streamlines multi-account GuardDuty management via AWS Organizations.

How to eliminate wrong answers

Option A is wrong because creating a Lambda function to call the Organizations API for each account is unnecessary and less efficient; the delegated administrator feature in GuardDuty already automates multi-account enablement without custom code. Option B is wrong because AWS Service Catalog is designed for provisioning and governing IT service catalogs, not for enabling security services like GuardDuty across accounts; it adds complexity without benefit. Option C is wrong because manually enabling GuardDuty in each member account is inefficient, error-prone, and does not scale, especially in environments with many accounts or frequent account creation.

113
MCQhard

A security engineer suspects that an EC2 instance is communicating with a known malicious IP address. The engineer needs to capture the full network packets for analysis. Which approach should be taken?

A.Enable AWS Security Hub to detect and capture malicious traffic.
B.Install the Amazon CloudWatch agent on the instance to capture network logs.
C.Enable VPC Flow Logs on the subnet and analyze the logs.
D.Use VPC Traffic Mirroring to mirror the instance's ENI to a monitoring appliance.
AnswerD

VPC Traffic Mirroring copies live traffic from a source ENI and sends it to a designated monitoring appliance or security tool, enabling full packet capture and deep packet inspection. Because it operates at the hypervisor level, it can see every packet, including payloads, without installing agents on the instance. This allows the security engineer to analyze the exact malicious traffic and is the correct method for capturing full network data from the EC2 instance.

Why this answer

VPC Traffic Mirroring captures and copies all network traffic from an EC2 instance's Elastic Network Interface (ENI) and forwards it to a monitoring appliance (e.g., a security appliance or packet analyzer) for full packet-level analysis. This is the only option that provides raw, full network packets (including headers and payloads) without impacting the instance's performance or requiring software installation on the instance itself.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which provide metadata only) with full packet capture, leading them to choose Option C, but VPC Flow Logs cannot capture packet payloads required for deep forensic analysis.

How to eliminate wrong answers

Option A is wrong because AWS Security Hub is a security posture management service that aggregates findings from other services (e.g., GuardDuty, Inspector) and does not capture raw network packets. Option B is wrong because the Amazon CloudWatch agent collects metrics and logs (e.g., CPU, memory, application logs) but cannot capture full network packets at the OSI Layer 2/3 level; it lacks packet capture capabilities. Option C is wrong because VPC Flow Logs capture metadata (e.g., source/destination IP, port, protocol, packet count) but do not capture the actual packet payloads or full network packets required for deep analysis.

114
Multi-Selecteasy

A company is designing an incident response plan for AWS. The plan must include the ability to collect forensic data from EC2 instances without requiring SSH key pairs. Which TWO AWS services can be used to acquire forensic data from EC2 instances without remote access? (Choose 2.)

Select 2 answers
A.AWS Systems Manager Run Command
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
E.Amazon EBS snapshots
AnswersA, E

AWS Systems Manager Run Command lets authorized responders execute scripts or commands on EC2 instances through the SSM Agent, eliminating the need for SSH bastion hosts or key management during an incident. This supports live response actions such as collecting volatile data, stopping services, or isolating a compromised instance, all while recording the execution in CloudTrail and allowing IAM-based permission controls.

Why this answer

AWS Systems Manager Run Command allows you to run scripts or commands on EC2 instances via the SSM Agent, without requiring SSH keys or direct network access. This enables forensic data collection (e.g., memory dumps, log files) by executing commands remotely through the AWS Systems Manager service, using IAM roles for authentication.

Exam trap

The trap here is that candidates often confuse AWS Config or CloudTrail as tools for collecting instance-level forensic data, when in fact they are governance and logging services that do not provide direct access to instance memory or disk contents.

115
MCQeasy

A security engineer is reviewing AWS CloudTrail and notices `AssumeRole` API calls to a role that should not be assumed by the source identity. What is the FIRST step in the incident response process?

A.Enable AWS GuardDuty to detect future anomalies.
B.Delete the IAM role immediately.
C.Investigate the source IP address and user agent of the `AssumeRole` calls.
D.Disable the AWS account and contact support.
AnswerC

Investigating the source IP address and user agent of the AssumeRole calls is the correct first step because those fields are directly logged in the CloudTrail management event and let the engineer determine whether the role was assumed from an expected corporate network and application versus an unknown external host. This information can be cross-referenced with VPC Flow Logs, AWS WAF logs, or threat intelligence to establish a baseline of legitimate usage and scope the incident. It preserves all evidence while enabling a quick threat verdict.

Why this answer

The first step in any incident response process is to investigate and gather evidence to understand the scope and impact of the potential security event. Option C is correct because analyzing the source IP address and user agent of the `AssumeRole` API calls provides critical forensic data to determine if the activity is malicious or a false positive, without disrupting operations or destroying evidence. AWS CloudTrail logs these details, enabling the security engineer to trace the origin of the unauthorized assumption before taking any containment or remediation actions.

Exam trap

The trap here is that candidates often jump to containment actions like deleting the role or disabling the account, forgetting that the first step in incident response is always to investigate and gather evidence to confirm the threat and preserve forensic data.

How to eliminate wrong answers

Option A is wrong because enabling AWS GuardDuty is a proactive detection measure, not an immediate first step during an active incident; it would not help investigate the existing suspicious `AssumeRole` calls already logged. Option B is wrong because immediately deleting the IAM role could destroy forensic evidence, disrupt legitimate workloads that depend on the role, and is a hasty containment action that should only follow a thorough investigation. Option D is wrong because disabling the entire AWS account is an extreme, disproportionate response that would cause a complete denial of service for all users and applications, and contacting support is not a technical first step for investigation.

116
MCQeasy

A security engineer is investigating a potential compromise of an EC2 instance. The engineer needs to capture network traffic to and from the instance for forensic analysis. Which AWS service should be used to capture this traffic?

A.AWS Config
B.AWS Network Firewall
C.VPC Traffic Mirroring
D.Amazon Inspector
AnswerC

VPC Traffic Mirroring copies the full packet content from one or more elastic network interfaces (ENIs) of an EC2 instance and forwards it to a target such as a security appliance, an NLB, or an ENI that hosts a packet capture tool. This gives investigators the raw traffic needed to detect and analyze anomalies, lateral movement, or exfiltration without affecting the workload's primary network path. It is the correct choice when the goal is to capture and inspect actual network packets for a suspected compromise.

Why this answer

VPC Traffic Mirroring captures and inspects network traffic at the Elastic Network Interface (ENI) level by copying packets from a source ENI to a target, such as a Network Load Balancer or another ENI. This allows the security engineer to perform deep packet inspection and forensic analysis without impacting the production traffic flow. It supports both IPv4 and IPv6 traffic and can filter by protocol, port, or packet direction, making it ideal for incident response scenarios.

Exam trap

The trap here is that candidates confuse VPC Traffic Mirroring with AWS Network Firewall, assuming that a firewall inherently captures traffic, but Network Firewall only inspects and filters traffic in-line without providing a separate packet capture stream for forensic analysis.

How to eliminate wrong answers

Option A is wrong because AWS Config is a resource inventory and compliance auditing service that records configuration changes, not network traffic. Option B is wrong because AWS Network Firewall is a managed firewall service that filters traffic at the VPC level but does not capture or mirror traffic for forensic analysis; it blocks or allows traffic based on rules. Option D is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and unintended network exposure, not a packet capture tool.

117
Multi-Selectmedium

A security engineer is designing a threat detection solution for a multi-account AWS environment. The engineer needs to detect and respond to suspicious API activity across all accounts. Which TWO services should be used together to achieve this? (Choose two.)

Select 2 answers
A.Amazon CloudWatch
B.Amazon GuardDuty
C.AWS Security Hub
D.Amazon Inspector
E.AWS Config
AnswersB, C

Amazon GuardDuty is a machine-learning and anomaly-detection security service that continuously analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS query logs to identify unauthorized behavior, crypto-mining, credential compromise, and API abuse. It generates severity-ranked findings using threat intelligence and behavioral modeling, making it the core service for a threat detection solution.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior across AWS accounts, including suspicious API activity. By enabling GuardDuty in all accounts and aggregating findings to a central administrator account, it provides the necessary detection layer for multi-account environments.

Exam trap

The trap here is that candidates often confuse AWS Security Hub (a findings aggregation and compliance service) with a primary detection tool, but Security Hub itself does not generate threat detections—it ingests findings from GuardDuty and other services, so both are needed together.

118
MCQmedium

Refer to the exhibit. A security engineer runs this AWS CLI command to investigate root user logins. The output shows a successful ConsoleLogin event. What should the engineer do next to improve security?

A.Delete the root user account.
B.Disable the root user password and require all logins via IAM users.
C.Enable IAM Access Analyzer to detect and alert on root user activity.
D.Enable multi-factor authentication (MFA) for the root user.
AnswerD

A successful root ConsoleLogin without MFA leaves the account's most privileged identity protected by a password alone. Enabling MFA for the root user adds a second authentication factor, satisfying the requirement to strengthen security after confirming root console access.

