Courseiva
Security Logging and MonitoringmediumMultiple ChoiceObjective-mapped

SCS-C02 Security Logging and Monitoring Practice Question

Network Topology
aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamestart-time 2024-01-01T00:00:00Zend-time 2024-01-31T23:59:59Z

Refer to the exhibit. A security engineer ran this AWS CLI command to find when a specific CreateKeyPair API call was made. The command returns no results, even though the engineer knows the call was made. What is the MOST likely reason?

⚠ Common exam trap

Many candidates assume the `--lookup-attributes` parameter accepts simple key=value syntax like other AWS CLI commands, but CloudTrail requires a specific `AttributeKey` and `AttributeValue` pair, and failing to use this correct structure silently returns no results instead of an error.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The --lookup-attributes parameter has incorrect syntax.

The `--lookup-attributes` parameter requires a JSON structure with an `AttributeKey` and `AttributeValue`. The provided syntax `--lookup-attributes EventName=CreateKeyPair` is invalid; the correct format is `--lookup-attributes AttributeKey=EventName,AttributeValue=CreateKeyPair`. This malformed parameter causes the AWS CLI to fail silently or return no results, even though the API call exists.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The time range is too narrow.

    Why it's wrong here

    The time range covers the entire month.

  • The command did not specify a region, so it defaults to us-east-1, but the call was made in a different region.

    Why it's wrong here

    Region mismatch could cause missing results, but the syntax error is more likely.

  • The event name should be 'CreateKeypair' (lowercase p).

    Why it's wrong here

    Event names are case-sensitive but the correct name is CreateKeyPair.

  • The --lookup-attributes parameter has incorrect syntax.

    Why this is correct

    The comma should be a space or the syntax is wrong.

About these practice questions

One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.