Courseiva

CCNA Security Logging Questions

75 of 250 questions · Page 1/4 · Security Logging topic · Answers revealed

1
MCQhard

A security engineer notices that an S3 bucket containing sensitive data has been accessed from an IP address outside the allowed range. CloudTrail logs show the access was made using temporary credentials from an assumed role. What additional logging is needed to trace the access back to the original IAM user who assumed the role?

A.Enable CloudTrail to log data events for the S3 bucket.
B.Enable VPC Flow Logs for the VPC where the request originated.
C.Configure CloudWatch Logs to capture the EC2 instance's system logs.
D.Enable S3 server access logging for the bucket.
E.Enable AWS Config to record S3 bucket policies.
AnswerE

AWS Config does not record API calls; CloudTrail already records the session issuer in management events.

Why this answer

The information needed to trace the access back to the original IAM user who assumed the role is already available in CloudTrail management events, which are enabled by default. The AssumeRole API call is logged as a management event and includes the ARN of the IAM user or role that performed the assumption. Therefore, no additional logging is required to identify the original user.

Options A, B, C, D, and E do not provide this specific information: A and D log the S3 access but show only the assumed role; B and C are unrelated; E records configuration changes but not the specific AssumeRole call.

Exam trap

Candidates may assume that data events (A) or S3 server access logs (D) will capture the original user, but they only log the assumed role's ARN. The key is recognizing that management events already contain the AssumeRole call with the original user identity.

How to eliminate wrong answers

Option A is wrong because CloudTrail data events for S3 would log the API calls made to the bucket (e.g., GetObject, PutObject) but would still show the assumed role's ARN, not the original IAM user who assumed the role. Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not include IAM user or role information, so they cannot trace back to the original user. Option C is wrong because EC2 instance system logs (e.g., /var/log/messages) capture OS-level events, not AWS IAM role assumption details, and are irrelevant to tracing the original IAM user.

Option D is wrong because S3 server access logs record requests to the bucket (e.g., requester, IP, operation) but the requester field will show the assumed role's ARN, not the original IAM user who assumed the role.

2
Multi-Selecthard

A security engineer wants to detect and alert on AWS account root user activity. Which THREE services can be used together to achieve this? (Select THREE.)

Select 3 answers
A.AWS Config
B.Amazon CloudWatch Events (EventBridge)
C.AWS CloudTrail
D.Amazon CloudWatch Logs
E.Amazon GuardDuty
AnswersB, C, D

EventBridge matches CloudTrail events against a rule pattern, for example filtering on the root account's ARN, and routes matches to an SNS topic or Lambda function. This provides the near-real-time detection and notification mechanism the scenario requires.

Why this answer

Amazon CloudTrail (C) is correct because it records AWS API activity including root user sign-in events and console logins, which are captured as management events in the CloudTrail event history and delivered to an S3 bucket or CloudWatch Logs. Amazon CloudWatch Logs (D) is correct because CloudTrail can be configured to send its trail logs to a CloudWatch Logs log group, where log data can be retained and made available for metric filters and alarms. Amazon CloudWatch Events (EventBridge) (B) is correct because it can match specific CloudTrail API events (for example, events with a userIdentity type of Root) via event patterns and route them to targets such as SNS or Lambda to generate alerts.

AWS Config (A) is not correct because it evaluates resource configuration compliance and records configuration changes, not real-time API activity or root user sign-in events. Amazon GuardDuty (E) is not correct because it is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious or anomalous behavior, but it does not provide the event-matching and alerting pipeline for root user activity described here.

Exam trap

The trap here is that candidates may think Amazon GuardDuty is the correct choice because it detects threats, but it does not provide a native, customizable alerting mechanism for root user activity; instead, the combination of CloudTrail, EventBridge, and CloudWatch Logs is the standard AWS-recommended approach.

3
MCQeasy

A security engineer notices that an Amazon S3 bucket has been accessed from an IP address outside the company's allowed range. The engineer needs to identify the IAM user who made the request. Which AWS service should be used to find this information?

A.S3 server access logs
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerB

CloudTrail captures management-plane and (with data events) object-level API calls. Each event includes the IAM user, role, or federated user that made the request, along with source IP, access key, timestamp, and request/response details. For S3, enabling data events on the bucket records GetObject/PutObject with full caller identity, making it the definitive audit source for identifying which IAM principal performed an action.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS services, including S3 operations, and captures the identity of the IAM user or role that made the request. By examining CloudTrail logs, the security engineer can find the specific IAM user associated with the source IP address that accessed the bucket, as CloudTrail logs include both the user identity and the source IP address for each event.

Exam trap

The trap here is that candidates often confuse S3 server access logs with CloudTrail, assuming that server access logs include IAM user details, when in fact they only log the requester's AWS account ID or anonymous access, not the specific IAM user identity.

How to eliminate wrong answers

Option A is wrong because S3 server access logs provide detailed records of requests made to an S3 bucket, including source IP and object accessed, but they do not include IAM user identity information; they only log the requester's AWS account ID or anonymous access, not the specific IAM user. Option C is wrong because VPC Flow Logs capture information about IP traffic to and from network interfaces within a VPC, but they do not log IAM user identity or API-level details; they only show network-level metadata such as source/destination IP, ports, and protocol. Option D is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files, but it does not generate logs itself; it can be used to store CloudTrail logs or other logs, but it is not the service that records IAM user identity for S3 API calls.

4
MCQeasy

A security engineer needs to identify which IAM users have been inactive for the past 90 days. Which AWS service should the engineer use?

A.AWS IAM Credential Report
B.Amazon CloudWatch Logs
C.AWS Config
D.AWS CloudTrail
AnswerA

The IAM Credential Report is the purpose-built tool for this task because it generates a CSV containing every IAM user in the account along with password and access key metadata, including the last-used dates. By reviewing the 'password_last_used' and 'access_key_last_used' columns, you can immediately identify users who have never signed in or never used their keys. This report can also be refreshed programmatically via AWS CLI or the IAM console, making it the most direct audit mechanism.

Why this answer

AWS IAM Credential Report is the correct service because it provides a CSV report that lists all IAM users in an account and includes the `password_last_used` and `access_key_last_used_date` fields. By examining these fields, a security engineer can determine which users have not authenticated or used their access keys for more than 90 days, directly meeting the requirement to identify inactive IAM users.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which records API calls) with the IAM Credential Report, assuming CloudTrail can directly identify inactive users, but CloudTrail logs do not aggregate per-user last activity dates and require extensive post-processing to derive inactivity, whereas the Credential Report is the purpose-built, single-source solution for this exact use case.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from AWS resources, but it does not natively track IAM user activity or generate reports on user inactivity; it would require custom metric filters and logs from CloudTrail to infer inactivity, which is indirect and not the intended service. Option C is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes, not for tracking IAM user login activity or credential usage; it lacks the specific fields like `password_last_used` needed for inactivity analysis. Option D is wrong because AWS CloudTrail records API activity for auditing, but it does not provide a consolidated report of all IAM users' last activity dates; extracting inactive users from CloudTrail logs would require complex queries across millions of events and is not the purpose-built solution for this task.

5
Multi-Selectmedium

A security engineer is troubleshooting an issue where CloudTrail is not delivering logs to an S3 bucket. The bucket policy appears correct. Which TWO additional steps should the engineer take to diagnose the issue? (Choose TWO.)

Select 2 answers
A.Verify that the S3 bucket exists and is in the correct region.
B.Check CloudWatch Logs for CloudTrail errors.
C.Create an IAM role for CloudTrail with S3 write permissions.
D.Enable S3 server access logging on the bucket.
E.Review the CloudTrail configuration in the AWS Management Console for error messages.
AnswersA, E

CloudTrail can only write log files to an S3 bucket that already exists and is located in the same AWS Region as the trail. If the bucket was accidentally deleted, renamed, or created in another Region, every delivery attempt fails, and the trail's status shows a delivery error. Confirming this prerequisite is therefore the correct first troubleshooting step, because no policy or role change can compensate for a missing or misregioned destination.

Why this answer

If the S3 bucket does not exist or is in a different region, CloudTrail cannot deliver log files to it. CloudTrail requires the bucket to be in the same region as the trail (for a single-region trail) or in the designated bucket region for a multi-region trail. Verifying the bucket's existence and region ensures the delivery path is valid.

Option E is correct because the CloudTrail configuration in the AWS Management Console displays error messages related to delivery failures, such as bucket policy issues or permission errors. Reviewing this console can provide immediate insight into why logs are not being delivered, without needing to check other logs manually.

Exam trap

The trap here is that candidates often assume CloudTrail uses an IAM role for S3 access (like many other AWS services), but CloudTrail relies solely on a resource-based bucket policy, so creating an IAM role (Option C) is unnecessary and incorrect.

6
MCQhard

A company uses AWS CloudTrail to log all API activity. They want to ensure that log files are tamper-proof and can be validated for forensic purposes. Which of the following should they enable?

A.AWS KMS server-side encryption on the S3 bucket
B.CloudTrail log file integrity validation
C.S3 bucket versioning
D.S3 Object Lock with governance mode
AnswerB

CloudTrail log file integrity validation creates a SHA-256 hash of each log file, chains that hash to the previous file's hash, and signs the resulting digest with a private key. The public key is distributed by AWS, so you can independently verify both the signature and the hash chain to detect any modification, deletion, or reordering of log files. It is the only option listed that provides cryptographic proof of log integrity.

Why this answer

CloudTrail log file integrity validation uses a SHA-256 hash chain to detect if log files have been modified, deleted, or altered after delivery. When enabled, CloudTrail delivers a digest file that includes the hash of each log file and the hash of the previous digest, creating an immutable chain that can be used to verify log integrity for forensic purposes.

Exam trap

The trap here is that candidates often confuse data protection mechanisms (encryption, versioning, object lock) with integrity validation, which specifically requires cryptographic hash verification to prove that log files have not been tampered with.

How to eliminate wrong answers

Option A is wrong because AWS KMS server-side encryption protects log files at rest from unauthorized access, but does not provide any mechanism to detect tampering or validate the integrity of the log files after they have been written. Option C is wrong because S3 bucket versioning preserves previous versions of objects, which can help recover from accidental deletion or overwrite, but it does not cryptographically verify that log files have not been altered. Option D is wrong because S3 Object Lock with governance mode prevents objects from being deleted or overwritten for a specified retention period, but it does not provide a hash-based integrity check to detect if the content of a log file was modified before being locked.

7
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to centralize CloudTrail logs from all accounts into a single S3 bucket in the management account. Which configuration ensures that only the management account can delete the log files?

A.Enable S3 Object Lock on the bucket with governance mode.
B.Use an S3 bucket policy that denies s3:DeleteObject for all principals.
C.Enable MFA Delete on the S3 bucket.
D.Configure CloudTrail to automatically delete logs older than 90 days.
E.Use an S3 bucket policy that denies s3:DeleteObject unless the principal is the management account.
AnswerE

The correct approach is to add a bucket policy with a Deny effect for s3:DeleteObject that includes a Condition such as StringNotEquals on aws:PrincipalAccount with the management account's ID. This denies deletion for every principal that is not in the management account, while excluding the management account itself from the Deny so that its principals can delete. By using this resource-based policy and the aws:PrincipalAccount condition key, you enforce that only users or roles from the management account can delete objects from the S3 bucket.

Why this answer

It uses an S3 bucket policy with a conditional deny that explicitly restricts the s3:DeleteObject action to only the management account. This ensures that even if an IAM user or role in a member account has S3 permissions, they cannot delete log files unless they are from the management account. The policy leverages the aws:PrincipalOrgID or a specific account ID condition to enforce this restriction.

Exam trap

The trap here is that candidates often confuse MFA Delete (option C) with account-level access control, but MFA Delete only adds an authentication factor and does not restrict deletion to a specific AWS account.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock in governance mode prevents objects from being deleted or overwritten by most users, but it can be bypassed by users with the s3:BypassGovernanceRetention permission, which could be granted to the management account or others, and it does not exclusively restrict deletion to the management account. Option B is wrong because denying s3:DeleteObject for all principals would prevent even the management account from deleting log files, which is not the requirement; the goal is to allow only the management account to delete. Option C is wrong because MFA Delete requires multi-factor authentication for delete operations but does not restrict deletion to a specific account; any principal with MFA could delete objects if they have the necessary permissions.

Option D is wrong because CloudTrail's automatic log deletion feature (e.g., via lifecycle policies) does not control which principals can delete logs; it simply removes old logs based on age, and it does not prevent unauthorized deletion by other accounts.

8
Multi-Selecthard

A company is using AWS CloudTrail and wants to detect when an IAM user performs a specific action, such as stopping an EC2 instance. The security engineer needs to set up a real-time notification. Which THREE steps should the engineer take? (Choose THREE.)

Select 3 answers
A.Create a metric filter in CloudWatch Logs to match the StopInstances event
B.Create a CloudTrail trail that delivers logs to CloudWatch Logs
C.Use Amazon QuickSight to visualize CloudTrail logs
D.Create a CloudWatch alarm on the metric and configure it to send an SNS notification
E.Use Amazon Athena to query CloudTrail logs in S3
AnswersA, B, D

A metric filter in CloudWatch Logs inspects incoming log events and matches patterns such as { $.eventName = "StopInstances" }. Each matching event increments a custom metric (e.g., StopInstancesCount), which is what turns raw log data into a numeric measure that a CloudWatch alarm can monitor. Without this metric filter, CloudWatch Logs data remains unstructured and cannot directly trigger alerts.

Why this answer

A metric filter in CloudWatch Logs can parse CloudTrail log events for the 'StopInstances' API call and convert it into a CloudWatch metric. This metric can then trigger an alarm for real-time notification, enabling the security engineer to detect the specific action as required.

Exam trap

The trap here is that candidates may confuse services like QuickSight or Athena for real-time monitoring, but they are designed for historical analysis and visualization, not for triggering real-time notifications.

9
Multi-Selecthard

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer needs to ensure that all findings from member accounts are visible in the administrator account. Additionally, the engineer wants to receive real-time notifications for high-severity findings. Which TWO actions should the engineer take? (Choose TWO.)

Select 2 answers
A.Enable Amazon Detective to analyze GuardDuty findings.
B.Designate an administrator account in GuardDuty to manage the multi-account environment.
C.Create an Amazon EventBridge rule that triggers an SNS notification for high-severity GuardDuty findings.
D.Enable AWS CloudTrail in all member accounts to log GuardDuty API calls.
E.Use AWS Config to monitor GuardDuty configuration.
AnswersB, C

GuardDuty multi-account architecture requires you to designate an administrator account (via AWS Organizations delegated administrator or invitation) that owns the GuardDuty detectors and manages all member accounts. The administrator account aggregates findings from every member account, giving you a single-pane-of-glass view and allowing you to configure threat lists and managed rules centrally. This designated administrator is the foundation for cross-account management and is mandatory for any multi-account GuardDuty setup.

Why this answer

Designating an administrator account in GuardDuty is the required step to centrally manage findings from all member accounts in an AWS Organizations multi-account setup. This configuration enables the administrator account to view and aggregate all findings from member accounts without needing to log into each account individually.

Exam trap

The trap here is that candidates may think Amazon Detective or AWS Config are needed for real-time notifications, but Detective is for post-incident analysis and Config is for compliance drift, not for triggering alerts on security findings.

10
Multi-Selectmedium

A company is using AWS CloudTrail to monitor API activity in its AWS account. The security team needs to be alerted when unauthorized API calls are made to delete Amazon S3 buckets. Which TWO steps should the security team take to meet this requirement? (Choose TWO.)

Select 2 answers
A.Enable Amazon VPC Flow Logs to capture API calls and use Amazon Athena to query for DeleteBucket events.
B.Create an AWS CloudTrail trail that monitors Amazon CloudWatch Logs for DeleteBucket API calls.
C.Create an AWS Config rule to detect DeleteBucket API calls and send an SNS notification.
D.Configure CloudTrail to deliver logs to Amazon CloudWatch Logs and create a metric filter for the DeleteBucket API call.
E.Create an Amazon CloudWatch Events rule that matches the DeleteBucket API call and triggers an Amazon SNS notification.
AnswersD, E

CloudTrail delivers API activity to CloudWatch Logs, where a metric filter counts DeleteBucket events and drives an alarm. This satisfies the requirement to detect unauthorised delete calls, since CloudTrail alone records but does not alert.

Why this answer

Option D is correct because CloudTrail can be configured to deliver management event logs to an Amazon CloudWatch Logs log group, where a metric filter can be created to match the DeleteBucket API call (for example, filtering on eventName = DeleteBucket and errorCode = AccessDenied), and a CloudWatch alarm on that metric can then trigger an SNS notification to alert the security team. Option E is correct because CloudWatch Events (now Amazon EventBridge) can match CloudTrail API activity by event pattern, such as {"eventSource":"s3.amazonaws.com","eventName":"DeleteBucket"}, and route the matching event directly to an Amazon SNS topic to notify the team. Option A is not correct because VPC Flow Logs capture IP traffic metadata at the ENI level, not API calls, so they cannot identify DeleteBucket events.