Why this answer

Enabling multi-factor authentication (MFA) for the root user adds an extra layer of security, making it much harder for an attacker to compromise the root account even if the password is known. While AWS recommends avoiding routine use of the root user, the root account cannot be deleted; instead, securing it with MFA is a best practice. Options A and B are incorrect because root user cannot be deleted, and disabling the password alone does not prevent root user login via password recovery or other methods.

Option C is incorrect because IAM Access Analyzer analyzes resource-based policies for unintended access, not root user activity; it does not generate findings for ConsoleLogin events.

Exam trap

The trap is that candidates may confuse IAM Access Analyzer (which analyzes resource policies) with AWS CloudTrail or Amazon GuardDuty (which can monitor root user activity). The question asks for the next step after detecting a root user login, which is to secure the root user with MFA, not to enable a service that does not monitor such events.

How to eliminate wrong answers

Option A is wrong because the root user account cannot be deleted; it is a permanent AWS account owner with immutable privileges. Option B is wrong because disabling the root user password does not prevent root user access via other methods (e.g., access keys) and does not address the need for monitoring; AWS requires root user credentials for certain account management tasks. Option D is wrong because while enabling MFA for the root user is a best practice, the question specifically asks what to do next after observing a successful ConsoleLogin event—MFA does not provide detection or alerting for root user activity, which is the immediate security concern.

119
MCQeasy

A security team detects that an IAM user's access keys are being used from an unusual geographic location. Which AWS service provides this type of anomaly detection?

A.Amazon Inspector
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerC

Amazon GuardDuty is a continuous threat detection service that uses machine learning and threat intelligence to analyze AWS API activity from CloudTrail, VPC Flow Logs, and DNS logs. It specifically identifies anomalous IAM user behavior, such as a user's access key being used from a geographically distant location or at impossible travel speeds, which strongly suggests the key has been stolen. GuardDuty then generates a security finding that can be routed to a response playbook, making it the correct service for detecting this type of credential misuse.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, including anomalous API calls from unusual geographic locations. It uses machine learning models and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS logs, making it the correct service for detecting IAM user access key usage from an unexpected region.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, but CloudTrail only records events and does not analyze them for anomalies—GuardDuty is the service that performs the analysis and generates findings.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not for monitoring IAM user activity or geographic anomalies. Option B is wrong because AWS CloudTrail is a governance, compliance, and auditing service that records API activity but does not perform real-time anomaly detection or flag unusual geographic patterns on its own. Option D is wrong because AWS Config is a resource inventory and compliance service that evaluates resource configurations against rules, not a threat detection service for anomalous user behavior.

120
MCQmedium

A company uses Amazon GuardDuty and AWS Security Hub. The security team wants to automatically remediate high-severity GuardDuty findings that indicate an EC2 instance is communicating with a known command and control (C&C) server. The remediation should isolate the instance by modifying the security group to deny all inbound and outbound traffic. Which solution is the most efficient?

A.Use Amazon CloudWatch Events to directly modify the security group when a GuardDuty finding is published.
B.Send Security Hub findings to Amazon EventBridge, which triggers a Lambda function to modify the security group.
C.Configure GuardDuty to automatically update the security group when a finding is generated.
D.Create an AWS Config rule that triggers a Lambda function when a security group change is detected.
AnswerB

This is the correct architecture because Security Hub ingests GuardDuty findings as security findings and can forward them to an EventBridge bus. An EventBridge rule can filter for specific finding types or severities and trigger a Lambda function, which then uses the AWS SDK to modify the security group. This decouples detection from remediation and is a standard, supported pattern for automated response to security findings.

Why this answer

It leverages Security Hub as a central aggregation point for GuardDuty findings, then uses EventBridge to trigger a Lambda function that modifies the security group. This is the most efficient architecture as Security Hub normalizes findings from multiple sources, and EventBridge provides reliable, low-latency event routing to Lambda for custom remediation logic without requiring direct GuardDuty-to-security-group integration.

Exam trap

The trap here is that candidates assume GuardDuty can directly modify security groups (Option C) or that CloudWatch Events can directly perform API actions (Option A), when in reality both require a Lambda function as an intermediary to execute the remediation logic.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events (now part of EventBridge) can trigger on GuardDuty findings, but directly modifying a security group from a CloudWatch Events rule is not possible — CloudWatch Events cannot execute API calls to modify security groups; it only routes events to targets like Lambda. Option C is wrong because GuardDuty does not have native capability to automatically modify security groups; it only generates findings and can send them to EventBridge or Security Hub, but cannot directly perform remediation actions. Option D is wrong because an AWS Config rule that triggers on security group changes is reactive and does not address the requirement to automatically remediate the GuardDuty finding; it would only detect changes after they occur, not initiate the isolation based on the finding.

121
MCQeasy

Which AWS service can be used to detect and alert on suspicious network traffic patterns within a VPC, such as port scanning or unusual outbound traffic?

A.AWS WAF
B.Amazon GuardDuty
C.AWS Network Firewall
D.VPC Flow Logs
AnswerB

Amazon GuardDuty is a managed threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to continuously monitor VPC Flow Logs, DNS logs, and CloudTrail event logs. It identifies suspicious activity such as reconnaissance, credential compromise, or data exfiltration, and automatically generates findings that can trigger CloudWatch Events. GuardDuty is purpose-built to detect and alert on a wide range of security threats without requiring manual analysis or custom logic.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors VPC Flow Logs, DNS logs, and CloudTrail events to identify suspicious network traffic patterns such as port scanning, unusual outbound traffic, and other malicious activities. It uses machine learning, anomaly detection, and integrated threat intelligence to generate security alerts without requiring manual rules or signatures.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (a raw data source) with a detection service, or assume AWS Network Firewall's stateful inspection includes anomaly-based alerting, when in fact GuardDuty is the only service that provides automated threat detection and alerting for network patterns like port scanning and unusual outbound traffic.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting at the application layer (HTTP/HTTPS), not for detecting network-level anomalies like port scanning or unusual outbound traffic within a VPC. Option C is wrong because AWS Network Firewall is a stateful managed firewall that enforces network traffic rules (e.g., allow/deny based on IP, port, protocol) but does not perform threat detection or anomaly-based alerting for patterns like port scanning; it requires explicit rule configuration. Option D is wrong because VPC Flow Logs is a raw logging feature that captures metadata about IP traffic (e.g., source/destination IP, port, protocol) but does not analyze, detect, or alert on suspicious patterns; it only provides the data that services like GuardDuty consume.

122
Multi-Selecthard

Which TWO steps are part of the forensic acquisition process for an EC2 instance suspected of being compromised?

Select 2 answers
A.Stop the instance immediately to prevent further damage.
B.Enable termination protection on the instance.
C.Terminate the instance to ensure the threat is contained.
D.Capture the instance's memory using a forensic tool.
E.Create a snapshot of the root EBS volume.
AnswersD, E

Capturing memory using a forensic tool is a correct forensic acquisition step because RAM contains volatile data such as running processes, open network connections, loaded kernel modules, and decryption keys that are lost when power is removed. In AWS, memory capture must be performed on the live instance, typically using tools like LiME or a memory dump utility, before any shutdown or snapshot. This preserves the most ephemeral evidence first, following the order of volatility.

Why this answer

Capturing the instance's memory using a forensic tool (such as LiME or F-Response) preserves volatile data—including running processes, network connections, and encryption keys—that would be lost if the instance were stopped or terminated. This is a critical step in the forensic acquisition process to gather evidence of compromise without altering the system state.

Exam trap

The trap here is that candidates often confuse incident response containment (stopping or terminating the instance) with forensic acquisition, which requires preserving both volatile memory and disk state before any changes are made.

123
MCQeasy

A company's security team wants to detect unauthorized S3 bucket access attempts in real time. Which service should they use to generate alerts when an IAM user attempts to access a bucket without proper permissions?

A.Amazon GuardDuty
B.AWS CloudTrail with CloudWatch alarms
C.S3 server access logs
D.AWS Config
AnswerB

AWS CloudTrail records all S3 API requests as event history, and by enabling data events, it captures object-level operations such as GetObject and PutObject. By delivering these events to CloudWatch Logs, you can create metric filters that match S3 error responses such as AccessDenied (403) or AuthorizationError, and then attach a CloudWatch alarm to trigger SNS notifications. Because CloudTrail pushes events to CloudWatch Logs near real time, it enables immediate detection of unauthorized access attempts. This makes it the most suitable option for real-time alerting on actual access denials.

Why this answer

AWS CloudTrail logs all API calls made to S3, including access denied errors. By creating a CloudWatch alarm on the `S3 AccessDenied` event in CloudTrail logs, the security team can receive real-time alerts when an IAM user attempts to access a bucket without proper permissions. This approach directly captures the unauthorized attempt at the API level, enabling immediate detection.