Option B is not correct because a CloudTrail trail does not 'monitor CloudWatch Logs'; the correct direction is CloudTrail delivering logs to CloudWatch Logs, and a trail alone does not generate alerts. Option C is not correct because AWS Config rules evaluate resource configuration compliance and cannot detect or alert on individual DeleteBucket API calls.

Exam trap

The trap here is that candidates may confuse AWS Config (which evaluates resource configurations) with CloudTrail (which records API activity), or think VPC Flow Logs can capture API-level events instead of network flows.

11
MCQeasy

A security engineer needs to detect unauthorized API calls in an AWS account. Which AWS service should be used to record and monitor API activity for auditing?

A.AWS CloudTrail
B.Amazon CloudWatch Logs
C.AWS Config
D.Amazon GuardDuty
AnswerA

AWS CloudTrail is the native audit service that records every API call and user activity as CloudTrail event history. Each event includes the identity of the caller, source IP, time, request parameters, and response, allowing engineers to detect unauthorized API calls by analyzing management and data events. This event history can be delivered to an S3 bucket and queried with Athena, or streamed to CloudWatch Logs for real-time alerting.

Why this answer

AWS CloudTrail is the correct service because it is specifically designed to record API activity across AWS services, capturing details such as the identity of the caller, the time of the call, the source IP address, and the request parameters. This audit log is essential for detecting unauthorized API calls, as it provides a complete history of all management and data plane operations for security analysis and compliance.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs (which stores logs) with CloudTrail (which records API activity), or they assume GuardDuty's threat detection capability includes native API logging, when in fact GuardDuty consumes CloudTrail logs rather than generating them.

How to eliminate wrong answers

Option B (Amazon CloudWatch Logs) is wrong because it is a service for monitoring, storing, and accessing log files from various sources (e.g., applications, EC2 instances), but it does not natively record AWS API calls; it can only ingest CloudTrail logs if configured as a destination. Option C (AWS Config) is wrong because it evaluates and records resource configuration changes and compliance rules, not API activity; it focuses on the state of resources rather than the actions that modify them. Option D (Amazon GuardDuty) is wrong because it is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself record or store API call history for auditing purposes.

12
MCQhard

A financial services company has a production AWS account with hundreds of EC2 instances running a mix of Linux and Windows workloads. The security team is responsible for detecting and responding to security incidents. They have enabled CloudTrail, VPC Flow Logs, and GuardDuty. Recently, GuardDuty generated a finding indicating that an EC2 instance is communicating with a known malicious IP address. The security engineer needs to investigate the incident. The engineer examines the GuardDuty finding and sees the affected resource is an EC2 instance ID. The engineer wants to identify which user or role launched the instance and what security groups were associated with it at launch time. Which approach should the engineer take to gather this information?

A.Log in to the EC2 console and view the instance details under the 'Security' tab.
B.Use AWS Systems Manager Inventory to collect metadata about the instance.
C.Search CloudTrail logs for the RunInstances event that created the instance, using the instance ID to filter.
D.Use AWS Config to view the configuration history of the EC2 instance and check the security group changes.
AnswerC

The correct method is to filter CloudTrail management events for eventName='RunInstances' (eventSource='ec2.amazonaws.com') and match the target instance ID, which appears in the responseElements.instancesSet.items field because the ID is generated when the instance is created. Each event's userIdentity block contains the ARN of the IAM user or role, access key ID, session context, and source IP, giving a definitive audit answer. For large accounts, use Athena or CloudTrail Lake to query the logs by instance ID rather than manually browsing Event history.

Why this answer

CloudTrail records every EC2 API call, including RunInstances, with the identity of the caller (user or role), the request parameters (including security group IDs), and the response (including the instance ID). By searching CloudTrail logs for the RunInstances event and filtering by the instance ID in the response elements, the engineer can determine who launched the instance and which security groups were specified at launch.

Exam trap

SCS-C02 often tests the difference between CloudTrail (API caller identity and request parameters) and AWS Config (resource configuration history) — candidates frequently pick Config because it shows security group changes but miss that it does not identify the launching principal.

How to eliminate wrong answers

Option A is wrong because the EC2 console's Security tab shows current security groups, not the security groups at launch time, and it does not reveal the launching identity. Option B is wrong because Systems Manager Inventory collects OS-level metadata (installed applications, network config) and does not record the API caller or launch-time security groups. Option D is wrong because AWS Config records configuration history and can show security group changes over time, but it does not directly identify the IAM principal that launched the instance — CloudTrail is the authoritative source for API caller identity.

13
MCQhard

A security team has enabled AWS CloudTrail in all regions and is delivering logs to an S3 bucket. The team has also enabled S3 server access logging for the CloudTrail bucket. The team needs to detect any unauthorized access to the CloudTrail logs. Which combination of services should the team use to achieve near-real-time detection?

A.AWS CloudTrail Insights and Amazon CloudWatch
B.Amazon GuardDuty and Amazon CloudWatch Events
C.Amazon Athena and Amazon QuickSight
D.AWS Config and Amazon SNS
AnswerB

Amazon GuardDuty is a continuous threat detection service that consumes AWS CloudTrail S3 data events, VPC flow logs, and DNS logs to identify suspicious S3 access, such as requests from unusual geographies, compromised credentials, or bucket exfiltration attempts. When a finding is generated, GuardDuty publishes it to Amazon CloudWatch Events (now part of Amazon EventBridge), enabling automated notification through SNS or invocation of Lambda for remediation. This end-to-end pipeline provides the real-time, actionable alerting required for S3 access anomalies.

Why this answer

Amazon GuardDuty continuously monitors S3 data plane events, including CloudTrail log delivery and S3 server access logs, to detect suspicious API calls or unauthorized access patterns. Amazon CloudWatch Events (now part of Amazon EventBridge) can trigger near-real-time alerts when GuardDuty generates findings, enabling immediate response. This combination provides the required near-real-time detection without relying on batch analysis or configuration rules.

Exam trap

The trap here is that candidates confuse AWS CloudTrail Insights (which analyzes management events for anomalies) with GuardDuty (which provides broader threat detection including S3 data events), leading them to choose Option A despite its lack of near-real-time S3 access detection.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail Insights analyzes management event trails for unusual activity but does not provide near-real-time detection of unauthorized access to S3 objects; it operates on a delayed basis and focuses on API call anomalies, not S3 data events. Option C is wrong because Amazon Athena and Amazon QuickSight are query and visualization tools that require you to first store logs and then run queries, which is not near-real-time detection; they are used for post-incident analysis and reporting. Option D is wrong because AWS Config evaluates resource configuration compliance against rules and can trigger SNS notifications, but it does not detect unauthorized access to CloudTrail logs; it is designed for configuration auditing, not threat detection on data plane operations.

14
MCQmedium

A company uses AWS CloudTrail and wants to ensure that logs are encrypted at rest using a customer-managed KMS key. The CloudTrail trail is configured to deliver logs to an S3 bucket. After enabling SSE-KMS on the S3 bucket, the logs are not being delivered. What is the most likely cause?

A.CloudTrail does not support SSE-KMS.
B.The KMS key is in a different AWS account.
C.The S3 bucket policy does not allow CloudTrail to write logs.
D.The KMS key policy does not grant CloudTrail permission to use the key.
AnswerD

For CloudTrail to encrypt log files with a customer managed KMS key, the key policy must grant the CloudTrail service principal (cloudtrail.amazonaws.com) permissions for kms:GenerateDataKey and kms:Decrypt. If these permissions are missing, CloudTrail cannot generate the data key needed to encrypt the logs, and log delivery will fail or produce unencrypted logs. This is the exact cause described in the question, making it the correct answer.

Why this answer

CloudTrail requires explicit permissions in the KMS key policy to use the key for encrypting log files. Even if SSE-KMS is enabled on the S3 bucket, CloudTrail must have `kms:GenerateDataKey` and `kms:Decrypt` permissions granted via the key policy. Without these, CloudTrail cannot encrypt the logs, causing delivery to fail.

Exam trap

The trap here is that candidates often assume enabling SSE-KMS on the S3 bucket is sufficient, overlooking that CloudTrail must also be explicitly authorized in the KMS key policy to use the key for encryption operations.

How to eliminate wrong answers

Option A is wrong because CloudTrail fully supports SSE-KMS with customer-managed KMS keys; it is a common and documented configuration. Option B is wrong because CloudTrail can use a KMS key from a different AWS account as long as the key policy grants cross-account permissions, and the question does not indicate a cross-account scenario. Option C is wrong because the S3 bucket policy is not the primary issue here; the logs are not being delivered due to encryption failure, not a write permission denial, and CloudTrail typically has the necessary S3 write permissions via its service principal.

15
MCQeasy

A company wants to receive an alert when an IAM user creates a new access key. Which AWS service should be used to trigger the alert?

A.Amazon CloudWatch Logs
B.Amazon GuardDuty
C.AWS CloudTrail and Amazon CloudWatch Events
D.AWS Config
AnswerC

AWS CloudTrail records every CreateAccessKey management event as a CloudTrail event containing the user identity, timestamp, source IP, and request details. Amazon CloudWatch Events (now Amazon EventBridge) can evaluate those CloudTrail events with an event pattern for eventName equal to CreateAccessKey and then route the matching event to an SNS topic or Lambda function to send the alert. Together, these two services provide the required real-time, event-driven notification.

Why this answer

AWS CloudTrail captures API calls made by or on behalf of an IAM user, including CreateAccessKey events. These events can be sent to Amazon CloudWatch Events (now part of Amazon EventBridge) using a rule that matches the specific API call, which then triggers an alert (e.g., via SNS or Lambda). This combination enables real-time monitoring and notification for security-sensitive actions like access key creation.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail with Amazon CloudWatch Logs, thinking CloudWatch Logs alone can trigger alerts, but CloudWatch Logs requires a metric filter and alarm setup, whereas CloudWatch Events directly matches API events without needing log ingestion.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is used for storing, monitoring, and accessing log files from various sources, but it does not natively parse AWS API events or trigger alerts based on specific IAM actions without additional integration with CloudTrail and CloudWatch Events. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide custom alerting for specific IAM user actions like creating an access key; it focuses on anomaly detection rather than policy-based triggers. Option D is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking changes over time, but it does not trigger real-time alerts for API calls; it records configuration changes and can invoke rules for compliance, but not for event-driven notifications like access key creation.

16
MCQhard

A company has a requirement to retain CloudTrail logs for 7 years to meet regulatory compliance. They want to minimize storage costs while ensuring logs are immutable and cannot be deleted by anyone, including the root user. What should they do?

A.Configure the S3 bucket with MFA Delete enabled.
B.Use CloudTrail log file validation and enable AWS CloudTrail Insights.
C.Store the logs in Amazon S3 Glacier Deep Archive with a vault lock policy.
D.Enable S3 Object Lock in Compliance mode on the destination bucket.
AnswerD

Enabling S3 Object Lock in Compliance mode places a retention lock on objects until a specified date; during that retention period no user, not even the AWS account root user, can delete or overwrite them. Compliance mode is the strongest Object Lock mode because the retention protection cannot be shortened, removed, or bypassed by any principal. When used as the destination for CloudTrail logs, this guarantees the logs are retained for the full seven years and satisfies the stated requirement.

Why this answer

S3 Object Lock in Compliance mode prevents any user, including the root user, from deleting or overwriting objects for the specified retention period. This meets the immutability and retention requirements for CloudTrail logs, and by using S3 lifecycle policies to transition logs to lower-cost storage classes (e.g., S3 Glacier Deep Archive) after the initial retention period, storage costs can be minimized while maintaining compliance.

Exam trap

The trap here is that candidates may confuse S3 Glacier Vault Lock (which applies to Glacier archives, not S3 objects) with S3 Object Lock, or assume MFA Delete provides sufficient immutability, when in fact only S3 Object Lock in Compliance mode guarantees that no user, including root, can delete objects before the retention period ends.

How to eliminate wrong answers

Option A is wrong because MFA Delete only requires multi-factor authentication for delete operations but does not prevent the root user from deleting objects if they have the MFA device; it also does not enforce immutability or a fixed retention period. Option B is wrong because CloudTrail log file validation provides integrity verification (detecting tampering) but does not prevent deletion or enforce retention; AWS CloudTrail Insights is for detecting unusual activity, not for immutability or retention. Option C is wrong because S3 Glacier Deep Archive with a vault lock policy can enforce write-once-read-many (WORM) compliance, but CloudTrail logs are stored in S3 buckets, not directly in Glacier vaults; the vault lock policy applies to archives in Glacier, not to S3 objects, and transitioning logs to Glacier Deep Archive via S3 lifecycle policies does not inherently provide immutability unless combined with S3 Object Lock.

17
MCQeasy

A company wants to receive real-time notifications for every root user login to the AWS Management Console. Which service should be used?

A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon CloudWatch Events
D.AWS Config
AnswerC

Amazon CloudWatch Events (and its successor Amazon EventBridge) is correct because it can ingest CloudTrail events and apply an event pattern that matches a root user console login. A rule can specify the event source as aws.signin, the detail.eventName as ConsoleLogin, and the userIdentity.userName as root, routing matches to an SNS topic for immediate delivery. This pattern-based routing reacts in near real time, typically within seconds of the API call, and can also capture failed login attempts and MFA-related details. Since the requirement is real-time notifications for every root login, CloudWatch Events with an SNS target is exactly the alerting layer that CloudTrail alone lacks.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture AWS API calls via CloudTrail and trigger a rule that matches the 'RootLogin' event. This allows real-time notification through SNS, Lambda, or other targets whenever a root user signs in to the Management Console.

Exam trap

The trap here is that candidates often choose AWS CloudTrail because it records root logins, but they overlook that CloudTrail alone does not provide real-time notifications; it requires CloudWatch Events/EventBridge to trigger alerts.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes logs for malicious activity, but it does not provide real-time event-driven notifications for specific API calls like root logins. Option B is wrong because AWS CloudTrail records API activity and delivers log files to S3, but it does not natively trigger real-time notifications; it requires integration with CloudWatch Events for that purpose. Option D is wrong because AWS Config evaluates resource configurations against desired policies and tracks configuration changes, but it does not monitor or notify on IAM user login events.

18
Multi-Selecteasy

Which TWO AWS services can be used to detect and alert on suspicious activity in near real-time?

Select 2 answers
A.Amazon CloudWatch Events
B.Amazon Inspector
C.Amazon GuardDuty
D.AWS CloudTrail
E.AWS Config
AnswersA, C

Amazon CloudWatch Events (now Amazon EventBridge) is the alerting and event-routing mechanism: you can define rules that match GuardDuty findings or specific CloudTrail API calls and automatically send them to an SNS topic, Lambda function, or Systems Manager automation. For example, a rule with event source 'aws.guardduty' and detail-type 'GuardDuty Finding' can trigger an SNS notification whenever a suspicious finding is generated. This makes CloudWatch Events the delivery/alerting layer in a detection pipeline, not a source of security data itself.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can detect suspicious activity by monitoring AWS API calls, resource state changes, and custom application events in near real-time. It can trigger automated responses, such as invoking a Lambda function or sending an SNS notification, when specific patterns (e.g., unauthorized API calls or unusual resource modifications) are detected. This makes it suitable for near real-time alerting on suspicious activity.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with real-time detection, but CloudTrail delivers log files with a delay (typically 5-15 minutes) and does not natively analyze or alert on suspicious activity without additional services like CloudWatch Events or GuardDuty.

19
MCQhard

Refer to the exhibit. A security engineer runs the above AWS CLI command to search for CreateKeyPair events in CloudTrail. The command returns no results, but the engineer knows that a key pair was created during that time. What is the most likely reason for the missing events?

A.CreateKeyPair is a data event and not recorded by CloudTrail.
B.The command was run in a different region than where the key pair was created.
C.CloudTrail events are only available after 24 hours.
D.CloudTrail is not enabled for management events.
AnswerB

CloudTrail trails are scoped to a single Region unless they are organization trails or you have configured aggregation. If the CLI command ran in a different Region than where the key pair was created, the CreateKeyPair event would be delivered to the trail in the creation Region, not the one the engineer queried. The engineer would see nothing, not because the event wasn't recorded, but because they were looking in the wrong regional trail.

Why this answer

CloudTrail logs are region-specific. The `aws cloudtrail lookup-events` command without the `--region` flag defaults to the region configured in the AWS CLI (e.g., via `AWS_DEFAULT_REGION` or the CLI profile). If the CreateKeyPair event occurred in a different region, the command would return no results.