Exam trap

The trap here is that candidates often choose Amazon GuardDuty because it is associated with threat detection, but they overlook that GuardDuty does not provide real-time, per-user unauthorized access alerts for S3; instead, CloudTrail with CloudWatch alarms directly captures the specific API error event needed for this use case.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not generate real-time alerts specifically for individual IAM user unauthorized S3 access attempts; it focuses on broader threat patterns. Option C is wrong because S3 server access logs are delivered on a best-effort basis, typically with a delay of several hours, making them unsuitable for real-time alerting. Option D is wrong because AWS Config is a service for evaluating resource compliance and tracking configuration changes, not for monitoring real-time API access attempts or generating alerts for unauthorized access.

124
MCQmedium

A company uses AWS CloudTrail to log all API activity. The security team needs to retain the logs for 7 years and ensure they are tamper-proof. Additionally, the team must be able to query the logs for investigations. Which solution meets these requirements?

A.Store logs in AWS CloudTrail Lake and use the built-in query feature.
B.Store logs in Amazon CloudWatch Logs with a retention policy of 7 years.
C.Store logs in an Amazon S3 bucket with standard settings and use Amazon S3 Select for querying.
D.Store logs in an Amazon S3 bucket with S3 Object Lock enabled and query using Amazon Athena.
AnswerD

The correct solution combines S3 Object Lock in either governance or compliance mode with Amazon Athena. Object Lock enforces a retention period that prevents any user — including an AWS account root user — from deleting or overwriting log files, and Athena can directly query the partitioned S3 logs using standard SQL through the Glue Data Catalog. This yields a durable, tamper-evident, serverless analytics pipeline for long-term CloudTrail log storage.

Why this answer

Amazon S3 Object Lock provides a write-once-read-many (WORM) model that prevents logs from being deleted or overwritten, ensuring tamper-proof retention for 7 years. Amazon Athena allows querying the logs directly in S3 using standard SQL, meeting the investigation requirement without needing to move data.

Exam trap

The trap here is that candidates often choose CloudTrail Lake (Option A) because it offers built-in querying, but they overlook the tamper-proof requirement, which only S3 Object Lock can guarantee for long-term retention.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail Lake is designed for short-term retention and analysis (up to 7 years but with limited query capabilities and higher cost), and it does not provide native tamper-proof controls like S3 Object Lock. Option B is wrong because Amazon CloudWatch Logs has a maximum retention period of 10 years, but it does not offer tamper-proof features; logs can be deleted or modified by authorized users, and querying is limited to CloudWatch Logs Insights, which is not as flexible as Athena for large-scale analysis. Option C is wrong because storing logs in an S3 bucket with standard settings does not prevent tampering—logs can be overwritten or deleted—and Amazon S3 Select is limited to simple filtering and cannot handle complex SQL queries needed for thorough investigations.

125
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all CloudTrail trails are enabled and logging to a central S3 bucket. They need to detect any account that disables or modifies its CloudTrail trail. Which approach meets these requirements with the least operational overhead?

A.Use AWS Config rules with an aggregator in the management account to evaluate CloudTrail configuration across all accounts.
B.Enable CloudTrail Insights in all accounts to detect unusual activity.
C.Enable IAM Access Analyzer in each account to monitor CloudTrail changes.
D.Create a Lambda function that periodically checks CloudTrail status in each account via the API.
AnswerA

AWS Config rules can run managed or custom rules against the configuration of CloudTrail trails, and an aggregator in the management account lets you view compliance results from all member accounts in a single dashboard. When a trail is misconfigured or deleted, the rule evaluates the change and can trigger an Amazon EventBridge event to notify administrators. This is the only option that provides continuous, native, multi-account governance without writing custom monitoring code or relying on external scheduling.

Why this answer

AWS Config rules with an aggregator in the management account can evaluate CloudTrail configuration across all accounts in AWS Organizations without deploying per-account resources. The aggregator collects configuration snapshots and changes from member accounts, allowing a single managed rule (e.g., cloud-trail-enabled) to detect when a trail is disabled or modified. This approach minimizes operational overhead because it uses native AWS services with no custom code or cross-account IAM roles to manage.

Exam trap

The trap here is that candidates may think a custom Lambda function (Option D) is necessary for cross-account monitoring, overlooking that AWS Config with an aggregator natively supports multi-account evaluation with far less operational overhead.

How to eliminate wrong answers

Option B is wrong because CloudTrail Insights detects unusual API activity (e.g., write events with error rates), not configuration changes to the trail itself; it does not monitor whether a trail is enabled or modified. Option C is wrong because IAM Access Analyzer analyzes resource-based policies for external access, not CloudTrail trail configuration or status; it cannot detect trail disablement or modification. Option D is wrong because a Lambda function that periodically checks CloudTrail status via the API requires custom code, cross-account IAM roles, and scheduling infrastructure, resulting in higher operational overhead compared to a managed AWS Config rule with an aggregator.

126
MCQhard

Your organization uses AWS Organizations with 50 member accounts. You are the security administrator for the root account. You have enabled AWS CloudTrail in all accounts and centralized the logs in an S3 bucket in the root account. You also enabled Amazon GuardDuty in the root account and have delegated an administrator account. Recently, you received an alert from GuardDuty about a potential credential compromise in a member account. The finding indicates that an IAM user in that account made an API call from an unusual IP address. You need to quickly gather all CloudTrail events for that user from the last 30 days across all accounts. The logs are stored in a single S3 bucket with a prefix structure like 'AWSLogs/<account-id>/CloudTrail/<region>/<year>/<month>/<day>'. What is the MOST efficient way to query these logs?

A.Use Amazon Athena to query the CloudTrail logs by creating a table partitioned by account, region, and date.
B.Enable AWS CloudTrail Lake and create a new event data store that includes the historical logs.
C.Download all log files from the S3 bucket for the last 30 days and parse them locally.
D.Use Amazon CloudWatch Logs Insights to query the logs from the member account.
AnswerA

Athena is the correct choice because CloudTrail logs are stored as gzipped JSON objects in an S3 bucket, and Athena can directly query that data with standard SQL through a table defined in the AWS Glue Data Catalog. Partitioning the table by account, region, and date lets Athena perform partition pruning, so only the relevant log files are scanned, which minimizes both cost and query latency. Because the logs for all member accounts are centrally delivered to a single S3 bucket in the management account, Athena provides a serverless, cross-account query capability without needing to move or transform the data.

Why this answer

Amazon Athena is the most efficient way to query CloudTrail logs stored in S3 because it allows you to run SQL queries directly on the data without moving or downloading it. By creating a table partitioned by account, region, and date, you can quickly filter for the specific IAM user's events across all 50 accounts for the last 30 days, leveraging partition pruning to scan only the relevant log files. This approach minimizes data scanned and cost, while providing near-instant results.

Exam trap

The trap here is that candidates may think CloudTrail Lake (Option B) is the only way to query CloudTrail logs efficiently, but Athena is actually the native, cost-effective solution for querying CloudTrail logs stored in S3 without additional ingestion steps.

How to eliminate wrong answers

Option B is wrong because CloudTrail Lake requires you to create a new event data store, which would need to ingest the historical logs from S3, incurring additional costs and time for data ingestion and indexing, making it less efficient than directly querying the existing S3 logs with Athena. Option C is wrong because downloading all log files for 30 days from a multi-account S3 bucket would be extremely time-consuming, bandwidth-intensive, and impractical for 50 accounts, and parsing them locally would require significant manual effort and storage. Option D is wrong because CloudWatch Logs Insights can only query logs that are sent to CloudWatch Logs, but the CloudTrail logs are stored in S3, not in CloudWatch Logs, and even if they were, CloudWatch Logs Insights cannot query logs across multiple accounts from a single query.

127
Multi-Selecteasy

Which TWO are best practices for securing an AWS account's root user? (Choose two.)

Select 2 answers
A.Share the root user credentials with the security team.
B.Delete the root user account.
C.Enable multi-factor authentication (MFA) on the root user.
D.Delete any access keys associated with the root user.
E.Use the root user for daily administrative tasks.
AnswersC, D

Enabling multi-factor authentication (MFA) on the root user is a critical AWS security best practice because the root user bypasses all IAM policies and has unrestricted access to all services and resources. A stolen or guessed root password alone is insufficient for an attacker if MFA is present; they would also need the MFA device, which is typically a hardware token or virtual authenticator app. AWS explicitly lists root-user MFA as the first step in account hardening, and it also reduces the risk of accidental destructive actions by requiring a second factor.

Why this answer

Enabling multi-factor authentication (MFA) on the root user adds a second layer of security beyond the password and is the single most effective control to prevent unauthorized access to the most privileged account in an AWS environment. AWS strongly recommends MFA for the root user as it mitigates the risk of credential theft or compromise, which could lead to full account takeover and irreversible damage.

Exam trap

The trap here is that candidates may think deleting the root user (Option B) is possible or that sharing credentials with a team (Option A) is a valid security practice, when in fact AWS prohibits deletion of the root user and sharing credentials violates security best practices.

128
MCQeasy

A company uses Amazon RDS for its database. The security team needs to detect when a database instance is started or stopped outside of maintenance windows. Which AWS service should the team use to monitor these API calls?