The engineer must specify the correct region using `--region` to retrieve events from that region.

Exam trap

The trap here is that candidates assume CloudTrail events are globally accessible or that the default region in the CLI will automatically include events from all regions, leading them to overlook the region-specific nature of the `lookup-events` command.

How to eliminate wrong answers

Option A is wrong because CreateKeyPair is a management (control plane) event, not a data event; CloudTrail records management events by default. Option C is wrong because CloudTrail events are typically available within minutes (up to 15 minutes), not after 24 hours. Option D is wrong because CloudTrail is enabled by default for management events in all AWS accounts, and no explicit enablement is required for management events like CreateKeyPair.

20
Multi-Selecthard

A company has a requirement to detect and alert on anomalous IAM user behavior, such as a user logging in from an unusual geographic location. The company uses AWS Organizations and has multiple accounts. Which services should the company use to meet this requirement? (Choose two.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS Config
C.Amazon GuardDuty
D.IAM Access Analyzer
E.AWS CloudTrail
AnswersC, E

Amazon GuardDuty is a managed threat detection service that continuously analyzes CloudTrail event logs, VPC Flow Logs, and DNS query logs using machine learning models and integrated threat intelligence to identify anomalous IAM behavior. It establishes a baseline of normal user activity and generates findings when it detects deviations, such as a logon from a known malicious IP, an unusual geolocation sign-in, or API calls made from a compromised credential. GuardDuty is purpose-built to alert on these anomalies and can automatically send findings to Amazon EventBridge for response.

Why this answer

Amazon GuardDuty (C) is correct because it uses machine learning to detect anomalous IAM user behavior, such as logins from unusual geographic locations, across multiple accounts when integrated with AWS Organizations. AWS CloudTrail (E) is correct because it records all IAM user sign-in events and API calls, providing the raw data that GuardDuty analyzes. CloudTrail is essential for capturing the logs that enable GuardDuty to detect anomalies.

IAM Access Analyzer (D) is incorrect because it focuses on resource policies and unintended external access, not user behavior anomalies like unusual login locations.

Exam trap

The trap is that candidates often choose only GuardDuty or mistakenly include IAM Access Analyzer. The correct pair is GuardDuty for detection and CloudTrail for logging the events that GuardDuty analyzes. CloudTrail alone does not detect anomalies, but it is necessary for providing the data.

21
Multi-Selecthard

A company wants to ensure that all API calls in their AWS account are logged and immutable. Which TWO actions should be taken? (Choose TWO.)

Select 2 answers
A.Enable MFA delete on the S3 bucket
B.Use AWS Config rules to monitor CloudTrail configuration
C.Enable S3 Object Lock on the CloudTrail S3 bucket
D.Encrypt the S3 bucket with AWS KMS
E.Enable AWS CloudTrail for all regions
AnswersC, E

Object Lock prevents log deletion or modification.

Why this answer

Enabling S3 Object Lock on the CloudTrail S3 bucket ensures that log files are immutable and cannot be overwritten or deleted by any user, including root. This is achieved through a write-once-read-many (WORM) model, which is essential for maintaining a tamper-proof audit trail of all API calls.

Exam trap

The trap here is that candidates often confuse encryption (Option D) with immutability, or they think MFA delete (Option A) provides sufficient protection, but neither prevents overwrites or ensures a WORM state, which is the core requirement for immutable logging.

22
MCQeasy

A company is experiencing unauthorized access attempts to an S3 bucket. Which AWS service can be used to detect and alert on such events in real time?

A.Amazon Macie
B.AWS Config
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty is a threat detection service that continuously monitors for malicious and unauthorized behavior using integrated threat intelligence and machine learning. It ingests S3 data events from CloudTrail, as well as VPC flow logs and DNS logs, to identify anomalies like unusual access patterns, credential compromise, or suspicious source IPs. GuardDuty generates findings in near real time, making it the appropriate service for detecting unauthorized access attempts to S3.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs. When it detects unauthorized access attempts to an S3 bucket, such as suspicious API calls or anomalous data access patterns, it generates real-time security findings that can be sent to Amazon CloudWatch Events for alerting and automated response.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with real-time threat detection, but CloudTrail only records events and does not analyze them for malicious patterns, whereas GuardDuty is purpose-built for continuous threat detection and alerting.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is a data security and data privacy service that uses machine learning to discover, classify, and protect sensitive data stored in S3, but it does not detect or alert on unauthorized access attempts in real time; it focuses on data classification and compliance, not threat detection. Option B is wrong because AWS Config is a service that evaluates and records resource configurations and compliance against desired policies, but it does not analyze real-time API activity or network traffic for unauthorized access; it is a configuration auditing tool, not a threat detection service. Option C is wrong because AWS CloudTrail records API activity for audit and governance purposes, but it does not perform real-time threat detection or alerting on its own; it provides the raw event logs that services like GuardDuty consume, but CloudTrail itself does not analyze events for malicious patterns or generate security findings.

23
MCQhard

A security team wants to collect and analyze logs from multiple AWS services including CloudTrail, VPC Flow Logs, and AWS WAF. They need a centralized solution that can filter, transform, and route logs to multiple destinations in near real-time. Which AWS service should they use?

A.Amazon CloudWatch Logs Insights
B.Amazon CloudWatch Logs subscription filters with AWS Lambda
C.Amazon Kinesis Data Streams combined with Amazon Kinesis Data Firehose
D.Amazon S3 with S3 Event Notifications
AnswerC

Kinesis Data Streams provides durable, real-time ingestion for log data arriving from multiple sources, and Kinesis Data Firehose can buffer, transform, and deliver that data to multiple destinations such as Amazon S3, Redshift, or OpenSearch. The integration is the core of a managed log pipeline, enabling both real-time processing via stream consumers and reliable batch delivery. This directly addresses the need to collect and analyze logs from multiple sources.

Why this answer

Amazon Kinesis Data Streams combined with Amazon Kinesis Data Firehose is the correct choice because it provides a fully managed, scalable, and near real-time pipeline for collecting, filtering, transforming, and routing logs from multiple AWS services (CloudTrail, VPC Flow Logs, WAF) to multiple destinations such as Amazon S3, Amazon Redshift, or Amazon Elasticsearch Service. Kinesis Data Streams captures and stores the data stream, while Kinesis Data Firehose can invoke AWS Lambda for transformation and reliably deliver the processed logs to the specified sinks, meeting the requirement for centralized, near real-time log processing.

Exam trap

The trap here is that candidates often confuse Amazon CloudWatch Logs subscription filters with Lambda as a simple routing solution, but they overlook the requirement for multiple destinations and near real-time transformation, which Kinesis Data Streams and Firehose handle natively with built-in buffering, retry logic, and Lambda integration.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs Insights is a query and analysis tool for existing CloudWatch Logs data, not a service for collecting, filtering, transforming, and routing logs to multiple destinations in near real-time. Option B is wrong because CloudWatch Logs subscription filters with AWS Lambda can forward logs to a single destination (e.g., Kinesis, Lambda, or Elasticsearch) but cannot natively route to multiple destinations or perform complex transformations without custom code, and it lacks the built-in buffering and retry capabilities of Kinesis Data Firehose. Option D is wrong because Amazon S3 with S3 Event Notifications is an object storage service that triggers notifications on object creation, but it does not support near real-time log collection, filtering, or transformation before storage, and it cannot route logs to multiple destinations directly.

24
MCQmedium

A company uses Amazon CloudWatch Logs to collect application logs from EC2 instances. The security team wants to create an alarm that triggers when a specific error pattern appears in the logs. They have set up a metric filter and an alarm. However, the alarm is not triggering even though the error pattern exists in the logs. What is the most likely cause?

A.The log group retention period is set to 1 day.
B.The metric filter uses a custom namespace that is not allowed.
C.The metric filter was created before the log group.
D.The metric filter is only applied to log events that occur after the filter is created.
AnswerD

When you create a metric filter, CloudWatch Logs begins applying it only to new log events that arrive after creation; it does not scan or backfill the log group's existing history. Any events that were recorded before the filter existed will never be evaluated, even if they match the pattern. This is why a newly added filter often shows no metrics until subsequent log events are generated.

Why this answer

CloudWatch Logs metric filters are not retroactive: they only evaluate log events that are ingested after the filter is created. If the error pattern existed in the logs before the metric filter was created, those events will not generate metric data points, so the alarm will not trigger based on historical events. This is the most likely cause of the alarm not firing.

Exam trap

SCS-C02 often tests the misconception that CloudWatch metric filters retroactively evaluate existing log data — candidates must remember that metric filters only apply to log events ingested after the filter is created, so historical errors will not trigger alarms.

How to eliminate wrong answers

Option A is wrong because a 1-day retention period would only delete old logs; it would not prevent the metric filter from matching new events that contain the error pattern, so it does not explain why the alarm fails to trigger. Option B is wrong because CloudWatch supports custom namespaces for metric filters; there is no restriction that disallows custom namespaces, so this is not a valid cause. Option C is wrong because creating a metric filter before the log group is not a supported operation — the log group must exist first — and even if recreated, the ordering does not explain the alarm not triggering for new events.

25
MCQeasy

A company needs to monitor for root account usage and receive immediate notifications. Which combination of AWS services should be used?

A.AWS Config and AWS Lambda
B.Amazon GuardDuty and AWS Lambda
C.S3 server access logs and Amazon Inspector
D.AWS CloudTrail, Amazon CloudWatch Logs, and Amazon SNS
AnswerD

AWS CloudTrail is the audit service that records every root account sign-in (eventName ConsoleLogin with userIdentity.type Root) and every root-initiated API call, and a trail can deliver those events to CloudWatch Logs. A CloudWatch Logs metric filter can match root events and publish a metric, and a CloudWatch alarm based on that metric then invokes an SNS topic to notify administrators in real time. This combination provides deterministic, account-wide monitoring of root usage and is the standard AWS-recommended pattern.

Why this answer

AWS CloudTrail captures all root account API calls, CloudWatch Logs can monitor those events for root activity using a metric filter, and Amazon SNS delivers immediate notifications when the filter triggers. This combination provides the logging, monitoring, and alerting pipeline required for real-time root account usage detection.

Exam trap

The trap here is that candidates often assume GuardDuty or Config can directly alert on root activity, but they lack the native log-to-notification pipeline that CloudTrail, CloudWatch Logs, and SNS provide together.

How to eliminate wrong answers

Option A is wrong because AWS Config is designed for resource compliance and configuration history, not for real-time monitoring of API calls like root account usage; Lambda alone cannot capture the root activity without a triggering event source like CloudTrail. Option B is wrong because Amazon GuardDuty focuses on threat detection from VPC Flow Logs, DNS logs, and CloudTrail management events, but it does not provide a native mechanism for immediate SNS notifications specifically for root account usage without additional services. Option C is wrong because S3 server access logs record object-level requests to S3, not root account API calls, and Amazon Inspector is a vulnerability assessment service that does not monitor or alert on root account activity.

26
MCQeasy

A company wants to detect and alert on SSH brute force attacks on EC2 instances. Which AWS service should be used?

A.AWS Config
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS CloudTrail
E.AWS Shield
AnswerB

Amazon GuardDuty is purpose-built for threat detection, analyzing continuous data from VPC Flow Logs, AWS CloudTrail events, and DNS query logs with machine learning and threat intelligence. It recognizes SSH brute force patterns, such as a single source IP making a large number of TCP connections to port 22 on an EC2 instance, and surfaces findings like UnauthorizedAccess:EC2/SSHBruteForce. Those findings can be pushed to Amazon EventBridge to trigger automated alerting or remediation, making it the correct service here.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, including SSH brute force attacks. It uses machine learning and integrated threat intelligence to analyze VPC Flow Logs, DNS logs, and CloudTrail events, and can generate findings for 'UnauthorizedAccess:EC2/SSHBruteForce' when repeated failed SSH login attempts are detected.

Exam trap

The trap here is that candidates often confuse Amazon Inspector (which scans for vulnerabilities) with GuardDuty (which detects active threats), or they assume CloudTrail alone can alert on brute force attacks without realizing it lacks built-in threat analysis and alerting capabilities.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration management and compliance service that evaluates resource configurations against rules, not a threat detection service; it cannot analyze network traffic or login patterns for brute force attacks. Option C is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not real-time threat detection like brute force attacks. Option D is wrong because AWS CloudTrail records API activity and can log SSH login events (via EC2 instance metadata or Systems Manager), but it does not analyze logs for malicious patterns or generate security alerts on its own.

Option E is wrong because AWS Shield is a DDoS protection service that defends against volumetric and application-layer attacks, not SSH brute force attacks which are authentication-based threats.

27
MCQmedium

A financial services company uses AWS CloudTrail to log all API calls in their account. They store the logs in an S3 bucket with server-side encryption using AWS KMS (SSE-KMS). The security team needs to ensure that only authorized users can decrypt and read the logs. They have created a KMS key with a key policy that grants decrypt permissions to the security team's IAM roles. However, when a security engineer tries to download a log file from the S3 bucket using the AWS CLI, they receive an 'AccessDenied' error. The engineer has s3:GetObject permission on the bucket. What is the most likely cause?

A.The CloudTrail trail is not configured to use SSE-KMS.
B.The S3 bucket has a bucket policy that denies access to the engineer's IAM role.
C.The S3 bucket policy does not allow the engineer to read objects.
D.The KMS key policy does not grant the engineer's role permission to decrypt.
AnswerD

To read SSE-KMS-encrypted CloudTrail logs, an IAM principal must have both s3:GetObject on the object and kms:Decrypt on the key. The KMS key policy is a resource-based policy that must include a statement allowing the engineer's role to call kms:Decrypt. If that grant is absent, the S3 GET can succeed but retrieval fails during decryption, causing the access denied error. This option correctly identifies the missing authorization.

Why this answer

The engineer has s3:GetObject permission, but the S3 object is encrypted with SSE-KMS. To decrypt and read the object, the engineer also needs kms:Decrypt permission on the KMS key. The key policy grants decrypt permissions to the security team's IAM roles, but the engineer's role may not be included.

The most likely cause is that the KMS key policy does not grant the engineer's role permission to decrypt.

Exam trap

The trap is focusing only on S3 permissions and forgetting that SSE-KMS requires additional KMS permissions; candidates might overlook the need for kms:Decrypt and the role of the key policy.

How to eliminate wrong answers

Option A is wrong because if the trail were not configured to use SSE-KMS, the object would not be encrypted with KMS, and the engineer would not need kms:Decrypt; but the scenario states it is SSE-KMS, so this is not the cause. Option B is wrong because the engineer has s3:GetObject permission, and there is no mention of a bucket policy denying access; if there were, the error would still be AccessDenied, but the most likely cause given the KMS key policy is the missing decrypt permission. Option C is wrong because the engineer already has s3:GetObject permission, so the bucket policy does not need to allow it; the issue is KMS permissions.

28
MCQmedium

A company uses Amazon GuardDuty and wants to automatically isolate a compromised EC2 instance by removing it from the security group. Which approach should be used?

A.Set up an AWS Config rule to detect the finding and remediate.
B.Configure GuardDuty to directly modify the security group.
C.Create an Amazon EventBridge rule that triggers an AWS Lambda function to remove the instance from the security group.
D.Use AWS Systems Manager Automation to automatically modify the security group based on GuardDuty findings.
AnswerC

This is the correct approach because GuardDuty publishes each finding to Amazon EventBridge as an event, and EventBridge rules can target a Lambda function with an event pattern that matches the finding's type or severity. The Lambda function can then call the ec2:RevokeSecurityGroupIngress or ModifyInstanceAttribute API to remove the instance from the offending security group, providing automated, near-real-time remediation without manual intervention. EventBridge handles the event delivery, Lambda executes the remediation logic, and IAM roles grant the necessary permissions, forming the standard architecture for GuardDuty-based automated responses.

Why this answer

Amazon GuardDuty publishes findings to Amazon EventBridge, which can be used to trigger an AWS Lambda function. The Lambda function can then call the EC2 API to modify the security group and remove the compromised instance, achieving automated isolation without requiring direct GuardDuty integration with security groups.

Exam trap

The trap here is that candidates assume GuardDuty can directly perform remediation actions (Option B) or that AWS Config is the primary service for event-driven remediation (Option A), when in reality EventBridge is the standard integration point for triggering automated responses to GuardDuty findings.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource compliance and can trigger remediation actions, but they do not natively consume GuardDuty findings; you would need a custom Lambda or Systems Manager automation to bridge them, making this an indirect and less efficient approach. Option B is wrong because GuardDuty is a threat detection service that cannot directly modify security groups; it only generates findings and has no built-in remediation capabilities. Option D is wrong because AWS Systems Manager Automation can run remediation workflows, but it requires a separate trigger (e.g., EventBridge) to start the automation document based on GuardDuty findings, making it an extra layer of complexity compared to directly invoking Lambda via EventBridge.

29
MCQmedium

A security engineer is troubleshooting why CloudTrail logs are not being delivered to an S3 bucket. The bucket policy allows CloudTrail to write objects, and the trail is configured to log management events. However, no log files appear in the bucket. What is the MOST likely cause?

A.The trail is not logging data events.
B.The S3 bucket uses SSE-KMS encryption and the trail does not have permission to use the KMS key.
C.The S3 bucket is in a different AWS account.
D.The bucket policy is missing a Deny statement.
AnswerB

When an S3 bucket uses SSE-KMS encryption, CloudTrail must have permission to call the KMS key to encrypt each delivered log file. Specifically, CloudTrail needs kms:Decrypt and kms:GenerateDataKey actions in the key policy. If those permissions are missing, CloudTrail cannot write the encrypted log objects and stops delivering logs, producing a delivery failure shown on the trail configuration page.

Why this answer

When an S3 bucket uses SSE-KMS encryption, CloudTrail requires explicit permission to use the KMS key for encrypting log files. Even if the bucket policy allows CloudTrail to write objects, the trail will fail to deliver logs if the KMS key policy does not grant the `kms:GenerateDataKey` and `kms:Decrypt` actions to the CloudTrail service principal. This is the most likely cause because the bucket policy appears correct, but the KMS key permissions are missing.

Exam trap

The trap here is that candidates assume a correct bucket policy is sufficient, overlooking that SSE-KMS encryption introduces a separate permission layer via the KMS key policy, which must explicitly authorize the CloudTrail service principal.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs management events by default and does not require data events to be enabled for log delivery to an S3 bucket; data events are an additional configuration for tracking object-level operations. Option C is wrong because CloudTrail can deliver logs to an S3 bucket in a different AWS account, provided the bucket policy grants cross-account access to the CloudTrail service principal. Option D is wrong because a Deny statement is not required for CloudTrail to write logs; the bucket policy only needs an Allow statement for the CloudTrail service principal, and a missing Deny statement would not prevent delivery.

30
MCQmedium

A company uses AWS CloudTrail to log all API calls. The security team needs to be alerted when an IAM user creates a new access key. Which approach is most efficient?

A.Enable AWS Config managed rule to detect access key creation and trigger an SNS notification.
B.Create a CloudWatch Events rule that matches the CreateAccessKey event and targets an SNS topic.
C.Use CloudWatch Logs Insights to run a query every minute on CloudTrail logs and send results to SNS.
D.Configure CloudTrail to send logs to an S3 bucket and enable S3 event notifications to an SNS topic.
AnswerB

A CloudWatch Events rule pattern-matching the CreateAccessKey API call routes the event straight to an SNS topic, delivering near-real-time alerting. This event-driven approach is more efficient than polling or log-scanning because CloudTrail already streams management events to CloudWatch Events.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can directly match the CreateAccessKey API call from AWS CloudTrail in real time and trigger an SNS notification. This approach is the most efficient as it requires no polling, no additional infrastructure, and provides immediate alerting with minimal latency.

Exam trap

The trap here is that candidates may confuse AWS Config's resource compliance monitoring with real-time event detection, or assume that S3 event notifications are suitable for low-latency security alerts, when in fact EventBridge rules are purpose-built for this use case.

How to eliminate wrong answers

Option A is wrong because AWS Config managed rules evaluate resource configurations periodically or on configuration changes, but they are not designed to detect API events like CreateAccessKey in real time; they would require a custom rule and still introduce delay. Option C is wrong because running a CloudWatch Logs Insights query every minute is inefficient, introduces up to a minute of latency, and incurs unnecessary costs for repeated scanning of log data. Option D is wrong because CloudTrail logs delivered to S3 have a delivery latency of up to 15 minutes, and S3 event notifications are not designed for real-time security alerting on API calls; this approach adds significant delay and complexity.

31
MCQeasy

A security engineer needs to capture all DNS queries made by EC2 instances in a VPC and send them to a security analytics tool. Which AWS service should be used to capture this traffic?

A.AWS Network Firewall
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerA

AWS Network Firewall is correct because it can perform stateful inspection of DNS traffic at the application layer and log each DNS request that traverses the firewall. To capture the queries, you configure a stateful rule group with the DNS protocol and enable logging to Amazon S3, CloudWatch Logs, or Kinesis Data Firehose. The resulting DNS logs include the queried domain name and the source interface, allowing the security engineer to retain a complete record of DNS activity.

Why this answer

AWS Network Firewall can be configured with stateful rule groups that inspect and log DNS traffic. By enabling DNS logging on the firewall, it captures all DNS queries and responses passing through the VPC, which can then be sent to a security analytics tool via Amazon S3, CloudWatch Logs, or Kinesis Data Firehose. This makes it the correct service for capturing DNS queries from EC2 instances.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show IP-level metadata) with the ability to capture DNS query content, not realizing that only a stateful inspection service like Network Firewall or Route 53 Resolver query logging can log the actual domain names being resolved.

How to eliminate wrong answers

Option B (VPC Flow Logs) is wrong because it captures IP traffic metadata (source/destination IP, ports, protocol, packet counts) but does not capture the content of DNS queries or responses, such as domain names being resolved. Option C (AWS CloudTrail) is wrong because it logs API calls made to AWS services (e.g., EC2 RunInstances, S3 PutObject) and does not capture network-level DNS traffic. Option D (Amazon GuardDuty) is wrong because it is a threat detection service that analyzes existing logs (like VPC Flow Logs, DNS logs from Route 53 Resolver) for anomalies; it does not capture or generate DNS query logs itself.

32
MCQmedium

A company is using AWS Config to track resource changes. They want to receive notifications when a security group is modified to allow inbound traffic from 0.0.0.0/0. What is the most efficient way to achieve this?

A.Use IAM Access Analyzer to detect publicly accessible security groups.
B.Enable Amazon GuardDuty and use its findings for security group changes.
C.Create a custom AWS Config rule with an AWS Lambda function that checks for public inbound traffic.
D.Create a CloudTrail trail and filter on AuthorizeSecurityGroupIngress events.
AnswerC

A custom AWS Config rule powered by a Lambda function can evaluate security groups on every configuration change. The Lambda function uses the AWS Config API to receive the resource's details, parses the IpPermissions, and checks for any rule with CidrIp 0.0.0.0/0 or ::/0. If public inbound traffic is found, the function returns NON_COMPLIANT, enabling continuous, automated compliance monitoring and remediation. This is exactly the kind of custom, resource-specific logic that Config supports.

Why this answer

AWS Config custom rules allow you to define a Lambda function that evaluates security group configurations against your compliance requirements. By writing a rule that checks for inbound rules with '0.0.0.0/0' on ports like SSH (22) or RDP (3389), you can trigger notifications via Amazon SNS when non-compliant changes occur. This is the most efficient approach as it directly monitors the desired condition without relying on external services or manual log analysis.

Exam trap

The trap here is that candidates often confuse CloudTrail's ability to log API calls (Option D) with the ability to evaluate the resulting resource state; CloudTrail only records the action, not the rule's content, so you would need additional logic to determine if the inbound rule actually allows 0.0.0.0/0.

How to eliminate wrong answers

Option A is wrong because IAM Access Analyzer analyzes resource policies for cross-account access, not security group rules; it does not detect inbound traffic from 0.0.0.0/0. Option B is wrong because Amazon GuardDuty focuses on threat detection (e.g., malicious activity, compromised instances) and does not provide real-time notifications for security group configuration changes. Option D is wrong because CloudTrail trails capture API calls like AuthorizeSecurityGroupIngress, but filtering these events requires additional processing (e.g., Athena queries or custom scripts) and does not directly evaluate the actual inbound rule for 0.0.0.0/0; it only logs the API call, not the rule's content.

33
MCQeasy

A security analyst needs to receive an alert when an IAM user attempts to perform an action they are not authorized to perform. Which AWS service can be used to monitor and alert on such authorization failures?

A.AWS Organizations SCPs
B.AWS CloudTrail with CloudWatch metric filter and alarm
C.AWS IAM Access Analyzer
D.AWS Config
AnswerB

CloudTrail records every IAM API call as an event, including AccessDenied responses, and can deliver those events to CloudWatch Logs. A CloudWatch Logs metric filter can count occurrences of a specific pattern, such as an IAM-issued authorization failure, and a CloudWatch alarm can then trigger an Amazon SNS notification. This combination provides near-real-time detective monitoring without inserting latency into the original IAM request.

Why this answer

AWS CloudTrail logs all API calls made by IAM users, including authorization failures (e.g., AccessDenied errors). By creating a CloudWatch metric filter on CloudTrail logs for specific error codes like 'AccessDenied' or 'UnauthorizedOperation', you can trigger a CloudWatch alarm to send notifications via SNS. This is the standard AWS approach for monitoring and alerting on unauthorized actions.

Exam trap

The trap here is that candidates confuse IAM Access Analyzer's 'findings' about external access with real-time monitoring of authorization failures, or they think AWS Config's compliance rules can alert on API denials, but neither service processes CloudTrail API logs for this purpose.

How to eliminate wrong answers

Option A is wrong because AWS Organizations SCPs are used to centrally control the maximum permissions for accounts in an organization, not to monitor or alert on authorization failures. Option C is wrong because IAM Access Analyzer identifies resources shared with external entities by analyzing resource-based policies, but it does not monitor real-time authorization failures from API calls. Option D is wrong because AWS Config evaluates resource configurations against rules and tracks configuration changes, but it does not monitor API-level authorization failures or generate alerts for denied actions.

34
MCQmedium

Refer to the exhibit. A security engineer reviews the CloudTrail trail configuration. What is a security concern?

A.The trail is not multi-region
B.The logs are not encrypted with a customer-managed KMS key
C.Log file validation is not enabled
D.CloudWatch Logs integration is missing
AnswerB

The real security gap is that `kmsKeyId` is null, meaning the CloudTrail log files are encrypted with S3-managed keys (SSE-S3) rather than a customer-managed AWS KMS key. With SSE-S3, AWS handles all key management, so the security team cannot control key rotation, define key policies, or revoke access for investigative or compliance purposes. Configuring a KMS key enables envelope encryption, provides a separate audit trail for KMS decrypt operations, and is the more secure option for CloudTrail log protection.

Why this answer

The security concern is that the CloudTrail logs are not encrypted with a customer-managed KMS key. By default, CloudTrail encrypts log files using SSE-S3 (S3-managed keys), which does not provide the customer with control over key rotation, access policies, or the ability to audit key usage. Using a customer-managed KMS key ensures that only authorized principals can decrypt the logs, and it enables fine-grained access control and audit trails via CloudTrail and CloudWatch Logs, which is critical for compliance and security monitoring.

Exam trap

The SCS-C02 exam often tests the misconception that default encryption (SSE-S3) is sufficient for compliance, but the exam expects you to recognize that customer-managed KMS keys provide additional control and auditability, making the lack of SSE-KMS a security concern.

How to eliminate wrong answers

Option A is wrong because a multi-region trail is not a mandatory security requirement; it is a configuration choice for aggregating logs from all regions, but the absence of multi-region does not directly expose logs to unauthorized access or tampering. Option C is wrong because log file validation provides integrity verification via hash digests, but it does not address encryption at rest; the lack of validation is a concern for integrity, not confidentiality, and the question specifically asks about a security concern related to the trail configuration shown. Option D is wrong because CloudWatch Logs integration is an optional feature for real-time monitoring and alerting, but its absence does not represent a direct security vulnerability; the primary concern is that logs are not encrypted with a customer-managed KMS key, which is a fundamental control for protecting sensitive audit data.

35
MCQeasy

A security engineer is configuring Amazon GuardDuty for the first time. The engineer wants to receive alerts when GuardDuty generates a finding of severity HIGH or higher. What is the simplest way to achieve this?

A.Create an Amazon EventBridge rule that matches GuardDuty findings and triggers an SNS topic.
B.Configure CloudWatch Logs to monitor GuardDuty logs and create a metric filter for high-severity findings.
C.Set up an S3 event notification on the GuardDuty findings bucket.
D.Configure GuardDuty to send email notifications for all findings.
AnswerA

Amazon GuardDuty publishes all generated findings to Amazon EventBridge (formerly CloudWatch Events) as events with a detail type of 'GuardDuty Finding'. By creating an EventBridge rule that matches the finding severity (for example, using the 'severity' field in the event detail) and setting the target to an SNS topic, you can send near-real-time alerts to security teams. This is the native, recommended integration path, and it also allows you to route findings to AWS Lambda, Step Functions, or other targets for automated remediation.

Why this answer

Amazon EventBridge can natively capture GuardDuty findings as events and route them to an SNS topic for alerting. This is the simplest approach because it requires no custom code, no log parsing, and no additional infrastructure—just a rule matching the `GuardDuty Finding` event type and a severity filter for HIGH or higher.

Exam trap

The trap here is that candidates may think GuardDuty has a native email notification feature or that findings are automatically stored in S3 or CloudWatch Logs, leading them to choose more complex or incorrect options.

How to eliminate wrong answers

Option B is wrong because GuardDuty does not write findings to CloudWatch Logs; it publishes events to EventBridge, and using CloudWatch Logs would require unnecessary log ingestion and metric filter setup. Option C is wrong because GuardDuty does not store findings in an S3 bucket by default; findings are stored in the GuardDuty service itself, and S3 event notifications are not applicable. Option D is wrong because GuardDuty does not have a built-in feature to send email notifications directly; it relies on integrations like EventBridge or SNS for alerting.

36
MCQeasy

A company wants to monitor failed SSH login attempts to EC2 instances. Which approach should be used?

A.Use the CloudWatch Logs agent to send /var/log/auth.log to CloudWatch Logs
B.Enable AWS CloudTrail for EC2 instances
C.Enable VPC Flow Logs
D.Use AWS Config to detect SSH access
AnswerA

The unified CloudWatch Logs agent (or legacy logs agent) installed on the EC2 instance tails /var/log/auth.log and streams each new line to a CloudWatch Logs log group. Once the log data is in CloudWatch Logs, you can create a metric filter that matches patterns such as 'Failed password for' or 'authentication failure' and then alarm on that metric. The agent needs an IAM role with logs:PutLogEvents permissions, but no other AWS service can natively reach into the guest OS to read auth logs.

Why this answer

Failed SSH login attempts are logged by the SSH daemon (sshd) to the system's authentication log file, typically /var/log/auth.log on Debian-based systems or /var/log/secure on Red Hat-based systems. The CloudWatch Logs agent can be configured to tail this log file and send the entries to CloudWatch Logs, where you can create metric filters to detect patterns like 'Failed password' and trigger alarms or automated responses.

Exam trap

The trap here is that candidates confuse control-plane logging (CloudTrail) with OS-level logging, or assume VPC Flow Logs can inspect application-layer data, when in fact they only capture Layer 3/4 network metadata.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API calls made to the AWS control plane (e.g., RunInstances, CreateKeyPair) and does not capture OS-level events like SSH login attempts inside an EC2 instance. Option C is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not inspect the payload of packets, so they cannot determine whether an SSH login succeeded or failed. Option D is wrong because AWS Config is a service for evaluating resource configurations against rules (e.g., checking if security groups allow SSH from 0.0.0.0/0) and does not monitor real-time OS-level authentication events.

37
Multi-Selecthard

A security team wants to implement a centralized logging solution for multiple AWS accounts. The team needs to collect VPC Flow Logs, CloudTrail logs, and DNS query logs from all accounts. Which THREE services should the team use to aggregate these logs? (Choose THREE.)

Select 3 answers
A.AWS CloudHSM
B.AWS Config
C.Amazon Route 53 Resolver query logging
D.AWS CloudTrail
E.VPC Flow Logs
AnswersC, D, E

Amazon Route 53 Resolver query logging captures DNS queries made by resources within your VPCs, including queries to on-premises networks. It satisfies the stem's requirement to collect DNS query logs centrally, publishing them to CloudWatch Logs, S3, or Kinesis Data Firehose for aggregation across accounts.

Why this answer

Amazon Route 53 Resolver query logging (C) is correct because it captures DNS queries made by resources within a VPC, including queries to the Resolver, and can publish those logs to CloudWatch Logs, S3, or Kinesis Data Firehose for centralization. AWS CloudTrail (D) is correct because it records API activity and account events across accounts, and with an organization trail you can aggregate CloudTrail logs from all accounts into a single S3 bucket. VPC Flow Logs (E) is correct because it captures IP traffic metadata for network interfaces in a VPC and can deliver logs to CloudWatch Logs or S3, enabling centralized collection across accounts.