A.Amazon CloudWatch
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
AnswerC

AWS CloudTrail is the correct service because it records all management events, including every RDS API call such as StartDBInstance and StopDBInstance. Each CloudTrail event contains the identity of the caller, the time of the action, the source IP address, and request parameters, enabling a complete audit trail. You can also configure CloudTrail to deliver logs to Amazon S3 and set up EventBridge rules to trigger real-time alerts whenever a specific RDS API action occurs. This makes CloudTrail the definitive source for monitoring and alerting on RDS instance lifecycle changes.

Why this answer

AWS CloudTrail is the correct service because it records API activity in your AWS account, including StartDBInstance and StopDBInstance calls from the RDS service. By monitoring CloudTrail logs, the security team can detect when a database instance is started or stopped outside of maintenance windows, as each API call is logged with a timestamp and user identity. CloudTrail is specifically designed for auditing API calls, making it the appropriate tool for this use case.

Exam trap

The trap here is that candidates confuse CloudWatch's ability to create alarms on CloudTrail events with CloudWatch itself being the service that records API calls, but CloudWatch only processes logs delivered by CloudTrail and cannot natively capture API activity without CloudTrail as the source.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms, but it does not natively capture or record API calls like StartDBInstance or StopDBInstance; it can only alert on CloudTrail-delivered events via a metric filter, not directly detect the API calls themselves. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious activity, but it is not designed for custom operational monitoring of specific API calls like database start/stop events; it focuses on security threats, not operational compliance. Option D is wrong because AWS Config is a configuration tracking and compliance service that evaluates resource configurations against rules, but it does not monitor real-time API calls; it can detect configuration changes (e.g., a DB instance being stopped) only after they occur via configuration changes, not the API call event itself.

129
MCQeasy

A security engineer needs to detect and respond to potential credential theft where an IAM user's access key is being used from an unusual geographic location. Which AWS service should be used to generate alerts based on this anomaly?

A.AWS IAM Access Analyzer
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerC

Amazon GuardDuty is a continuous threat detection service that consumes CloudTrail management and data events, VPC flow logs, and DNS logs, then applies anomaly detection and threat intelligence to identify suspicious API activity and credential compromise. It uses machine learning to baseline normal behavior and can trigger findings for events like unusual login patterns, account compromises, or API calls made from known malicious IPs. This directly satisfies the requirement to detect and respond to potential behavioral threats, making it the correct choice.

Why this answer

Amazon GuardDuty is the correct choice because it is a threat detection service that uses machine learning and integrated threat intelligence to identify anomalous behavior, such as an IAM access key being used from an unusual geographic location. It specifically analyzes CloudTrail management and data events, VPC flow logs, and DNS logs to detect credential theft patterns like a new geolocation or an impossible travel scenario, and can trigger alerts via Amazon EventBridge or SNS for automated response.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, assuming that CloudTrail alone can generate alerts for geographic anomalies, when in reality it only provides raw logs that require additional analysis services like GuardDuty or custom solutions to detect and alert on such patterns.

How to eliminate wrong answers

Option A is wrong because AWS IAM Access Analyzer is designed to identify resources shared with external entities by analyzing resource-based policies, not to detect anomalous usage patterns like geographic anomalies in access key usage. Option B is wrong because AWS CloudTrail is a logging service that records API activity but does not perform real-time anomaly detection or generate alerts based on unusual geographic locations; it would require additional custom logic (e.g., Athena queries or Lambda functions) to analyze the logs for such patterns. Option D is wrong because AWS Config is a configuration management and compliance service that tracks resource configuration changes and evaluates rules, not a threat detection service capable of identifying credential theft or geographic anomalies in IAM user activity.

130
MCQeasy

A security engineer needs to ensure that any changes to an S3 bucket's public access settings are immediately detected and an alert is sent. Which combination of AWS services should be used?

A.Amazon GuardDuty and AWS Lambda
B.Amazon CloudWatch Logs and Amazon SNS
C.AWS CloudTrail and Amazon CloudWatch Logs
D.AWS Config and AWS Lambda
AnswerD

AWS Config natively tracks configuration items for S3 buckets and applies managed rules such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited to flag noncompliant public access settings. When a change makes a bucket noncompliant, Config can invoke an AWS Lambda function through an SNS topic or a custom rule, allowing the Lambda to send an alert or automatically remediate the issue. This pairing provides the state-based monitoring and action-taking pipeline the requirement asks for.

Why this answer

AWS Config continuously monitors and records changes to AWS resource configurations, including S3 bucket public access settings. By creating a Config rule that triggers on changes to the `PublicAccessBlockConfiguration` or bucket ACLs, you can invoke an AWS Lambda function via an Amazon SNS topic to send an alert. This combination provides real-time detection and automated response to unauthorized public access changes.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with AWS Config (which evaluates configuration compliance), leading them to choose Option C, but CloudTrail alone cannot trigger alerts without additional services like CloudWatch Logs and Lambda, and it lacks the continuous compliance evaluation that AWS Config provides.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity (e.g., unusual API calls or compromised credentials), not for configuration changes to S3 bucket public access settings. Option B is wrong because Amazon CloudWatch Logs can store log data but does not natively detect or alert on S3 configuration changes; it would require additional services like CloudTrail to capture the events, and the combination lacks the rule-based evaluation needed for immediate detection. Option C is wrong because AWS CloudTrail logs API calls (including changes to S3 bucket policies), but CloudTrail alone does not provide real-time alerting; while you can create a metric filter on CloudWatch Logs, this setup requires manual configuration and does not natively evaluate configuration compliance like AWS Config does, and it lacks the automated remediation capability of AWS Lambda.

131
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team uses AWS Security Hub to consolidate findings. They notice that a critical finding in the production account is not being aggregated in Security Hub. The finding is generated by Amazon GuardDuty. What is the MOST likely cause?

A.Amazon GuardDuty is not enabled in the production account.
B.The IAM role for Security Hub does not have permissions to read GuardDuty findings.
C.AWS Config is not enabled in the production account.
D.VPC Flow Logs are not enabled in the production account.
AnswerA

GuardDuty is the source service that produces the security findings in question. Security Hub is purely an aggregator: it ingests findings from GuardDuty only when GuardDuty is actually enabled and actively detecting threats in the account. If GuardDuty is not enabled in the production account, it generates no findings, so Security Hub has nothing to aggregate, regardless of how correctly Security Hub and cross-account roles are configured. Enabling Security Hub does not automatically enable GuardDuty, so this is the root cause.

Why this answer

Amazon Security Hub aggregates findings from enabled security services across accounts. For GuardDuty findings to appear in Security Hub, GuardDuty must be enabled in the account where the finding is generated. If GuardDuty is not enabled in the production account, it cannot produce findings for Security Hub to consume, which is the most likely cause of the missing critical finding.

Exam trap

The trap here is that candidates may assume Security Hub automatically enables or integrates with all security services across accounts, but in reality, each service (like GuardDuty) must be individually enabled in each account for its findings to be aggregated.

How to eliminate wrong answers

Option B is wrong because Security Hub uses a service-linked role (AWSServiceRoleForSecurityHub) that automatically includes permissions to read findings from GuardDuty via the BatchImportFindings API; an explicit IAM role for reading GuardDuty findings is not required. Option C is wrong because AWS Config is not a prerequisite for Security Hub to aggregate GuardDuty findings; Security Hub can ingest GuardDuty findings independently of Config. Option D is wrong because VPC Flow Logs are not a source of findings for Security Hub; they are used by GuardDuty for anomaly detection but are not required for Security Hub to receive GuardDuty findings.

132
MCQmedium

An organization uses AWS Organizations and wants to centrally manage Amazon GuardDuty across multiple accounts. What is the correct architecture?

A.Enable GuardDuty only in the master account; it will automatically monitor all member accounts.
B.Use AWS CloudFormation StackSets to deploy GuardDuty in all accounts and regions.
C.Designate a delegated administrator account in Organizations and enable GuardDuty in that account.
D.Enable GuardDuty in each region separately and use cross-region aggregation.
AnswerC

The correct approach is to designate a delegated administrator account in AWS Organizations for GuardDuty. This delegated admin can enable GuardDuty for all member accounts, manage their detectors, and view aggregated findings centrally without needing per-account invitations. It is the only method that provides a single admin control plane over multi-account GuardDuty coverage and findings.

Why this answer

AWS Organizations allows you to designate a delegated administrator account for Amazon GuardDuty, which can then centrally manage GuardDuty across all member accounts in the organization. This architecture simplifies enabling GuardDuty and managing findings without needing to configure each account individually, as the delegated administrator can enable GuardDuty for all accounts in the organization from a single point.

Exam trap

The trap here is that candidates often assume enabling GuardDuty in the master account automatically covers all member accounts (Option A), but in reality, GuardDuty requires explicit member account management or a delegated administrator setup, and the delegated administrator model is the recommended architecture for centralized management in Organizations.