AWS CloudHSM (A) is not a logging service; it provides dedicated hardware security modules for cryptographic key operations. AWS Config (B) tracks resource configuration changes and compliance, not VPC Flow Logs, CloudTrail events, or DNS query logs, so it does not fulfill the aggregation requirement.

Exam trap

The trap here is that candidates may confuse AWS CloudHSM or AWS Config as logging services, but neither is designed for log collection or aggregation; CloudHSM is for key management and Config is for configuration auditing, not for aggregating VPC Flow Logs, CloudTrail logs, or DNS query logs.

38
Multi-Selecteasy

A security engineer is configuring VPC Flow Logs to capture network traffic metadata. Which TWO attributes can be captured in VPC Flow Logs? (Choose TWO.)

Select 2 answers
A.Packet payload
B.Source IP address
C.IAM user ID
D.Destination port
E.DNS query name
AnswersB, D

This is the correct answer. VPC Flow Logs capture the source IP address in the srcaddr field for every accepted or rejected network connection, as part of the standard flow log record. The srcaddr field is available in all flow log versions and is used to identify the origin of the traffic. It is recorded regardless of whether the traffic was allowed or denied by security groups or network ACLs.

Why this answer

VPC Flow Logs capture metadata about network traffic, including the source IP address (option B) and destination port (option D). The source IP address identifies the origin of the traffic, while the destination port indicates the application or service being targeted. These are standard fields in the flow log record format, as defined by AWS for capturing IP traffic metadata.

Exam trap

The trap here is that candidates often confuse network metadata with application-layer data, mistakenly thinking VPC Flow Logs can capture packet payloads or DNS query names, which are not part of the flow log record format.

39
Multi-Selectmedium

A company needs to monitor for unauthorized changes to security group rules. Which TWO AWS services can be used together to achieve this?

Select 2 answers
A.Amazon GuardDuty
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
E.Amazon CloudWatch Events
AnswersB, E

AWS Config is purpose-built for recording configuration item changes and evaluating them against desired policies. When a security group rule is added, removed, or modified, Config generates a configuration item and can trigger an AWS Config rule (e.g., a managed rule or a custom Lambda rule) that determines whether the new state is compliant with the organization's requirements. It provides a timeline of every change, so you can identify exactly what was unauthorized and when it happened, and it can automatically remediate noncompliant rules via Systems Manager Automation. This is why AWS Config is the core service for this monitoring need.

Why this answer

Options B and E are correct. AWS Config can track changes to security group rules, and Amazon CloudWatch Events can trigger a notification when a Config rule detects a change. Option A (GuardDuty) is for threat detection.

Option C (Inspector) is for vulnerability scanning. Option D (CloudTrail) logs API calls but is not the best for direct rule-level monitoring.

40
MCQhard

A security team uses Amazon Macie to discover sensitive data in S3. They have configured Macie to run automated sensitive data discovery jobs. After reviewing the findings, they notice that some S3 objects containing personally identifiable information (PII) are not being flagged. What is the most likely cause?

A.The Macie service-linked role does not have permissions to read the objects.
B.The S3 bucket is in a different AWS Region than the Macie job.
C.The S3 objects are encrypted with SSE-S3.
D.The PII is in a format that Macie's managed data identifiers do not recognize, and no custom data identifier is configured.
AnswerD

This is correct because Macie relies on managed data identifiers that recognize common PII patterns, such as US Social Security numbers and credit card numbers. If the PII is in a proprietary or less common format that these built-in identifiers do not match, Macie will not flag it. Since no custom data identifier was created to define that specific format, Macie has no way to detect the sensitive data, so the data goes undiscovered.

Why this answer

Macie uses managed data identifiers to detect PII based on predefined patterns. If the PII in the S3 objects is in a format that does not match any of these managed identifiers (e.g., a non-standard date format or a custom ID number), and no custom data identifier has been configured to recognize that specific pattern, Macie will not flag the objects. This is the most likely cause given that the security team has already configured automated discovery jobs and other common issues like permissions or encryption are not preventing scanning.

Exam trap

The trap here is that candidates often assume encryption (SSE-S3) or cross-region issues block Macie, but Macie is designed to handle both seamlessly, and the real limitation is the scope of its pattern-matching identifiers.

How to eliminate wrong answers

Option A is wrong because the Macie service-linked role (AWSServiceRoleForAmazonMacie) is automatically created and granted the necessary permissions (e.g., s3:GetObject, s3:ListBucket) to read objects in S3 buckets that are in scope for the discovery job; if the role lacked permissions, Macie would report an access error, not silently skip objects. Option B is wrong because Macie supports cross-region analysis: a single Macie job can analyze S3 buckets in any AWS Region, as long as the bucket is in the same AWS partition and the Macie service is enabled in the job's home Region. Option C is wrong because Macie can scan objects encrypted with SSE-S3 (Amazon S3-managed keys) without any additional configuration; SSE-S3 encryption does not block Macie's read access because Macie uses the service-linked role to decrypt the objects via S3's server-side decryption.

41
Multi-Selecthard

A company wants to ensure that all S3 buckets are encrypted at rest. Which THREE services can be used to detect and alert on unencrypted buckets?

Select 3 answers
A.AWS Config
B.Amazon CloudWatch Logs Insights
C.Amazon VPC Flow Logs
D.AWS Security Hub
E.AWS CloudTrail with Amazon CloudWatch Events
AnswersA, D, E

AWS Config provides a managed rule, s3-bucket-server-side-encryption-enabled, that continuously evaluates each S3 bucket's configuration to determine whether default encryption is set to SSE-S3, SSE-KMS, or DSSE. It records the compliance state as a resource configuration history and can trigger automatic remediation actions, such as enabling encryption via a Systems Manager automation document. This gives you ongoing, real-time visibility into unencrypted buckets rather than relying on post-hoc event detection.

Why this answer

AWS Config can evaluate S3 bucket configurations against managed rules like 's3-bucket-server-side-encryption-enabled' to detect unencrypted buckets. When a bucket violates the rule, AWS Config can trigger an Amazon SNS notification or invoke a Lambda function for remediation, enabling real-time alerting.

Exam trap

The trap here is that candidates may think Amazon CloudWatch Logs Insights or VPC Flow Logs can be used for configuration auditing, but they are designed for log analysis and network monitoring, not for detecting resource configuration states like encryption settings.

42
Multi-Selectmedium

A security engineer is designing a centralized logging solution for multiple AWS accounts. Which TWO services should be used to aggregate logs from all accounts into a single account? (Choose TWO.)

Select 2 answers
A.AWS Config
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.Amazon S3
E.AWS CloudTrail
AnswersC, E

Amazon CloudWatch Logs is correct because you can create a cross-account destination in a central account—for example, a Kinesis Data Streams stream or an Amazon OpenSearch Service cluster—and attach a subscription filter in each source account's log group to stream log events to that destination. The CloudWatch Logs destination resource holds the ARN of the central resource and an IAM role that grants the source account permission to send data. This natively supports the real-time, centralized log collection that the scenario requires.

Why this answer

Amazon CloudWatch Logs can receive log data from multiple AWS accounts via cross-account subscription filters, allowing a centralized logging account to aggregate logs from all source accounts. AWS CloudTrail can be configured to deliver trail logs from multiple accounts to a single S3 bucket in a central account, enabling consolidated audit logging. Together, these two services provide a comprehensive centralized logging solution for multi-account environments.

Exam trap

The trap here is that candidates often confuse log destinations (like S3) with log aggregation services, failing to recognize that S3 is a passive storage target and does not actively collect or aggregate logs from multiple accounts without the orchestration provided by CloudWatch Logs or CloudTrail.

43
MCQeasy

A company uses Amazon GuardDuty to detect threats. The security team wants to receive real-time notifications for all GuardDuty findings with a severity of HIGH or CRITICAL. What is the MOST efficient way to achieve this?

A.Create a CloudWatch Events rule that matches GuardDuty findings with severity HIGH or CRITICAL and targets an SNS topic.
B.Use the GuardDuty console to set up email alerts for high-severity findings.
C.Configure GuardDuty to export findings to an S3 bucket and use S3 event notifications to trigger an SNS topic.
D.Stream GuardDuty findings to CloudWatch Logs and create a metric filter to trigger an alarm.
AnswerA

GuardDuty publishes every finding to Amazon EventBridge (formerly CloudWatch Events) in near real-time as it is generated, with the finding's severity encoded in the detail.payload.severity field. A rule with an event pattern matching severity labels HIGH or CRITICAL (numeric values 7 and 8) can invoke an SNS topic, giving you the lowest-latency, fully managed notification path. This is the correct approach because it uses the native event bus rather than relying on polling or periodic exports.

Why this answer

Amazon GuardDuty integrates natively with Amazon CloudWatch Events (now part of Amazon EventBridge) to emit findings as events. By creating a CloudWatch Events rule that filters for findings with a severity value of 7.0 or higher (HIGH or CRITICAL), you can directly target an Amazon SNS topic to send real-time notifications. This approach is the most efficient as it avoids intermediate storage or polling, providing near-instantaneous alerting with minimal latency and operational overhead.

Exam trap

The trap here is that candidates may think exporting to S3 or CloudWatch Logs is necessary for analysis, but for real-time notifications, CloudWatch Events (EventBridge) is the direct and most efficient integration, avoiding unnecessary intermediate steps.

How to eliminate wrong answers

Option B is wrong because the GuardDuty console does not provide a native feature to set up email alerts directly; it relies on integrations like CloudWatch Events or SNS for automated notifications. Option C is wrong because exporting findings to an S3 bucket and using S3 event notifications introduces unnecessary latency and complexity, as S3 event notifications are not designed for real-time alerting and may have delays of several minutes. Option D is wrong because streaming findings to CloudWatch Logs and creating a metric filter to trigger an alarm adds extra steps and potential delays, whereas CloudWatch Events provides a more direct and real-time path without the need for log ingestion and metric evaluation.

44
MCQhard

A company uses Amazon GuardDuty to monitor for malicious activity in its AWS environment. The security team receives a high number of findings, many of which are false positives. They want to reduce noise by suppressing findings for known benign activities, such as internal vulnerability scans performed by the security team. GuardDuty has a feature to create suppression rules based on finding criteria. However, the team also wants to ensure that if a new type of threat is detected, it is immediately escalated. What is the MOST effective way to manage GuardDuty findings?

A.Set GuardDuty to only generate findings for medium and high severity, ignoring low severity findings.
B.Create a suppression rule that blocks all findings from the internal IP range used by the security team.
C.Disable the specific GuardDuty finding types that generate false positives.
D.Create suppression rules that automatically archive findings matching the known benign activity criteria, and periodically review the suppressed findings.
AnswerD

Creating suppression rules that match the exact criteria of the known benign activity lets GuardDuty automatically archive those findings while still generating every other finding for review. Because suppression does not delete findings, you can periodically audit the Suppressed tab to ensure the criteria still reflect genuinely innocuous behavior and to adjust for evolving threat intelligence or environment changes. This reduces alert noise without sacrificing visibility and follows GuardDuty's recommended best practice of using scoped filters and suppression instead of disabling broad detection capabilities.

Why this answer

GuardDuty suppression rules automatically archive findings that match specified criteria (e.g., a known internal scanner IP), removing them from the active findings list without disabling detection. Periodically reviewing suppressed findings ensures that if the benign activity pattern changes or a real threat reuses that IP, the team can catch it. This balances noise reduction with the requirement to escalate genuinely new threats.

Exam trap

SCS-C02 often tests the misconception that suppression equals disabling detection — candidates may pick 'disable the finding type' or 'block all findings from an IP,' but the correct answer preserves detection while archiving known-benign matches and reviewing them periodically.

How to eliminate wrong answers

Option A is wrong because filtering by severity would suppress low-severity findings that may still be meaningful (e.g., reconnaissance), and it does not address the specific false positives from internal scans. Option B is wrong because a blanket suppression rule blocking all findings from the internal IP range would also hide genuine compromises originating from or targeting that range, violating the requirement to escalate new threats. Option C is wrong because disabling finding types entirely stops detection of those threats across the whole account, which is far more dangerous than suppressing specific known-benign instances.

45
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to enable CloudTrail for all accounts and centrally store logs. What is the most efficient way to achieve this?

A.Use an S3 bucket policy to allow cross-account log delivery
B.Create a CloudTrail trail in the management account and apply it to all accounts in the organization
C.Use AWS Lambda to create trails in each account
D.Ask each account admin to create their own CloudTrail trail and deliver to a central S3 bucket
AnswerB

Creating the trail in the management account with organisation-wide application lets CloudTrail deliver every member account's events to one central S3 bucket, satisfying the centralised-storage constraint. This is the native AWS Organizations integration, avoiding per-account trail duplication and the operational overhead of manual configuration across accounts.

Why this answer

AWS Organizations allows you to create a single CloudTrail trail in the management account that automatically applies to all member accounts within the organization. This is the most efficient method as it eliminates the need for manual per-account configuration or custom automation, and it ensures consistent logging across the entire organization with centralized log delivery to a single S3 bucket.

Exam trap

The trap here is that candidates often assume cross-account S3 bucket policies (Option A) are sufficient, overlooking the native organization-wide trail capability that automates trail creation and management across all accounts.

How to eliminate wrong answers

Option A is wrong because while an S3 bucket policy can allow cross-account log delivery, it does not automate the creation of CloudTrail trails in each account; each account would still need to manually create its own trail, which is inefficient and error-prone. Option C is wrong because using AWS Lambda to create trails in each account introduces unnecessary complexity, potential latency, and maintenance overhead compared to the native organization-wide trail feature. Option D is wrong because asking each account admin to create their own trail is not only inefficient but also risks inconsistent configurations, missing logs, and increased administrative burden.

46
MCQhard

A company uses Amazon RDS for MySQL and needs to monitor database activity for suspicious queries, such as unauthorized access attempts or SQL injection. The security team wants to centralize the logs from multiple RDS instances and analyze them in near real-time. Which solution should be implemented?

A.Enable RDS Enhanced Monitoring and stream the metrics to Amazon CloudWatch.
B.Enable VPC Flow Logs for the RDS instances and analyze the logs using Amazon Athena.
C.Enable AWS CloudTrail for RDS API calls and use Amazon GuardDuty to analyze the logs.
D.Enable database audit logs on each RDS instance, stream them to Amazon CloudWatch Logs, and use CloudWatch Logs Insights to query the logs.
AnswerD

Streaming RDS audit logs to CloudWatch Logs satisfies the centralisation and near real-time analysis constraints: multiple instances publish to one log service, and Logs Insights queries them interactively. Unlike RDS Performance Insights, which reports load metrics rather than statement text, audit logging captures suspicious queries such as SQL injection attempts for investigation.

Why this answer

RDS for MySQL audit logs capture detailed database-level activity, including login attempts, query execution, and SQL injection patterns. Streaming these logs to CloudWatch Logs enables near real-time analysis using CloudWatch Logs Insights, which supports querying and alerting on suspicious queries across multiple RDS instances from a centralized location.

Exam trap

The trap here is confusing database-level audit logs (which capture SQL queries and authentication events) with infrastructure-level logs like Enhanced Monitoring or VPC Flow Logs, leading candidates to choose options that monitor performance or network traffic instead of actual database activity.

How to eliminate wrong answers

Option A is wrong because RDS Enhanced Monitoring provides OS-level metrics (CPU, memory, disk I/O) but does not capture database query content or authentication events needed to detect suspicious queries or SQL injection. Option B is wrong because VPC Flow Logs record network traffic metadata (IP addresses, ports, protocols) but do not include database query text or user authentication details; they cannot identify SQL injection or unauthorized access attempts at the database level. Option C is wrong because AWS CloudTrail logs RDS API calls (e.g., CreateDBInstance, ModifyDBInstance) but does not capture database engine-level activity such as SQL queries or login attempts; GuardDuty analyzes CloudTrail, VPC Flow Logs, and DNS logs for threats but cannot inspect database query content.

47
MCQmedium

A company uses AWS CloudTrail to log API activity across multiple accounts. The security team wants to ensure that any S3 bucket created with public read access is detected within minutes. Which solution is MOST efficient?

A.Create an Amazon EventBridge rule that matches CloudTrail CreateBucket API calls and triggers a Lambda function that inspects the bucket's public access settings and alerts if public.
B.Use AWS Config rules to check S3 bucket public access settings and trigger an AWS Lambda function to send alerts.
C.Use S3 server access logs and run a daily script to parse the logs for PutBucketAcl actions.
D.Enable CloudTrail log file validation and use Athena to query logs hourly for CreateBucket events with public ACLs.
AnswerA

An EventBridge rule can pattern-match CloudTrail API events as they are emitted, meaning a CreateBucket call with a public access configuration triggers the Lambda function within seconds of the API completing. The Lambda can then use GetPublicAccessBlock, GetBucketPolicyStatus, or GetBucketAcl to determine whether the bucket is actually public and immediately alert a security team, making this the only option that combines near-real-time detection with direct inspection of the resulting bucket configuration.

Why this answer

It uses an Amazon EventBridge rule to capture the CloudTrail `CreateBucket` API call in near real-time, then triggers a Lambda function to immediately inspect the bucket's public access settings. This approach detects public buckets within minutes without polling or batch processing, making it the most efficient solution for the stated requirement.

Exam trap

The trap here is that candidates often choose AWS Config rules (Option B) because they associate Config with compliance checks, but they overlook the latency of Config evaluations versus the near-real-time capability of EventBridge for API-driven detection.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource configurations on a periodic basis (e.g., every 10 minutes or hourly) or on configuration changes, but they do not guarantee detection within minutes of the bucket creation; the evaluation delay can exceed the required time window. Option C is wrong because S3 server access logs are delivered on a best-effort basis, often with delays of several hours, and a daily script would not meet the 'within minutes' requirement. Option D is wrong because CloudTrail log file validation only ensures integrity, not real-time detection, and using Athena to query logs hourly introduces at least a one-hour delay, failing the 'within minutes' requirement.

48
MCQmedium

A security engineer is troubleshooting an issue where CloudTrail logs are not being delivered to the specified S3 bucket. The bucket policy allows CloudTrail to write objects. What is the MOST likely cause?

A.The S3 bucket uses server-side encryption with customer-provided keys (SSE-C).
B.The S3 bucket has a bucket policy that denies access to the CloudTrail service principal.
C.The S3 bucket does not have versioning enabled.
D.The S3 bucket is in a different AWS account.
AnswerB

An explicit Deny statement in the destination bucket policy that references the CloudTrail service principal (cloudtrail.amazonaws.com) will override any Allow that CloudTrail receives through its service role or resource-based policies. In AWS IAM policy evaluation, an explicit deny acts as an absolute veto, so CloudTrail's attempts to perform s3:PutObject and s3:GetBucketAcl fail with Access Denied. Because this would block delivery regardless of encryption, versioning, or account location, it is the likely root cause.

Why this answer

The most likely cause is that the S3 bucket policy explicitly denies access to the CloudTrail service principal. Even if a bucket policy allows CloudTrail to write logs, an explicit deny statement overrides any allow, preventing log delivery. This is a common misconfiguration where a deny rule is inadvertently applied to the CloudTrail principal.

Exam trap

The trap here is that candidates often overlook explicit deny statements in bucket policies, assuming that an allow statement alone is sufficient for CloudTrail log delivery, but AWS IAM policy evaluation always prioritizes explicit denies over allows.

How to eliminate wrong answers

Option A is wrong because SSE-C does not prevent CloudTrail from writing logs; CloudTrail supports SSE-C and can deliver logs to buckets using customer-provided keys. Option C is wrong because S3 versioning is not required for CloudTrail log delivery; CloudTrail can write objects to a bucket without versioning enabled. Option D is wrong because CloudTrail can deliver logs to an S3 bucket in a different AWS account, provided the bucket policy grants the necessary permissions to the CloudTrail service principal from the source account.

49
MCQhard

Refer to the exhibit. A security engineer created this S3 bucket policy to allow CloudTrail to deliver logs from account 123456789012 to the bucket my-trail-bucket. However, CloudTrail logs are not being delivered. What is the most likely reason?

A.The Principal should be the CloudTrail service principal for the specific region.
B.The Action should be s3:PutObjectAcl instead of s3:PutObject.
C.The resource ARN does not include the bucket name.
D.The policy is missing s3:GetBucketAcl permission.
AnswerD

CloudTrail requires not only write permission via s3:PutObject but also s3:GetBucketAcl to inspect the bucket's ACL and confirm it is not publicly writable. Without this permission, CloudTrail aborts log delivery even if the bucket policy allows PutObject, which is why this option identifies the real defect. Granting both actions fixes the configuration.

Why this answer

CloudTrail requires both s3:PutObject and s3:GetBucketAcl permissions on the destination S3 bucket to validate that the bucket policy grants the necessary access. Without s3:GetBucketAcl, CloudTrail cannot confirm the bucket's ACL allows log delivery, causing delivery to fail.

Exam trap

The trap here is that candidates focus on the obvious s3:PutObject action and overlook the required s3:GetBucketAcl permission, which is a subtle but critical prerequisite for CloudTrail log delivery.

How to eliminate wrong answers

Option A is wrong because CloudTrail uses a service principal (cloudtrail.amazonaws.com) that is region-agnostic; specifying a region-specific principal is unnecessary and not the cause of the failure. Option B is wrong because CloudTrail uses s3:PutObject to deliver logs, not s3:PutObjectAcl; ACLs are managed separately via bucket policies or ACLs, not through the PutObject action. Option C is wrong because the resource ARN in the exhibit includes the bucket name (my-trail-bucket), so the ARN is correctly formatted; the issue is missing permissions, not an incorrect ARN.

50
MCQeasy

A security engineer is investigating a potential security incident and needs to determine if an EC2 instance was launched with a specific AMI ID. Which AWS log should be examined?

A.AWS Config timeline
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs (EC2 agent logs)
AnswerC

AWS CloudTrail is the correct source because it records the RunInstances API call as a management event, and the event's requestParameters field contains the ImageId (AMI ID) as well as instance type, key name, security groups, and subnet. The event's userIdentity and sourceIPAddress/vpcEndpoint fields identify exactly which IAM principal or role launched the instance and from where. CloudTrail EventHistory is normally searchable for 90 days; for older incidents, you must query the delivery to an S3 bucket or CloudTrail Lake.

Why this answer

AWS CloudTrail records all API calls made within an AWS account, including the RunInstances API call that launches an EC2 instance. The CloudTrail event for RunInstances contains the AMI ID in the request parameters, allowing you to determine if a specific AMI was used. This makes CloudTrail the correct log to examine for this investigation.

Exam trap

The trap here is that candidates often confuse AWS Config (which shows resource configuration history) with CloudTrail (which logs API calls), leading them to choose AWS Config timeline even though it does not capture the AMI ID parameter from the launch request.

How to eliminate wrong answers

Option A is wrong because AWS Config timeline shows configuration changes and compliance history of resources over time, but it does not log the specific AMI ID used at launch; it records the resulting configuration state, not the API call parameters. Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) and have no visibility into EC2 instance launch details like AMI IDs. Option D is wrong because Amazon CloudWatch Logs with the EC2 agent collect OS-level logs (syslog, application logs) from inside the instance, which cannot capture the AMI ID used to launch the instance, as that information is not available to the guest OS.

51
MCQmedium

A security engineer is investigating a potential security incident involving an EC2 instance. The engineer needs to determine if any unauthorized SSH keys were added to the instance's authorized_keys file. Which AWS service should be used to detect this change?

A.Amazon Inspector
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerD

AWS Config is the correct service because it records configuration state changes and can track software and file inventory from managed instances through an integration with AWS Systems Manager Inventory. When SSM Inventory collects file attributes such as path, size, and modification time, AWS Config can use custom rules or advanced queries to flag deviations from a known-good baseline. This makes AWS Config the service that directly supports file-change audits and compliance enforcement in response to suspected tampering.

Why this answer

AWS Config is the correct service because it can be used to monitor configuration changes to EC2 instances, including changes to the authorized_keys file when integrated with AWS Systems Manager. While AWS Config does not natively track guest OS file changes, you can create a custom AWS Config rule that invokes a Lambda function to check the instance's Systems Manager inventory or run a command to verify the file contents. CloudTrail tracks API calls but does not monitor internal OS changes.

Amazon Inspector and GuardDuty focus on vulnerabilities and threats, not configuration changes. Therefore, AWS Config, with appropriate custom rules, is the best choice among the options.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's ability to track API-level changes (e.g., modifying an EC2 instance) with the need to monitor guest OS file changes, which requires a configuration management service like AWS Config, not CloudTrail.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not for tracking file changes like SSH authorized_keys. Option B is wrong because AWS CloudTrail records API calls made to the AWS environment, such as launching or modifying EC2 instances, but it does not monitor changes inside the guest OS, such as modifications to the authorized_keys file. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (e.g., VPC Flow Logs, DNS logs) for malicious activity, but it does not track configuration changes to files within an EC2 instance.

52
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. The user reports that they cannot upload objects to the S3 bucket 'example-bucket' using the AWS CLI from a remote location. What is the MOST likely cause?

A.The CLI is using HTTP instead of HTTPS.
B.The bucket policy denies access.
C.The bucket requires server-side encryption.
D.The user is not authorized to upload to the bucket.
E.The user does not have s3:PutObject permission.
AnswerA

The IAM policy includes a Deny statement that triggers when the `aws:SecureTransport` condition is false, which is exactly the case for HTTP requests. The AWS CLI can be configured to use an HTTP endpoint (e.g., via `--endpoint-url http://...`), and doing so causes the Deny to take precedence over the Allow for `s3:PutObject`. As a result, the upload is rejected with an AccessDenied error.

Why this answer

The IAM policy shown in the exhibit includes a `Deny` effect for `s3:PutObject` when the request does not use `aws:SecureTransport` (i.e., HTTPS). If the AWS CLI is configured to use HTTP instead of HTTPS, the condition `aws:SecureTransport=false` is met, and the explicit deny blocks the upload. The user reports the issue from a remote location, which often involves misconfigured endpoints or proxies that force HTTP.

Exam trap

The trap here is that candidates often focus on the `Allow` statement and overlook the `Deny` statement with the `aws:SecureTransport` condition, assuming the user lacks permission entirely rather than recognizing the protocol-level restriction.

How to eliminate wrong answers

Option B is wrong because the exhibit shows an IAM policy attached to the user, not a bucket policy; a bucket policy is a separate resource-based policy that could deny access, but the question states the policy is attached to the user, and no bucket policy is mentioned. Option C is wrong because the policy does not reference server-side encryption (e.g., `s3:x-amz-server-side-encryption`), and the error is about upload failure, not encryption mismatch. Option D is wrong because the user is authorized via the IAM policy's `Allow` statement for `s3:PutObject`; the issue is the `Deny` condition on `aws:SecureTransport`.

Option E is wrong because the user does have `s3:PutObject` permission granted by the `Allow` statement; the problem is the overriding `Deny` when HTTP is used.

53
MCQmedium

A security engineer configured the S3 bucket policy shown above for CloudTrail log delivery, but CloudTrail is not delivering logs. What is the MOST likely reason?

A.The policy does not include s3:GetBucketAcl permission.
B.The bucket is in the wrong region.
C.The resource ARN is incorrect.
D.The bucket does not have default encryption enabled.
AnswerA

CloudTrail's bucket policy must explicitly grant the service principal cloudtrail.amazonaws.com both s3:GetBucketAcl and s3:PutObject permissions for the target bucket. s3:GetBucketAcl is what lets CloudTrail verify that the bucket's access control list permits CloudTrail to write and manage log objects; without this permission, CloudTrail aborts the delivery configuration with an access denial even if PutObject is correctly allowed. Therefore, omitting s3:GetBucketAcl is a direct cause of the 'bucket policy does not allow for S3 access' error.

Why this answer

CloudTrail requires the s3:GetBucketAcl permission on the destination S3 bucket to verify that the bucket policy grants the necessary access. Without this permission, CloudTrail cannot confirm it has write access and will fail to deliver logs. The bucket policy must explicitly allow the CloudTrail service principal to perform GetBucketAcl and PutObject actions.

Exam trap

The trap here is that candidates often focus on the PutObject permission or the resource ARN, overlooking the mandatory GetBucketAcl permission that CloudTrail requires for initial validation.

How to eliminate wrong answers

Option B is wrong because CloudTrail can deliver logs to a bucket in any region as long as the bucket policy allows cross-region access; the bucket region does not prevent delivery. Option C is wrong because the resource ARN in the policy is typically correct when it matches the bucket name and account, and an incorrect ARN would cause an access denied error, but the most common missing permission is GetBucketAcl. Option D is wrong because default encryption on the S3 bucket is not a prerequisite for CloudTrail log delivery; CloudTrail can write unencrypted objects or use server-side encryption with S3-managed keys (SSE-S3) by default.

54
MCQeasy

A company needs to be alerted when root account credentials are used in their AWS account. Which service should be used to create a metric filter and alarm for this event?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerD

Amazon CloudWatch Logs can receive CloudTrail events and apply a metric filter, for example matching $.userIdentity.type = 'Root' and $.eventName = 'ConsoleLogin', to count root credential activity. A CloudWatch alarm on that metric threshold can then trigger an SNS notification to alert the company in near real time. This is the correct service because it directly enables custom, log-driven alerting on the root account usage pattern.

Why this answer

Amazon CloudWatch Logs can monitor CloudTrail log events for root account usage by creating a metric filter that matches the `userIdentity.type` field with a value of `Root`. When the filter detects a match, it triggers a CloudWatch alarm to notify the operations team. This is the standard AWS-recommended approach for alerting on root activity.

Exam trap

The trap here is that candidates confuse CloudTrail (the log source) with CloudWatch Logs (the service that processes and alerts on logs), assuming CloudTrail itself can create alarms when it only delivers logs to S3 or CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that uses machine learning to identify malicious activity, but it does not natively support creating custom metric filters or alarms for specific CloudTrail events like root login. Option B is wrong because AWS Config is a service for evaluating resource configurations against rules, not for monitoring API call patterns in logs; it cannot create metric filters or alarms on CloudTrail events. Option C is wrong because AWS CloudTrail itself records API activity and delivers log files, but it does not provide the ability to create metric filters or alarms; that functionality is delegated to CloudWatch Logs.

55
Multi-Selecthard

Which THREE are best practices for securing AWS CloudTrail log files? (Choose three.)

Select 3 answers
A.Restrict access to the S3 bucket using a bucket policy that requires MFA and encryption.
B.Enable CloudTrail log file integrity validation.
C.Enable server-side encryption (SSE) for the S3 bucket.
D.Deliver logs to an S3 bucket in the same region as the trail.
E.Set a lifecycle policy to delete logs after 30 days.
AnswersA, B, C

Restricting access to the S3 bucket with a bucket policy that includes the aws:MultiFactorAuthPresent condition ensures that every request requires MFA authentication, significantly reducing the risk of unauthorized log access even if a user's long-term credentials are compromised. Adding an encryption enforcement condition, such as requiring TLS (aws:SecureTransport) or mandatory SSE-KMS headers, further protects the logs in transit and at rest. This layered access control is a best practice because it hardens the audit trail against both external attacks and accidental exposure.

Why this answer

Restricting access to the S3 bucket with a bucket policy that requires MFA (Multi-Factor Authentication) and encryption (e.g., aws:MultiFactorAuthPresent and aws:SecureTransport conditions) ensures that only authenticated and authorized users can access CloudTrail logs, and that data is encrypted in transit. This prevents unauthorized deletion or modification of log files, which is critical for maintaining an immutable audit trail.

Exam trap

The trap here is that candidates often confuse operational convenience (e.g., same-region delivery or short retention) with security best practices, forgetting that security requires cross-region resilience and long-term retention for auditability.

56
MCQhard

A company uses AWS CloudTrail to log all API calls across multiple accounts in AWS Organizations. The security team notices that management events are being logged, but data events for Amazon S3 are not appearing in the CloudTrail logs for any account. The team needs to enable data event logging for S3 across all accounts. Currently, the organization trail is configured in the management account, and all member accounts have default CloudTrail configurations. What is the MOST efficient way to enable S3 data event logging for all current and future accounts in the organization?

A.Ask each member account to create a new trail in their own account with S3 data events enabled.
B.Update the existing organization trail's event selectors in the management account to include S3 data events for all accounts.
C.Enable S3 server access logging on all S3 buckets across the organization and aggregate logs in a central S3 bucket.
D.Create a new organization trail in the management account with S3 data events enabled, and share it with member accounts.
AnswerB

In the management account, edit the existing organization trail and update its event selectors to include S3 data events, choosing 'All S3 buckets' for object-level operations such as GetObject, PutObject, and DeleteObject. CloudTrail propagates this configuration to every member account, so all current and future accounts are captured automatically without per-account changes. This is the intended, least-effort method and keeps delivery centralized in the original destination bucket.

Why this answer

An organization trail in the management account can have its event selectors updated to include S3 data events for all accounts in the organization. This change automatically applies to all existing and future member accounts, as organization trails are replicated to all accounts by AWS CloudTrail. No additional configuration is needed in member accounts, making it the most efficient approach.

Exam trap

The trap here is that candidates may think they need to create a new organization trail or involve member accounts, but the most efficient solution is to update the existing organization trail's event selectors, which automatically applies to all current and future accounts.