How to eliminate wrong answers

Option A is wrong because enabling GuardDuty only in the master account does not automatically monitor member accounts; GuardDuty must be explicitly enabled in each account, or a delegated administrator must be used to manage member accounts centrally. Option B is wrong because while AWS CloudFormation StackSets can deploy resources across accounts and regions, GuardDuty is a regional service that requires a centralized management approach via Organizations, and StackSets do not provide the native integration for cross-account threat detection management that a delegated administrator does. Option D is wrong because GuardDuty findings are regional by default, and cross-region aggregation is not a built-in feature; instead, you would need to use a delegated administrator to centrally view findings from multiple regions, but the correct architecture for multi-account management is through Organizations delegation, not separate per-region enablement.

133
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to centrally collect and analyze VPC Flow Logs from all accounts. The team has set up a central logging account with an S3 bucket that has a bucket policy allowing cross-account writes. However, VPC Flow Logs from member accounts are not appearing. What is the most likely cause?

A.AWS CloudTrail is not enabled in the member accounts.
B.The VPC Flow Logs must be delivered to CloudWatch Logs first, then exported to S3.
C.VPC Flow Logs cannot be published directly to an S3 bucket in a different account. The logs must be published to a bucket in the same account as the VPC, and then replicated to the central account.
D.The S3 bucket policy does not allow the s3:PutObject action for the member accounts.
AnswerC

When you create a VPC Flow Log, the destination S3 bucket must be in the same AWS account as the VPC; Amazon VPC does not support publishing flow logs directly to an S3 bucket in a different account. To aggregate logs from member accounts into a central account, you must first deliver them to an S3 bucket in each member account, then configure S3 replication or another copy mechanism to move the logs to the central bucket. Because the company attempted direct cross-account delivery, the flow logs fail to appear in the central destination.

Why this answer

VPC Flow Logs cannot be published directly to an S3 bucket in a different AWS account. The destination S3 bucket must reside in the same account as the VPC from which the logs are generated. To centralize logs, you must first publish them to a bucket in the same account as the VPC, then use S3 cross-region replication or a similar mechanism to copy them to the central logging account.

This is a fundamental limitation of the VPC Flow Logs service.

Exam trap

The trap here is that candidates assume a properly configured bucket policy with cross-account permissions is sufficient, but AWS explicitly restricts VPC Flow Logs to same-account S3 destinations, making the policy irrelevant for direct cross-account delivery.

How to eliminate wrong answers

Option A is wrong because CloudTrail is not required for VPC Flow Logs; they are independent services and CloudTrail's absence does not prevent Flow Log delivery. Option B is wrong because VPC Flow Logs can be published directly to an S3 bucket without first sending them to CloudWatch Logs; the delivery destination can be either CloudWatch Logs or S3. Option D is wrong because the question states the bucket policy already allows cross-account writes, so the s3:PutObject permission is not the issue; the core problem is the architectural limitation of cross-account direct delivery.

134
MCQmedium

Your company has a single AWS account with a production VPC that contains several EC2 instances running a web application. The security team has enabled Amazon GuardDuty and AWS CloudTrail. Recently, GuardDuty reported a finding 'UnauthorizedAccess:EC2/TorClient' for one of the instances. The finding indicates that the instance is making connections to Tor exit nodes. You need to investigate and contain the incident. The instance is critical to the application and cannot be terminated. You have a forensic analysis instance in a separate security group. What should you do FIRST?

A.Isolate the instance by modifying its security group to remove all inbound and outbound rules except for the forensic analysis instance.
B.Terminate the instance immediately and launch a replacement.
C.Take an EBS snapshot of the instance's root volume for analysis.
D.Use AWS Systems Manager Run Command to install a forensic agent on the instance.
AnswerA

This is the correct immediate response because modifying the security group to remove all inbound and outbound rules—except for a single forensic analysis instance—instantly severs the attacker's network channel while preserving the running instance for investigation. It halts data exfiltration in real time and prevents the attacker from issuing further commands over the network, unlike a snapshot that captures disk state but does not stop ongoing activity. The isolated instance retains volatile evidence like process memory and active network connections, which a forensic analyst can later harvest using controlled, trusted access.

Why this answer

The first step in incident response for a compromised instance that cannot be terminated is to contain the threat by isolating it from the network. Modifying the security group to remove all inbound and outbound rules except for a specific forensic analysis instance prevents the compromised EC2 instance from communicating with Tor exit nodes or other external hosts, while still allowing controlled forensic access. This containment is immediate and reversible, aligning with the AWS incident response best practice of 'isolate first, investigate later'.

Exam trap

The trap here is that candidates may rush to collect forensic evidence (snapshot or agent) before containing the threat, failing to recognize that the first priority in incident response is to stop the active malicious behavior (outbound Tor connections) to prevent data exfiltration or further compromise.

How to eliminate wrong answers

Option B is wrong because the instance is critical to the application and cannot be terminated, and immediate termination would destroy volatile data (e.g., running processes, memory contents) needed for forensic analysis. Option C is wrong because taking an EBS snapshot is a valid forensic step, but it should be performed after containment to prevent the compromised instance from continuing malicious outbound connections during the snapshot process. Option D is wrong because installing a forensic agent via Systems Manager Run Command requires network connectivity and could be blocked or tampered with by the malware, and it does not address the immediate need to stop the outbound Tor connections.

135
MCQeasy

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer wants to designate a delegated administrator account to manage GuardDuty for all member accounts. Which AWS service must be used to enable GuardDuty for all accounts?

A.AWS CloudFormation StackSets
B.AWS Control Tower
C.AWS Config
D.AWS Organizations
AnswerD

AWS Organizations is the foundation for GuardDuty's multi-account management: when you designate a delegated administrator and enable GuardDuty for the organization, GuardDuty automatically provisions detectors in all current and future member accounts and centrally aggregates their findings. This native integration lets you onboard new accounts without manual invites and gives you unified visibility through the administrator account, making Organizations the correct answer.

Why this answer

AWS Organizations is the foundational service required to designate a delegated administrator for Amazon GuardDuty in a multi-account environment. GuardDuty integrates directly with Organizations to allow a management account to enable GuardDuty for all member accounts and delegate administration to a specified account, which then manages threat detection across the organization without needing additional services.

Exam trap

The trap here is that candidates may confuse AWS Organizations as merely an organizational tool and think they need a separate service like CloudFormation StackSets or Control Tower to enable GuardDuty across accounts, but GuardDuty natively integrates with Organizations for delegated administration and automatic enablement.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation StackSets is used to deploy infrastructure as code across multiple accounts and regions, but it is not required or used to enable GuardDuty or designate a delegated administrator; GuardDuty's multi-account setup is managed through the GuardDuty console or API using Organizations. Option B is wrong because AWS Control Tower provides a governance framework for landing zones and uses Account Factory and preventive/ detective guardrails, but it does not directly enable GuardDuty or designate a delegated administrator; GuardDuty integration is handled via Organizations, not Control Tower. Option C is wrong because AWS Config is a service for resource inventory, configuration history, and compliance rules, not for enabling GuardDuty or managing delegated administration; GuardDuty's multi-account enablement relies on Organizations APIs, not Config.

136
MCQmedium

A company has enabled Amazon GuardDuty in all accounts within AWS Organizations. The security team wants to view aggregated findings from all accounts in a single dashboard. Which service should the team use?

A.Amazon CloudWatch
B.Amazon Inspector
C.Amazon Macie
D.AWS Security Hub
AnswerD

AWS Security Hub is a cloud security posture management service that aggregates security findings from GuardDuty, Inspector, Macie, and other AWS services into a consistent format. It supports cross-account aggregation through AWS Organizations, enabling a consolidated view of threat findings across all accounts. Security Hub also runs continuous security standard checks and enables automated remediation, making it the correct service to centralize GuardDuty findings.

Why this answer

AWS Security Hub is the correct service because it provides a single dashboard that aggregates and prioritizes security findings from multiple AWS services, including Amazon GuardDuty, across all accounts in an AWS Organization. It normalizes findings from GuardDuty, Inspector, Macie, and other sources into the AWS Security Finding Format (ASFF), enabling centralized viewing and automated response workflows.

Exam trap

The trap here is that candidates may confuse GuardDuty's own multi-account dashboard with Security Hub's cross-service aggregation, or mistakenly think CloudWatch can serve as a centralized security dashboard, but CloudWatch lacks the finding normalization and multi-account aggregation capabilities that Security Hub provides.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring and observability service for metrics, logs, and alarms, not designed to aggregate security findings from GuardDuty across multiple accounts into a single dashboard. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure; it does not aggregate GuardDuty findings. Option C is wrong because Amazon Macie is a data security service that discovers and protects sensitive data in S3 using machine learning; it does not aggregate GuardDuty findings from other accounts.

137
MCQmedium

A company is using AWS Lambda functions to process sensitive data. The security team wants to detect when a Lambda function is invoked with an unexpected payload that may indicate an injection attack. Which AWS service should the team use to inspect the function's input for malicious patterns?

A.AWS WAF
B.None of the above; the team should implement custom validation within the Lambda function.
C.Amazon Inspector
D.AWS Shield
E.Amazon GuardDuty
AnswerB

Lambda does not include a built-in AWS service that intercepts and validates event payloads for injection attacks such as SQL, OS command, or NoSQL injection. The correct approach is to implement custom input validation and sanitization inside the function code—for example using allowlists, parameterized queries, and parsing libraries—because only the function itself understands the expected schema and context of its event data.

Why this answer

AWS Lambda functions process event payloads directly within the function code, and no AWS managed service can inspect the actual input data passed to a Lambda function at invocation time. AWS WAF operates at the HTTP/HTTPS layer for API Gateway or CloudFront, not for Lambda function payloads. Amazon Inspector scans for software vulnerabilities in EC2 instances and container images, not runtime payloads.

AWS Shield provides DDoS protection at the network and transport layers. Amazon GuardDuty analyzes VPC flow logs, DNS logs, and CloudTrail events for threats, but it does not inspect Lambda function invocation payloads. Therefore, the only way to detect malicious patterns in the function's input is to implement custom validation logic within the Lambda function code itself.

Exam trap

The trap here is that candidates often assume AWS WAF or GuardDuty can inspect all types of data flowing through AWS, but in reality, these services have specific scope limitations and cannot inspect Lambda invocation payloads directly.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at the application layer for resources like API Gateway, CloudFront, or ALB, but it cannot inspect the payload passed directly to a Lambda function via SDK, CLI, or other AWS services. Option C is wrong because Amazon Inspector is a vulnerability management service that assesses EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure, not for inspecting runtime invocation payloads for injection attacks. Option D is wrong because AWS Shield is a managed DDoS protection service that operates at the network and transport layers (Layer 3/4) and does not inspect application-level payloads for malicious patterns.

Option E is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, CloudTrail management events, DNS logs, and EKS audit logs, but it does not have visibility into the actual data payloads passed to Lambda functions during invocation.

138
MCQhard

A security analyst notices an IAM role 'AdminRole' is being assumed from an IP address outside the company's allowed network. The analyst wants to receive real-time alerts when this role is assumed from unauthorized locations. Which combination of services should be used?

A.AWS CloudTrail, Amazon S3, and Amazon Athena
B.AWS Config, Amazon SNS, and AWS Lambda
C.Amazon GuardDuty and AWS Lambda
D.AWS CloudTrail, Amazon CloudWatch Events, and Amazon SNS
AnswerD

This is the correct answer because each service plays a specific role in a real-time alert pipeline: CloudTrail captures the API activity from adminrole, CloudWatch Events (now Amazon EventBridge) applies a custom pattern to match events containing that role's ARN or name and forwards them to SNS, and SNS delivers the notification to subscribers. The integration is event-driven and near-real-time, with no need for polling or querying, which makes it the ideal setup for immediate alerts.

Why this answer

AWS CloudTrail logs IAM role assumption events (sts:AssumeRole) as CloudTrail events, which can be sent to Amazon CloudWatch Events (now Amazon EventBridge) as a real-time event stream. CloudWatch Events rules can then match specific patterns (e.g., source IP outside allowed ranges) and trigger an Amazon SNS notification to alert the security analyst immediately. This combination provides the real-time alerting required without additional polling or storage.

Exam trap

The trap here is that candidates often confuse AWS Config (which evaluates configuration compliance) with CloudTrail (which records API activity), or they assume GuardDuty can be customized for specific role assumption alerts, when in fact GuardDuty does not support custom event pattern matching for individual IAM roles.

How to eliminate wrong answers

Option A is wrong because while CloudTrail logs to S3 and Athena can query those logs, this setup is for historical analysis and batch queries, not real-time alerting. Option B is wrong because AWS Config evaluates resource configuration changes (e.g., IAM policy changes) but does not monitor API call events like sts:AssumeRole from specific IP addresses; it is not designed for real-time event-driven alerting on API activity. Option C is wrong because Amazon GuardDuty detects threats based on DNS, VPC flow logs, and CloudTrail management events, but it does not provide custom real-time alerts for a specific IAM role being assumed from unauthorized IPs; it focuses on broader anomaly detection and requires additional services to trigger custom SNS alerts.

139
MCQmedium

A security engineer is configuring automated response to a GuardDuty finding of type 'UnauthorizedAccess:EC2/SSHBruteForce'. The engineer needs to isolate the compromised instance by modifying the security group to deny all inbound traffic. Which AWS service should be used to orchestrate this response?

A.AWS Lambda
B.AWS CloudFormation
C.AWS Config
D.AWS Systems Manager Automation
AnswerD

Systems Manager Automation is the correct service because it uses automation documents (runbooks) designed specifically to perform operational remediation in a controlled, repeatable way. A runbook can include steps that modify security group rules, stop or isolate EC2 instances, collect diagnostics, or invoke Lambda functions, and it supports IAM roles, approval gates, and rate controls for safe execution. EventBridge rules can trigger these runbooks automatically from security findings, making it the orchestration layer for automated incident response.

Why this answer

AWS Systems Manager Automation is the correct service because it provides a pre-built runbook, AWS-IsolateInstanceEC2, specifically designed to isolate an EC2 instance by modifying its security group to deny all inbound traffic. This runbook can be triggered directly by a CloudWatch Events rule that matches the GuardDuty finding, enabling fully automated incident response without custom code. Systems Manager Automation also supports cross-account and cross-region execution, making it suitable for enterprise-scale response orchestration.

Exam trap

The trap here is that candidates often choose AWS Lambda because they think they need custom code to modify security groups, but AWS Systems Manager Automation provides a pre-built, auditable, and fully managed runbook that eliminates the need for custom code and is the recommended service for orchestrating automated incident response actions.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service for running custom code, not an orchestration service; while you could write a Lambda function to modify security groups, the question asks for the service to *orchestrate* the response, and Systems Manager Automation provides a managed, auditable runbook without requiring custom code. Option B is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not for real-time incident response orchestration; it cannot dynamically react to a GuardDuty finding and execute a security group modification. Option C is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it cannot execute remediation actions like modifying security groups; it can only trigger Lambda or Systems Manager for remediation, not perform the action itself.

140
MCQhard

A company is using Amazon GuardDuty to detect threats. They notice that GuardDuty is generating a high volume of 'UnauthorizedAccess:EC2/SSHBruteForce' findings from an internal EC2 instance that is used for vulnerability scanning. The security team wants to reduce false positives without disabling GuardDuty entirely. What should they do?

A.Change the security group of the vulnerability scanner to block SSH traffic.
B.Disable GuardDuty for the subnet where the vulnerability scanner is located.
C.Disable the 'UnauthorizedAccess:EC2/SSHBruteForce' finding type in GuardDuty.
D.Create a suppression rule for findings originating from the vulnerability scanner's IP address.
AnswerD

Creating a suppression rule that matches the vulnerability scanner's IP address is the correct action because GuardDuty suppression rules automatically archive findings from trusted sources without changing your security posture. The rule can be scoped to the specific IP and finding type (or even the specific scanner instance), preventing future false positives while preserving detection of real SSH brute-force attempts from any other source.

Why this answer

Amazon GuardDuty's suppression rules allow you to filter out findings based on criteria such as IP address, without disabling the detector or any finding types. By creating a suppression rule that matches the vulnerability scanner's IP address, you automatically archive and suppress future 'UnauthorizedAccess:EC2/SSHBruteForce' findings from that specific source, reducing false positives while maintaining full threat detection coverage for all other instances.

Exam trap

The trap here is that candidates often confuse suppression rules with disabling finding types or disabling GuardDuty entirely, not realizing that suppression rules provide a granular, IP-based mechanism to reduce noise without compromising overall security coverage.

How to eliminate wrong answers

Option A is wrong because changing the security group to block SSH traffic would break the vulnerability scanner's functionality, as it needs SSH access to perform its scanning tasks. Option B is wrong because disabling GuardDuty for the subnet would stop all threat detection for every instance in that subnet, not just the scanner, leaving other workloads unprotected. Option C is wrong because disabling the 'UnauthorizedAccess:EC2/SSHBruteForce' finding type globally would suppress all SSH brute force alerts across the entire AWS account, including legitimate threats, which defeats the purpose of targeted false positive reduction.

141
MCQeasy

A company uses AWS CloudTrail to log all API activity. The security team wants to be alerted when an IAM user creates a new access key. They have created a CloudWatch metric filter on the CloudTrail log group for the event name 'CreateAccessKey' and set up a CloudWatch alarm that sends an email via Amazon SNS. However, the alarm is not triggering even though the team knows that access keys have been created. The metric filter has been tested and shows data points in CloudWatch. What should the security team check next?

A.Ensure that the CloudTrail trail is delivering logs to the correct CloudWatch Logs log group.
B.Verify that the CloudTrail trail is logging data events.
C.Review the CloudWatch alarm configuration, including the period and threshold.
D.Check that the IAM user has permissions to create access keys.
AnswerC

Once the metric filter confirms that the CreateAccessKey events are being published to CloudWatch, the alarm logic itself is the next layer to inspect. A period that is too long, a threshold set above the number of events in the window, or an inappropriate statistic (such as Average instead of Sum) can keep the alarm in OK even though events are occurring. Also, the alarm must be configured with a ComparisonOperator and EvaluationPeriods that reflect the expected bursty nature of access-key creation; one event in a five-minute period will never breach a threshold of 1 if the metric is evaluated every minute.