How to eliminate wrong answers

Option A is wrong because asking each member account to create a separate trail is inefficient and does not scale for future accounts; it also duplicates effort and log storage. Option C is wrong because S3 server access logging logs object-level access requests (e.g., GET, PUT) but is not CloudTrail data event logging; it does not integrate with CloudTrail's event history or organization-wide trails. Option D is wrong because you cannot 'share' a trail with member accounts; organization trails are created in the management account and automatically applied to all accounts in the organization—creating a new trail is unnecessary when the existing organization trail can be updated.

57
MCQeasy

A company wants to monitor CPU utilization of their EC2 instances and receive an alert when utilization exceeds 80% for 5 consecutive minutes. Which AWS service should be used to set up this metric alarm?

A.Amazon CloudWatch Alarms
B.Amazon Inspector
C.AWS Config
D.AWS CloudTrail
AnswerA

Amazon CloudWatch Alarms watch the EC2 instance's CPUUtilization metric published to CloudWatch and transition to ALARM when the value crosses a defined threshold for consecutive evaluation periods. Because this metric and the alarm's state are specifically designed for performance monitoring, an alarm can directly trigger actions such as SNS notifications or Auto Scaling policies when CPU load becomes unacceptable.

Why this answer

Amazon CloudWatch Alarms is the correct service because it is specifically designed to monitor CloudWatch metrics, such as EC2 CPU utilization, and trigger actions (e.g., SNS notifications) when a metric crosses a defined threshold for a specified number of consecutive evaluation periods. In this scenario, you would create a CloudWatch Alarm on the `CPUUtilization` metric with a threshold of 80%, set the period to 1 minute, and configure the alarm to evaluate 5 consecutive datapoints (periods) to meet the '5 consecutive minutes' requirement.

Exam trap

The trap here is that candidates often confuse AWS Config (configuration compliance) or CloudTrail (API auditing) with CloudWatch Alarms, because they all involve 'monitoring' in a broad sense, but only CloudWatch Alarms handles metric-based threshold alerts for performance data like CPU utilization.

How to eliminate wrong answers

Option B (Amazon Inspector) is wrong because it is a vulnerability management service that scans EC2 instances for software vulnerabilities and unintended network exposure, not for monitoring CPU utilization metrics. Option C (AWS Config) is wrong because it is a service for evaluating and recording resource configuration changes and compliance against rules, not for real-time metric monitoring or alarm thresholds. Option D (AWS CloudTrail) is wrong because it records API activity and user actions for auditing and governance, not for monitoring performance metrics like CPU utilization.

58
MCQhard

A company uses Amazon Route 53 for DNS and wants to log all DNS queries made from its VPC. The logs must be stored in Amazon S3 for compliance purposes. Which solution meets these requirements?

A.Enable Route 53 Resolver query logging and publish to an S3 bucket.
B.Install a CloudWatch Logs agent on each EC2 instance and configure it to send DNS logs to CloudWatch Logs.
C.Enable AWS CloudTrail for DNS API calls and deliver to an S3 bucket.
D.Enable VPC Flow Logs and publish to an S3 bucket.
AnswerA

Route 53 Resolver query logging captures DNS queries from within a VPC and can deliver them directly to an S3 bucket, meeting both the query-visibility and compliance-storage requirements. Resolver logging is the VPC-scoped mechanism; public hosted zone logging would not capture instance queries.

Why this answer

Route 53 Resolver query logging is the native AWS feature designed to capture DNS queries that originate from resources within a VPC. By enabling this feature and specifying an S3 bucket as the destination, you can log all DNS queries made by EC2 instances, Lambda functions, and other VPC resources without needing any additional agents or configuration. This directly meets the requirement for storing DNS query logs in S3 for compliance.

Exam trap

The trap here is confusing data-plane DNS query logs (Route 53 Resolver query logging) with control-plane API logs (CloudTrail) or network flow logs (VPC Flow Logs), leading candidates to select options that log the wrong type of information for the stated requirement.

How to eliminate wrong answers

Option B is wrong because installing a CloudWatch Logs agent on each EC2 instance captures only the DNS queries made by that specific instance's operating system, not all DNS queries from the VPC (e.g., queries from other services or from the Route 53 Resolver itself), and it requires manual agent management. Option C is wrong because AWS CloudTrail logs API calls made to Route 53 (e.g., creating hosted zones), not the DNS query traffic itself; DNS queries are data-plane operations, not control-plane API calls. Option D is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log the content or queries of DNS traffic; they cannot provide the actual DNS query names or types.

59
MCQhard

Refer to the exhibit. An AWS Config rule checks that S3 buckets deny HTTP requests. The bucket 'my-bucket' is reported as non-compliant. Which change would make the bucket compliant?

A.Add a bucket policy that allows only HTTPS requests.
B.Change the Effect to Allow.
C.Add the bucket ARN to the Resource element in the policy.
D.Remove the Condition element from the policy.
AnswerC

The current policy only lists the object ARN (arn:aws:s3:::bucket/*) in the Resource element, so the Deny statement applies to object-level operations like s3:GetObject and s3:PutObject. To also block bucket-level actions such as s3:ListBucket, the Resource must include the bucket ARN itself (arn:aws:s3:::bucket). Adding the bucket ARN (without the trailing /*) ensures both the bucket and its objects are covered by the Deny, satisfying the rule's requirement for bucket-level HTTP denial.

Why this answer

The bucket policy denies actions when 'aws:SecureTransport' is false (HTTP). However, the policy only applies to the bucket's objects (arn:aws:s3:::my-bucket/*), not to the bucket itself. To deny HTTP requests to the bucket as well, the resource should include the bucket ARN (arn:aws:s3:::my-bucket).

The rule likely checks that both bucket and objects are denied.

60
MCQmedium

Refer to the exhibit. A security engineer finds this CloudTrail log entry. What is the most significant security concern indicated by this event?

A.The security group rule allows SSH access from any IP address (0.0.0.0/0).
B.The event is a normal administrative action and poses no security concern.
C.The user did not have MFA enabled when assuming the AdminRole.
D.The source IP address (203.0.113.5) is from an unusual location.
AnswerA

Ingress from 0.0.0.0/0 on port 22 exposes SSH to the entire internet, permitting brute-force and credential-stuffing attempts against every instance in that security group. This unrestricted CIDR is the concrete exposure the log reveals, regardless of other fields present.

Why this answer

The CloudTrail log entry shows an `AuthorizeSecurityGroupIngress` API call that adds a rule allowing SSH (port 22) from 0.0.0.0/0. This is a critical security concern because it exposes the EC2 instance to SSH access from any IP address on the internet, creating a high risk of brute-force attacks, unauthorized access, and potential compromise. Security best practices mandate restricting SSH access to specific trusted IP ranges, not the entire internet.

Exam trap

The trap here is that candidates may focus on the source IP address or MFA status, but the core security concern is the overly permissive security group rule that grants unrestricted SSH access to the internet.

How to eliminate wrong answers

Option B is wrong because the event is not a normal administrative action; it explicitly opens SSH to the world, which is a significant security risk and should be flagged as a concern. Option C is wrong because the CloudTrail log does not indicate whether MFA was enabled or not; the event shows the user assumed the AdminRole, but MFA status is not recorded in this log entry, so it cannot be concluded as a security concern from this event alone. Option D is wrong because the source IP address 203.0.113.5 is a documentation/test IP range (RFC 5737) and is not necessarily unusual; more importantly, the security concern is the open SSH rule, not the source IP of the API call.

61
MCQmedium

A company uses AWS CloudTrail to log management events. The security team wants to be alerted when an IAM user creates a new access key. Which solution would meet this requirement with the least operational overhead?

A.Create a CloudWatch Logs metric filter on the CloudTrail log group for CreateAccessKey events and set an alarm.
B.Create an Amazon EventBridge rule that matches the CreateAccessKey event and triggers an Amazon SNS notification.
C.Write a Python script that uses the CloudTrail LookupEvents API and run it on a scheduled basis using Amazon EventBridge Scheduler.
D.Develop a custom AWS Lambda function that queries CloudTrail logs in S3 every hour.
AnswerB

EventBridge is the least-overhead, near-real-time option because CloudTrail automatically delivers all management events to the default EventBridge bus without extra configuration. A rule with an event pattern that matches eventSource="iam.amazonaws.com" and eventName="CreateAccessKey" triggers an SNS topic immediately when the API call occurs, enabling instantaneous security notifications. This is fully event-driven and serverless: there is no polling, no custom code, no log parsing, and no separate metric filter to maintain, which makes it the architecturally cleanest solution.

Why this answer

Amazon EventBridge can directly capture CloudTrail API calls (like CreateAccessKey) as events and route them to an SNS topic for notification, requiring no custom code or polling. This serverless, event-driven approach minimizes operational overhead by eliminating the need to manage log groups, metric filters, or scheduled scripts.

Exam trap

The trap here is that candidates often assume CloudWatch Logs metric filters are the standard way to monitor CloudTrail events, but EventBridge is the native, lower-overhead service for reacting to specific API calls in real time without needing to ship logs to CloudWatch Logs first.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs management events to CloudTrail itself, not to a CloudWatch Logs log group by default; you would need to explicitly configure CloudTrail to deliver events to CloudWatch Logs, and then create a metric filter and alarm, which adds unnecessary complexity. Option C is wrong because writing a Python script to call the CloudTrail LookupEvents API on a schedule introduces polling overhead, latency, and maintenance burden compared to the real-time, push-based EventBridge approach. Option D is wrong because developing a custom Lambda function to query CloudTrail logs in S3 every hour is overly complex, introduces at least one hour of delay, and requires managing S3 bucket notifications or scheduled invocations, all of which are unnecessary when EventBridge can react instantly.

62
MCQhard

Refer to the exhibit. A security engineer has attached this IAM policy to a user. What is the effect of this policy?

A.Allows uploads with KMS encryption or without encryption.
B.Allows uploads only when encryption is not specified.
C.Denies uploads when encryption is not provided.
D.Allows uploads only when using KMS encryption.
AnswerA

The bucket policy contains two separate allow statements that combine as an OR. One allow statement grants s3:PutObject when the request header s3:x-amz-server-side-encryption is set to aws:kms, covering KMS-encrypted uploads. The second allow statement grants s3:PutObject when the encryption header is absent, covering unencrypted uploads. Because AWS policies evaluate allow statements additively, the effective permission is exactly that uploads with KMS encryption or without encryption are allowed.

Why this answer

The IAM policy uses a `Deny` effect with a `NotPrincipal` condition that denies uploads unless the request includes the `s3:x-amz-server-side-encryption` header with value `aws:kms`. However, the `Condition` block uses `StringNotEquals`, which means any request that does NOT have the encryption header set to `aws:kms` is denied. This effectively allows uploads with KMS encryption (header matches) or without encryption (no header present, because `StringNotEquals` does not match a missing header — the condition evaluates to false, so the Deny does not apply).

Therefore, uploads without encryption are allowed by default (since there is no explicit Allow), and uploads with KMS encryption are also allowed.

Exam trap

The trap here is that candidates assume `StringNotEquals` on a header condition will deny requests that omit the header, but in AWS IAM, missing condition keys cause the condition to evaluate to false, so the Deny does not apply — leaving unencrypted uploads allowed.

How to eliminate wrong answers

Option B is wrong because the policy does not require encryption to be absent; it denies only when encryption is specified but not equal to `aws:kms`, so uploads without any encryption header are allowed. Option C is wrong because the policy does not deny uploads when encryption is not provided; it only denies when encryption is provided but is not KMS (i.e., `AES256`). Option D is wrong because the policy does not require KMS encryption for all uploads; it allows uploads without any encryption header as well.

63
MCQeasy

A security team needs to audit all changes to IAM policies in their AWS account. Which AWS service should be used?

A.AWS Config
B.Amazon CloudWatch
C.IAM Access Analyzer
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the correct service because it records management events for all IAM actions, including CreatePolicy, PutRolePolicy, AttachUserPolicy, and DetachUserPolicy, and includes the identity of the caller, the time of the request, source IP, request parameters, and response elements. Management events are logged by default for every region, and you can create a trail to deliver them to S3 for long-term retention and protection with features such as S3 object lock and CloudWatch Logs integration. This gives the security team a complete, chronological audit trail of every IAM policy change.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in the AWS account, including IAM policy changes such as CreatePolicy, PutRolePolicy, and AttachUserPolicy. These events are captured as CloudTrail log entries, which can be audited to track who made the change, when it was made, and from which source IP. CloudTrail is the primary service for auditing and logging all management events across AWS services.

Exam trap

The trap here is that candidates often confuse AWS Config (which checks compliance of current configurations) with CloudTrail (which records the history of API calls), leading them to select Config for auditing changes instead of CloudTrail.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against desired rules (e.g., checking if an IAM policy is compliant), not for recording the history of changes or API calls. Option B is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms; it does not natively capture IAM policy change events unless CloudTrail logs are streamed to it, but CloudWatch itself is not the audit trail source. Option C is wrong because IAM Access Analyzer is used to identify resources shared with external principals (e.g., analyzing resource-based policies for unintended access), not for auditing the history of policy changes.

64
Multi-Selectmedium

A security team wants to detect and alert on potential security threats such as compromised instances or malicious activity within their AWS environment. Which TWO AWS services should be used together to provide comprehensive threat detection?

Select 2 answers
A.AWS Security Hub
B.AWS CloudTrail
C.Amazon Inspector
D.AWS Config
E.Amazon GuardDuty
AnswersA, E

Security Hub aggregates and prioritises findings from GuardDuty, which performs the actual threat detection for compromised instances and malicious activity. Together they satisfy the requirement for comprehensive detection plus centralised alerting across the AWS environment.

Why this answer

Amazon GuardDuty (E) is correct because it is the AWS managed threat detection service that continuously monitors VPC Flow Logs, DNS logs, and CloudTrail management/event logs using machine learning and threat intelligence feeds to identify compromised instances, reconnaissance, and malicious activity. AWS Security Hub (A) is correct because it aggregates and prioritizes findings from GuardDuty and other services into a single dashboard, enabling centralized alerting and automated response workflows for comprehensive threat visibility. Together, GuardDuty provides the detection engine while Security Hub provides aggregation and alerting.

AWS CloudTrail (B) only records API activity for auditing and does not itself detect or alert on threats. Amazon Inspector (C) is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not runtime threat detection. AWS Config (D) evaluates resource configuration compliance against rules and does not perform threat detection or alerting on malicious behavior.

Exam trap

The trap here is that candidates often confuse logging services (CloudTrail, Config) or vulnerability scanners (Inspector) with active threat detection, but GuardDuty and Security Hub are the only pair that provide continuous, intelligent threat monitoring and centralized alerting.

65
Multi-Selecthard

Which THREE are features of Amazon GuardDuty that help with threat detection? (Select THREE.)

Select 3 answers
A.Analyzes AWS Config configuration history.
B.Analyzes S3 object content for malware.
C.Analyzes VPC Flow Logs.
D.Analyzes DNS query logs.
E.Analyzes AWS CloudTrail management events.
AnswersC, D, E

GuardDuty ingests VPC Flow Logs from enabled VPCs to analyze network traffic metadata, including source and destination IPs, ports, and packet counts. It uses this telemetry to detect malicious activities like port scanning, brute-force attempts, and communication with known command-and-control or cryptocurrency-mining infrastructure. Flow Logs must be enabled for the VPCs you want monitored, and GuardDuty consumes them through an integrated service-linked role.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It ingests and analyzes VPC Flow Logs (option C) to detect suspicious network traffic patterns, such as port scans or data exfiltration attempts. This analysis is a core feature of GuardDuty's threat detection capabilities.

Exam trap

The trap here is that candidates may confuse GuardDuty's core log sources (VPC Flow Logs, DNS logs, CloudTrail) with other AWS security services like AWS Config (for configuration history) or Amazon Macie (for S3 data classification), leading them to select options A or B incorrectly.

66
MCQmedium

A company is using Amazon Route 53 and wants to log DNS queries for investigative purposes. The logs must be stored in a centralized S3 bucket in the security account. What is the MOST efficient way to achieve this?

A.Enable VPC Flow Logs and analyze DNS traffic.
B.Enable CloudWatch Logs for Route 53 and stream to a Lambda function that writes to S3.
C.Configure Route 53 Resolver query logging to deliver to the central S3 bucket.
D.Use a custom Lambda function to poll Route 53 logs and write to S3.
AnswerC

Route 53 Resolver query logging is the native capability that records the full DNS query and response data for queries handled by Route 53 Resolver, including those from VPCs, inbound, and outbound endpoints. It can directly write logs to a central S3 bucket, and using a cross-account bucket policy, you can allow Route 53 in your account to deliver into the consolidated logging bucket. This approach avoids any intermediate compute, scales automatically, and is the most straightforward secure delivery mechanism.