Why this answer

The metric filter is producing data points, which means logs are being ingested and the filter is matching events. The most likely issue is that the CloudWatch alarm's period or threshold is misconfigured—for example, the evaluation period might be too long or the threshold too high, causing the alarm to not transition to ALARM state despite the metric having values. The security team should verify the alarm's settings, such as the period (e.g., 5 minutes) and the threshold (e.g., >= 1), to ensure they align with the expected frequency of access key creation events.

Exam trap

The trap here is that candidates assume the issue must be with log delivery or event type, but the metric filter already shows data points, so the problem lies in the alarm's evaluation configuration—specifically the period and threshold settings that control when the alarm triggers.

How to eliminate wrong answers

Option A is wrong because the metric filter is showing data points, which confirms that the CloudTrail trail is already delivering logs to the correct CloudWatch Logs log group; if it were not, no data points would appear. Option B is wrong because 'CreateAccessKey' is a management event, not a data event, and CloudTrail logs management events by default; data events are for S3 object-level or Lambda function invocations and are irrelevant here. Option D is wrong because the question states that access keys have been created, which means the IAM user already has the necessary permissions; the issue is with the alarm triggering, not with the creation of keys.

142
MCQmedium

A security team needs to analyze historical CloudTrail logs across multiple AWS accounts to detect patterns of suspicious activity. Which solution provides the MOST cost-effective and scalable analysis?

A.Aggregate logs into a central S3 bucket and query with Amazon Athena
B.Stream logs to Amazon Elasticsearch Service and use Kibana
C.Load logs into Amazon Redshift for analysis
D.Use Amazon CloudWatch Logs Insights across all accounts
AnswerA

Centralizing CloudTrail logs in a single S3 bucket is the AWS-recommended architecture for historical analysis. Amazon Athena uses serverless Presto/Trino to run SQL directly over S3 objects, charging only for bytes scanned, which is cost-effective for infrequent deep queries. Partitioning the data by date and converting to columnar formats like Parquet further reduces scan costs and speeds up analysis. This approach avoids provisioning any compute, making it the natural fit for auditing historical events across accounts.

Why this answer

Aggregating CloudTrail logs into a central S3 bucket and querying with Amazon Athena is the most cost-effective and scalable solution because Athena uses a serverless, pay-per-query model with no infrastructure to manage, and it can directly analyze large volumes of structured log data stored in S3 using standard SQL. This approach avoids the cost of provisioning and maintaining dedicated clusters (as with Redshift or Elasticsearch) and avoids the per-GB ingestion and storage fees of CloudWatch Logs Insights, making it ideal for historical analysis across multiple accounts.

Exam trap

The trap here is that candidates often choose CloudWatch Logs Insights (Option D) because it seems convenient for log analysis, but they overlook its high ingestion costs and limited retention for historical data, whereas Athena's serverless, pay-per-query model is far more cost-effective for large-scale, infrequent queries of archived logs.

How to eliminate wrong answers

Option B is wrong because streaming logs to Amazon Elasticsearch Service (now OpenSearch Service) incurs ongoing costs for cluster instances, storage, and data ingestion, and it is not as cost-effective for infrequent historical queries compared to Athena's pay-per-query model. Option C is wrong because loading logs into Amazon Redshift requires provisioning a cluster, paying for compute and storage even when idle, and involves ETL overhead, making it overkill and more expensive for ad-hoc analysis of CloudTrail logs. Option D is wrong because Amazon CloudWatch Logs Insights is designed for real-time log analysis and has a per-GB ingestion cost and a limited query history retention (typically 30 days), making it unsuitable and costly for analyzing long-term historical logs across multiple accounts.

143
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to centralize threat detection and automatically remediate high-severity GuardDuty findings across all accounts. What is the MOST efficient way to achieve this?

A.Enable GuardDuty in the management account and designate a delegated administrator to manage findings across all accounts
B.Create a Lambda function that enables GuardDuty in each account using cross-account IAM roles
C.Configure Amazon EventBridge to forward findings from each account to a central account
D.Use AWS Security Hub and enable GuardDuty in each account separately
AnswerA

Designating a GuardDuty delegated administrator in AWS Organizations is the native, recommended pattern because it uses the service's integration with Organizations to auto-enable GuardDuty for every current and future member account via a single API call. The delegated administrator account receives a centralized view of all findings and can configure threat detection policies, while individual accounts retain read access to their own results. This eliminates per-account manual steps and provides a consistent audit trail of enablement state across the organization.

Why this answer

AWS Organizations allows you to enable GuardDuty in the management account and designate a delegated administrator, which automatically enables GuardDuty across all member accounts and centralizes finding management. This approach eliminates the need for per-account configuration or cross-account IAM roles, as the delegated administrator can view and manage findings from all accounts in a single GuardDuty console. It is the most efficient method because it leverages native AWS Organizations integration for automated, centralized threat detection and remediation.

Exam trap

The trap here is that candidates often assume Security Hub (Option D) is required for centralization, but GuardDuty's delegated administrator feature already provides native centralized finding management without additional services.

How to eliminate wrong answers

Option B is wrong because creating a Lambda function to enable GuardDuty in each account using cross-account IAM roles is inefficient, requires custom scripting, and does not provide centralized finding management without additional EventBridge or S3 forwarding. Option C is wrong because configuring Amazon EventBridge to forward findings from each account to a central account adds complexity and latency, and still requires GuardDuty to be enabled individually in each account. Option D is wrong because using AWS Security Hub and enabling GuardDuty in each account separately does not centralize the GuardDuty console itself; Security Hub aggregates findings but does not replace the need for per-account GuardDuty setup or provide the same native centralized management as a delegated administrator.

144
MCQhard

A company uses AWS Lambda functions to process sensitive data. The security team wants to ensure that if a Lambda function is compromised, the attacker cannot use the function's IAM role to access other AWS resources. The team has implemented the principle of least privilege by restricting the IAM role's permissions. However, they are concerned about a scenario where an attacker could use the Lambda function to execute AWS API calls that are not intended by the application. What additional measure should the team implement to reduce the risk of such lateral movement?

A.Use AWS IAM Access Analyzer to generate and refine the IAM policy based on actual usage.
B.Enable AWS CloudTrail data events for the Lambda function.
C.Attach a service control policy (SCP) that denies all actions except those explicitly allowed.
D.Place the Lambda function inside a VPC with no internet access.
AnswerA

IAM Access Analyzer's policy generation feature reviews CloudTrail logs to identify the specific API actions the Lambda function actually invoked, then proposes a least-privilege IAM policy. You refine and attach that policy to the function's execution role, which prevents the role from calling unrelated AWS services that it never legitimately needs. This is a preventive control because it reduces the attack surface and blast radius if credentials are compromised, as opposed to merely logging or auditing activity.

Why this answer

AWS IAM Access Analyzer can generate IAM policies based on the actual API calls made by the Lambda function over a specified period. By reviewing and refining the policy to include only those actions, the team can further tighten least privilege beyond manual estimation, reducing the risk that an attacker could abuse unintended API calls. This directly addresses the concern of lateral movement by ensuring the function's role cannot perform actions not observed in normal operation.

Exam trap

The trap here is that candidates may confuse service control policies (SCPs) with IAM permissions boundaries or think they can be applied to individual resources, when in fact SCPs only affect accounts in an organization and cannot be attached to a Lambda function.

How to eliminate wrong answers

Option B is wrong because enabling CloudTrail data events for the Lambda function only provides logging of invocations and does not restrict the function's IAM role permissions or prevent an attacker from making unintended API calls. Option C is wrong because service control policies (SCPs) apply at the AWS Organizations level to accounts or organizational units, not to individual Lambda functions or their IAM roles; they cannot be attached directly to a function to limit its permissions. Option D is wrong because placing the Lambda function inside a VPC with no internet access restricts network connectivity but does not prevent the function from using its IAM role to call AWS APIs via the AWS private network or VPC endpoints; the attacker could still make API calls to other AWS services.

145
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to automatically receive alerts when an IAM user attempts to access resources they do not have permissions for, across all accounts. Which combination of services should be used?

A.Amazon Inspector and AWS Lambda
B.AWS Config and Amazon SNS
C.AWS CloudTrail and Amazon CloudWatch Logs
D.Amazon GuardDuty and AWS Security Hub
AnswerD

Amazon GuardDuty is a managed threat detection service that consumes CloudTrail management events, VPC Flow Logs, and DNS query logs to identify compromised credentials, unusual API patterns, and malicious behavior. AWS Security Hub collects GuardDuty findings from all member accounts in the organization, applies security standards, and can forward high-severity results to Amazon SNS through Amazon EventBridge for immediate alerting. Together they give continuous detection plus centralized, actionable visibility across the multi-account environment.

Why this answer

Amazon GuardDuty continuously monitors for suspicious activity, including unauthorized API calls or failed access attempts, across all accounts in an AWS Organization. Security Hub aggregates these findings from GuardDuty and other services, enabling automated alerts via integrations like Amazon SNS or AWS Chatbot. Together, they provide a centralized, cross-account threat detection and alerting solution that meets the requirement of notifying the security team when IAM users attempt unauthorized resource access.

Exam trap

The trap here is that candidates often choose CloudTrail and CloudWatch Logs (Option C) because they know CloudTrail logs API calls, but they overlook that GuardDuty and Security Hub provide automated, cross-account threat detection and aggregation without requiring custom metric filters and manual setup for every account.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposure, not for monitoring IAM user access attempts or authorization failures. Option B is wrong because AWS Config evaluates resource configurations against rules and tracks configuration changes, but it does not monitor or detect unauthorized API calls or access attempts by IAM users. Option C is wrong because AWS CloudTrail logs API calls and CloudWatch Logs can store and alert on those logs, but this combination requires custom metric filters and alarms to detect unauthorized access attempts; it lacks the built-in, automated threat detection and cross-account aggregation that GuardDuty and Security Hub provide, making it less efficient and more error-prone for this specific use case.

146
MCQeasy

A company is using AWS WAF to protect a web application. The security team wants to receive alerts when a specific rule block is triggered. Which AWS service should they use to achieve this?

A.Amazon EventBridge
B.CloudWatch Alarms with SNS
C.Amazon S3
D.Amazon SNS
AnswerB

AWS WAF publishes real-time CloudWatch metrics such as BlockedCount and CountedCount for each web ACL and rule. A CloudWatch Alarm can monitor these metrics and transition to the ALARM state when a threshold (e.g., blocked requests exceed 100 per minute) is breached, then automatically publish to an SNS topic to send email or SMS notifications. This is the native, direct alerting mechanism for WAF rule events because it uses the service's own metric stream.

Why this answer

AWS WAF integrates with Amazon CloudWatch to provide metrics for each rule, including the 'BlockedRequests' count. By creating a CloudWatch Alarm on this metric, you can trigger an SNS notification when the threshold is exceeded, alerting the security team. This is the standard pattern for receiving alerts on WAF rule actions, as CloudWatch Alarms with SNS provide the necessary monitoring and notification pipeline.

Exam trap

The trap here is that candidates often confuse the notification mechanism (SNS) with the evaluation mechanism (CloudWatch Alarms), selecting SNS alone without recognizing that CloudWatch Alarms are required to evaluate the WAF metric and trigger the notification.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge is used for event-driven architectures to route events from various sources to targets, but it does not natively evaluate metric thresholds or generate alerts based on WAF rule triggers without additional custom logic. Option C is wrong because Amazon S3 is an object storage service and cannot evaluate metrics or send alerts; it can only store logs or data. Option D is wrong because Amazon SNS alone is a notification service that requires a publisher to send messages; without a CloudWatch Alarm to evaluate the WAF metric and publish to the SNS topic, no alert will be generated.

147
Multi-Selectmedium

A security engineer is configuring AWS CloudTrail to monitor data events for S3 objects. Which TWO of the following must be enabled to log object-level operations? (Select TWO.)

Select 2 answers
A.Enable data events in the CloudTrail trail.
B.Enable S3 server access logs on the bucket.
C.Enable management events in the CloudTrail trail.
D.Enable S3 Object Lambda.
E.Specify the S3 bucket ARN or prefix in the trail configuration.
AnswersA, E

CloudTrail data events record S3 object-level operations such as GetObject, PutObject, and DeleteObject. Enabling data events is essential because management events only cover control-plane actions (e.g., bucket creation or policy changes), not the actual access to objects. Data events must be explicitly enabled in the trail, as they are not on by default due to their high volume, but they are exactly what you need to monitor object-level activity.

Why this answer

CloudTrail data events capture S3 object-level operations such as GetObject, PutObject, and DeleteObject. To enable this, you must explicitly select 'Data events' in the CloudTrail trail configuration, as management events only cover bucket-level operations like CreateBucket.

Exam trap

The trap here is that candidates often confuse management events (which log bucket-level actions) with data events (which log object-level actions), leading them to select Option C instead of recognizing that both data events and a specific bucket ARN or prefix are required.

148
MCQmedium

A security team is using AWS CloudTrail and Amazon CloudWatch Logs to monitor for unauthorized API calls. They want to receive an alert when an API call is made with an access key that has been reported as compromised. They have configured CloudTrail to send logs to CloudWatch Logs. What should they do next to achieve this?

A.Create an AWS Lambda function that periodically queries CloudTrail event history for the access key ID and sends an alert via Amazon SES.
B.Create a CloudWatch Logs metric filter that matches the access key ID in the CloudTrail logs, and create a CloudWatch alarm that publishes to an SNS topic.
C.Use Amazon GuardDuty to monitor for the compromised access key and configure it to send findings to an SNS topic.
D.Enable AWS CloudTrail Insights to automatically detect the compromised access key and send an alert.
AnswerB

CloudWatch Logs metric filters can search for specific terms, such as the compromised access key ID, in the log data. When the filter matches, it increments a metric. A CloudWatch alarm on that metric can trigger an SNS notification, providing the desired alert. This is the standard method for alerting on specific log patterns.

Why this answer

The most efficient and real-time method is to create a CloudWatch Logs metric filter that matches the compromised access key ID in the CloudTrail logs. When the filter matches, it increments a custom metric. A CloudWatch alarm on that metric can then publish to an SNS topic, alerting the team.

This leverages the existing log delivery and requires no custom code.

Exam trap

The trap here is assuming GuardDuty or CloudTrail Insights can monitor for a specific user-defined access key ID, when they do not support such custom matching.

149
MCQhard

A company uses AWS Systems Manager Patch Manager to apply patches to EC2 instances. The security team wants to ensure that instances are patched within 7 days of a patch release. Which service should be used to monitor and report compliance?

A.AWS Config
B.AWS Security Hub
C.Amazon Inspector
D.AWS Trusted Advisor
AnswerA

AWS Config integrates with Systems Manager Patch Manager to record patch compliance state as a configuration item. You can use managed rules like ec2-managedinstance-patch-compliance-status-check or custom Lambda rules to evaluate whether instances are patched within the required timeframe, and trigger remediation actions such as Systems Manager Automation. It provides an ongoing compliance history and can enforce patch validation across the fleet.

Why this answer

AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations, including patch compliance status via Systems Manager Patch Manager. You can create an AWS Config rule (e.g., 'ec2-managedinstance-patch-compliance-status') that checks whether instances have the required patches installed within a specified time frame (e.g., 7 days). AWS Config then reports noncompliant resources, enabling the security team to track and remediate patching gaps.

Exam trap

The trap here is that candidates often confuse Amazon Inspector's vulnerability scanning with patch compliance monitoring, but Inspector does not track whether patches have been applied within a specific time window after release—it only identifies missing patches or vulnerabilities at a point in time.

How to eliminate wrong answers

Option B (AWS Security Hub) is wrong because it aggregates security findings from multiple AWS services (like AWS Config, GuardDuty, Inspector) but does not itself perform patch compliance monitoring; it relies on AWS Config rules to provide that data. Option C (Amazon Inspector) is wrong because it focuses on vulnerability assessments and network reachability analysis, not on tracking whether patches have been applied within a specific time window after release. Option D (AWS Trusted Advisor) is wrong because it provides best-practice checks for cost, performance, security, and fault tolerance, but it does not monitor patch compliance status or report on patch age relative to release dates.

150
MCQmedium

During an incident response, a security team needs to capture a memory dump of an Amazon EC2 instance running Linux. What is the recommended approach?

A.Use AWS Systems Manager Run Command to run a script that extracts memory using LiME.
B.Use Amazon Inspector to collect memory dumps.
C.Stop the instance and create an EBS snapshot for memory analysis.
D.Use the EC2 console to take a screenshot and capture memory from the hypervisor.
AnswerA

AWS Systems Manager Run Command is the correct approach because it can execute a script on the running EC2 instance through the SSM agent, installing the LiME kernel module and dumping the full contents of volatile memory to a file. The acquired memory image can then be uploaded to S3 for forensic analysis. Unlike other methods, Run Command works while the instance remains powered on, which is essential because memory is lost the moment the instance is stopped or rebooted. It also provides fine-grained IAM permissions and a complete audit trail of the command invocation.

Why this answer

AWS Systems Manager Run Command allows you to execute a script on a running EC2 instance without needing SSH access, and LiME (Linux Memory Extractor) is a trusted tool for capturing volatile memory. This approach preserves the memory state for forensic analysis while maintaining the instance's running state, which is critical for incident response.

Exam trap

The trap here is that candidates confuse memory capture with disk capture, assuming an EBS snapshot or Inspector can retrieve volatile data, when in fact only a tool like LiME executed on the running instance can capture RAM.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposures, not a tool for capturing memory dumps. Option C is wrong because stopping the instance and creating an EBS snapshot captures only disk data, not volatile memory (RAM), which is lost when the instance stops. Option D is wrong because the EC2 console screenshot captures only the display output, not the full memory contents, and the hypervisor does not expose a mechanism to capture a guest instance's RAM directly.

← PreviousPage 2 of 3 · 215 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Threat Detection and Incident Response questions.