Why this answer

Route 53 Resolver query logging natively supports delivering DNS query logs directly to an S3 bucket, including cross-account S3 buckets, without requiring any intermediate services. This is the most efficient method because it eliminates the need for additional compute resources or manual polling, and it directly satisfies the requirement for centralized logging in the security account.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (which capture network flows) with DNS query logs, or assume that CloudWatch Logs or Lambda are required for S3 delivery, when Route 53 Resolver query logging can directly write to S3 with minimal configuration.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log DNS query details such as domain names or query types. Option B is wrong because Route 53 does not natively send logs to CloudWatch Logs; you would need to configure query logging to CloudWatch Logs first, then use a subscription filter to stream to Lambda, which adds unnecessary complexity and cost compared to direct S3 delivery. Option D is wrong because there is no native 'Route 53 logs' API to poll; Route 53 Resolver query logging can be configured to deliver directly to S3, making a custom polling Lambda redundant and inefficient.

67
MCQhard

A company requires real-time analysis of AWS CloudTrail logs to detect unauthorized API calls. The logs are stored in Amazon S3. Which architecture minimizes latency and cost?

A.Use AWS Glue to crawl S3 and load into Amazon Redshift for analysis
B.Send CloudTrail logs to Amazon CloudWatch Logs, then use a subscription filter to Amazon Kinesis Data Firehose delivering to Amazon OpenSearch Service
C.Query CloudTrail logs directly using Amazon Athena
D.Configure S3 event notifications to invoke an AWS Lambda function that writes to Amazon OpenSearch Service
AnswerB

CloudTrail can be configured to deliver events to Amazon CloudWatch Logs within minutes, and a subscription filter can immediately forward matching events to Amazon Kinesis Data Firehose. Firehose then buffers and delivers a continuous stream to Amazon OpenSearch Service, which indexes documents as they arrive for near-real-time search and visualization with OpenSearch Dashboards/Kibana. This managed pipeline gives the low-latency ingestion and querying the requirement asks for.

Why this answer

It provides the lowest-latency path for real-time analysis: CloudTrail logs are delivered to CloudWatch Logs in near real-time, and a subscription filter streams them to Kinesis Data Firehose, which buffers and delivers directly to Amazon OpenSearch Service for immediate indexing and search. This architecture avoids batch processing, minimizes data movement overhead, and uses managed services that scale automatically, keeping both latency and cost low.

Exam trap

The trap here is that candidates often assume S3 event notifications (Option D) are the fastest path for real-time processing, but they overlook the inherent delivery delay of CloudTrail to S3 (up to 15 minutes) and the risk of Lambda concurrency limits causing dropped events under high log volume.

How to eliminate wrong answers

Option A is wrong because AWS Glue crawling S3 and loading into Amazon Redshift introduces significant batch processing latency (minutes to hours) and incurs high costs for Redshift compute and storage, making it unsuitable for real-time analysis. Option C is wrong because querying CloudTrail logs directly with Amazon Athena requires scanning the entire S3 object set per query, which adds seconds to minutes of latency and incurs per-scan costs that become prohibitive for continuous real-time detection. Option D is wrong because S3 event notifications for CloudTrail logs are typically delivered with a delay (up to 15 minutes) and invoking a Lambda function per object to write to OpenSearch Service creates a tight coupling that can lead to throttling, data loss under high volume, and higher operational overhead compared to the managed streaming pipeline in B.

68
Matchingmedium

Match each AWS security tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Automated vulnerability assessment

Threat detection service

Centralized security findings aggregation

Investigation and analysis of security issues

Resource configuration monitoring and compliance

Why these pairings

Correct matches: AWS Shield protects against DDoS, AWS WAF filters web traffic, and GuardDuty provides threat detection. Common confusions include swapping Shield with WAF and Inspector with Macie.

69
MCQeasy

A company uses AWS CloudTrail to log API activity. The security team wants to ensure that any modification to CloudTrail configuration is logged and that the logs are tamper-proof. Which feature should be enabled?

A.S3 MFA Delete on the CloudTrail S3 bucket
B.S3 Versioning on the CloudTrail S3 bucket
C.CloudTrail Log File Integrity Validation
D.CloudWatch Logs log stream encryption
AnswerC

CloudTrail Log File Integrity Validation is correct because it generates a SHA-256 hash of each log file and signs it with a private key, enabling you to detect any tampering or deletion of log files. You can retrieve the public key from a pre-signed URL to verify both the hash and the digital signature, ensuring the logs have not been altered. This provides strong, cryptographic proof of integrity, which is exactly what the requirement demands.

Why this answer

CloudTrail Log File Integrity Validation (option C) uses a hash chain and digital signatures (SHA-256 hashing with RSA) to verify that log files have not been modified, deleted, or tampered with after delivery to the S3 bucket. This feature creates a digest file that contains the hash of each log file, and the digest files themselves are signed, enabling the security team to detect any unauthorized changes to CloudTrail configuration logs.

Exam trap

The trap here is that candidates often confuse S3 Versioning (which provides object recovery) with cryptographic integrity validation, failing to recognize that only Log File Integrity Validation provides tamper-proof verification through digital signatures and hash chains.

How to eliminate wrong answers

Option A is wrong because S3 MFA Delete requires multi-factor authentication to delete objects or suspend versioning on the bucket, but it does not provide tamper-proof verification of log file integrity after the logs are written. Option B is wrong because S3 Versioning preserves previous versions of objects, which helps recover from accidental deletion or overwrite, but it does not cryptographically verify that log files have not been altered. Option D is wrong because CloudWatch Logs log stream encryption (using AWS KMS) protects data at rest in CloudWatch Logs, but it does not apply to CloudTrail logs stored in S3 and does not provide integrity validation for the log files themselves.

70
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team wants to ensure that all API activity across all accounts is logged and immutable. CloudTrail is enabled in all accounts, but the logs are stored in individual account buckets. The team wants to centralize logs and prevent any account from disabling logging. What should they do?

A.Create a new CloudTrail trail for each account and configure S3 bucket policies to allow cross-account access.
B.Enable S3 MFA Delete on each account's log bucket and require MFA for IAM users.
C.Use CloudWatch Logs to aggregate logs and set a retention policy of 10 years.
D.Apply an SCP to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail, and create an organization trail that delivers logs to a central S3 bucket with a bucket policy that prevents deletion.
AnswerD

Applying an SCP to the organization root or to all member accounts that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail ensures that even an IAM admin or the root user in a member account cannot disable or delete the trail. An organization trail automatically delivers CloudTrail logs from every account to a designated central S3 bucket, and the bucket policy can explicitly Deny actions such as s3:DeleteBucket, s3:DeleteBucketPolicy, and s3:DeleteObject for all principals, making the log data tamper-proof. This combination provides a centralized, immutable audit record while removing the ability of individual account administrators to interfere with logging. It directly satisfies the requirement to prevent disabling and to protect the integrity of the logs.

Why this answer

It uses an SCP to prevent disabling CloudTrail (denying cloudtrail:StopLogging and cloudtrail:DeleteTrail) and creates an organization trail that delivers logs to a central S3 bucket. The central bucket policy prevents deletion of logs, ensuring immutability and centralized logging across all accounts in the AWS Organization.

Exam trap

The trap here is that candidates often confuse S3 MFA Delete or cross-account bucket policies as sufficient for immutability and centralization, but they fail to address the core requirement of preventing accounts from disabling CloudTrail itself, which requires an SCP or organization trail.

How to eliminate wrong answers

Option A is wrong because creating separate trails per account does not centralize logs into a single location, and cross-account S3 bucket policies alone do not prevent individual accounts from disabling their own CloudTrail. Option B is wrong because enabling S3 MFA Delete on each account's log bucket only protects against accidental deletion of objects, but does not prevent an account from stopping or deleting the CloudTrail trail itself, nor does it centralize logs. Option C is wrong because CloudWatch Logs aggregation does not provide immutability; logs can be deleted or altered in CloudWatch Logs, and a retention policy of 10 years does not prevent deletion of the log group or stream.

71
MCQhard

A company is using Amazon GuardDuty to detect threats in its AWS environment. The security team notices that GuardDuty is generating a high number of 'UnauthorizedAccess:IAMUser/MaliciousIPCaller' findings for an IAM user that is used by a legacy application. The security team has verified that the IP addresses flagged are not malicious but are legitimate IPs used by the application's third-party service. The company wants to suppress these findings without disabling GuardDuty entirely. Which solution is the MOST effective and secure?

A.Disable the specific finding type in GuardDuty settings.
B.Create a GuardDuty suppression rule that automatically archives findings for that IAM user.
C.Create a VPC flow log filter to exclude traffic from those IP addresses.
D.Modify the IAM user's permissions to restrict the IP addresses it can use.
AnswerB

A suppression rule filters findings matching specified criteria, such as the IAM user's principal ID, and automatically archives them so the security team stops receiving alerts. This satisfies the requirement to suppress the false-positive findings while keeping GuardDuty fully enabled and monitoring all other activity.

Why this answer

GuardDuty suppression rules allow you to automatically archive findings that match specific criteria (such as a particular finding type and IAM user) without disabling the detector or the finding type entirely. This is the most effective and secure way to reduce noise from known-legitimate activity while preserving GuardDuty's ability to detect other threats.

Exam trap

The trap is choosing to disable the finding type or alter IAM permissions instead of using suppression rules — the exam tests whether you know suppression rules archive findings without losing detection capability.

How to eliminate wrong answers

Option A is wrong because disabling the specific finding type in GuardDuty settings would stop detection of that threat across the entire account, potentially missing real malicious IP caller findings for other users. Option C is wrong because VPC flow log filters do not affect GuardDuty findings — GuardDuty analyzes CloudTrail, VPC Flow Logs, and DNS logs independently, and filtering flow logs does not suppress findings. Option D is wrong because modifying IAM permissions to restrict IP addresses does not suppress GuardDuty findings and may break the legacy application; it also doesn't address the root cause of noise.

72
MCQeasy

A security engineer needs to monitor AWS account activity for suspicious API calls and receive alerts. Which AWS service should the engineer use to meet this requirement?

A.VPC Flow Logs
B.AWS Config with AWS Config Rules
C.AWS CloudTrail with CloudWatch Alarms
D.Amazon GuardDuty
AnswerC

AWS CloudTrail is the authoritative service for recording API activity: it captures every management and data event with details such as the event name, IAM user or role that made the call, source IP address, request parameters, and response elements. When you send those CloudTrail events to CloudWatch Logs via a trail, you can define a metric filter on a specific pattern — such as eventName for a sensitive action or an errorCode indicating failed access — and attach a CloudWatch Alarm to trigger an SNS notification. That pipeline gives a deterministic, near-real-time alert for account activity, which is exactly what the security engineer needs.

Why this answer

AWS CloudTrail records all API calls made to the AWS environment, providing a detailed audit trail of account activity. By sending these logs to Amazon CloudWatch, you can create metric filters that match suspicious API call patterns and trigger CloudWatch Alarms to send notifications via SNS. This combination directly meets the requirement to monitor and alert on specific API calls.

Exam trap

The trap here is that candidates confuse GuardDuty's threat detection with the ability to monitor and alert on specific API calls, but GuardDuty does not provide customizable metric filters or alarms for arbitrary API patterns; CloudTrail with CloudWatch Alarms is the correct service for that precise requirement.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) at the network interface level, not API-level activity; they cannot monitor or alert on specific AWS API calls. Option B is wrong because AWS Config with Config Rules evaluates resource configuration compliance against desired states (e.g., checking if S3 buckets are public), not API call activity; it does not record or alert on individual API operations. Option D is wrong because Amazon GuardDuty uses threat intelligence and machine learning to detect anomalous behavior and potential threats (e.g., compromised credentials, crypto-mining), but it does not provide a direct, customizable alerting mechanism for specific API calls; it focuses on broader threat detection rather than monitoring defined API call patterns.

73
MCQhard

Refer to the exhibit. After invoking the Lambda function, why are there no log streams in the log group?

A.The CloudWatch Logs log group retention policy is set to 0 days.
B.The Lambda function is not configured with a CloudWatch Logs log group.
C.The Lambda function timed out before writing logs.
D.The Lambda function's execution role lacks permissions to write to CloudWatch Logs.
AnswerD

To stream logs, Lambda's execution role must have IAM permissions for logs:CreateLogStream and logs:PutLogEvents on the target log group. Even when the log group exists, a restrictive or missing execution role policy prevents the log stream from being created, so no logs appear. Because no log streams exist despite the log group being present, the most plausible root cause is that the role lacks the necessary CloudWatch Logs permissions.

Why this answer

Lambda writes logs to CloudWatch Logs using the permissions granted to its execution role. If that role lacks the required actions (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents), the function still executes but the log writes are silently denied, so no log streams appear in the log group. This is the classic cause of an empty log group after a successful invocation.

Exam trap

SCS-C02 often tests the misconception that Lambda needs a pre-created log group or that timeouts/retention settings suppress log delivery, when the real culprit in an empty log group is almost always missing CloudWatch Logs permissions on the execution role.

How to eliminate wrong answers

Option A is wrong because a retention policy of 0 days is not a valid CloudWatch Logs setting — retention values are 1 day, 3, 5, 7, 14, 30, 60, 90, 120, 150, 180, 365, 400, 545, 731, 1096, 1827, 2192, 2557, 2922, 3288, 3653, or 'Never expire'; retention only deletes old events, it never prevents new log streams from being created. Option B is wrong because Lambda does not require you to pre-configure a log group — if the execution role has the proper permissions, Lambda automatically creates the /aws/lambda/<function-name> log group on first invocation. Option C is wrong because a timeout does not suppress log delivery; Lambda flushes buffered logs even when a function times out, and a timeout would still produce a log stream with a START, END, and Report line.

74
MCQeasy

A security team wants to receive real-time notifications when an IAM user makes a change to a security group. Which AWS service should be used to trigger the notification?

A.AWS Config
B.AWS CloudTrail with Amazon CloudWatch Events
C.Amazon S3 event notifications
D.Amazon GuardDuty
AnswerB

AWS CloudTrail captures all supported API calls as events, and CloudWatch Events (or EventBridge) can filter those events by service, action, and other fields using event patterns. Once matched, a rule can immediately invoke a Lambda function, SNS topic, or SQS queue to deliver the notification. This combination provides near-real-time alerting on specific API calls, which is exactly what the security team needs.

Why this answer

AWS CloudTrail captures API calls made by IAM users, including changes to security groups (e.g., AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress). By sending these CloudTrail events to Amazon CloudWatch Events (now part of Amazon EventBridge), you can create a rule that matches specific API calls and triggers a notification via SNS, Lambda, or other targets in real time.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation (which can detect drift but not real-time API calls) with CloudTrail's event-driven notification capability, or they mistakenly think S3 event notifications can be applied to EC2 resources.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it does not provide real-time event-driven notifications for API calls; it operates on a periodic or configuration-change detection basis, not on the exact moment an IAM user makes a change. Option C is wrong because Amazon S3 event notifications are designed for object-level events in S3 buckets (e.g., PUT, POST, DELETE), not for IAM user actions on security groups in EC2. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (e.g., VPC Flow Logs, DNS logs) for malicious activity, but it does not trigger notifications for routine IAM user changes to security groups.

75
MCQhard

A security engineer is using Amazon GuardDuty in a multi-account environment managed by AWS Organizations. The engineer wants to ensure that GuardDuty findings from all member accounts are centrally visible and that new accounts are automatically enrolled. What should the engineer do?

A.Create an Amazon EventBridge rule in each account that forwards GuardDuty findings to a central event bus.
B.Enable GuardDuty in each member account and configure each account to publish findings to a central SNS topic.
C.Designate a delegated administrator for GuardDuty in the organization and enable GuardDuty for all accounts.
D.Use AWS Security Hub to aggregate GuardDuty findings from all accounts.
AnswerC

Designating a delegated administrator allows a member account to manage GuardDuty for the entire organization. The administrator can enable GuardDuty for all existing and new accounts automatically. Findings from all accounts are aggregated in the delegated administrator account, providing central visibility. This is the recommended approach for multi-account GuardDuty management.

Why this answer

Designating a delegated administrator for GuardDuty in AWS Organizations allows centralized management, automatic enrollment of new accounts, and aggregation of findings. This is the most efficient and recommended method for multi-account GuardDuty deployment. Other options require manual configuration and do not provide automatic enrollment or central visibility.

Exam trap

The trap here is assuming that Security Hub or EventBridge can manage GuardDuty enrollment, when only the delegated administrator feature provides automatic enablement and central management.

Page 1 of 4 · 250 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Logging questions.