Courseiva

CCNA Security Logging Questions

75 of 250 questions · Page 2/4 · Security Logging topic · Answers revealed

76
MCQhard

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer wants to ensure that all member accounts send findings to the delegated administrator account. However, some member accounts are not sending findings. What is the most likely cause?

A.The GuardDuty service-linked role is missing in the member accounts.
B.AWS CloudTrail is not enabled in the member accounts.
C.GuardDuty is not enabled in the member accounts, or they have not accepted the invitation.
D.VPC Flow Logs are not enabled in the member accounts.
AnswerC

In a GuardDuty multi-account setup, the administrator account sends invitations to member accounts. Each member account must explicitly enable GuardDuty and accept the invitation before it can begin sending findings to the administrator. If a member account has not enabled GuardDuty or has not accepted the invitation, no findings are received from that account. This is the most common reason for missing findings in the administrator console.

Why this answer

GuardDuty requires that each member account has the service explicitly enabled and has accepted the invitation from the delegated administrator account. Without these steps, the member accounts cannot send findings to the administrator, even if AWS Organizations is configured correctly. The delegated administrator can only manage findings from accounts that have completed the onboarding process.

Exam trap

The trap here is that candidates often assume that enabling GuardDuty via AWS Organizations automatically activates it in all member accounts and forwards findings, but in reality, each member account must either accept the invitation or be explicitly enabled by the delegated administrator using the appropriate API call.

How to eliminate wrong answers

Option A is wrong because the GuardDuty service-linked role (AWSServiceRoleForAmazonGuardDuty) is automatically created when GuardDuty is enabled in an account; its absence is a symptom of GuardDuty not being enabled, not a separate cause. Option B is wrong because AWS CloudTrail is a data source for GuardDuty but is not required for findings to be sent; GuardDuty can still generate findings from VPC Flow Logs and DNS logs even if CloudTrail is disabled. Option D is wrong because VPC Flow Logs are another optional data source; GuardDuty can still send findings based on other threat detection feeds without VPC Flow Logs being enabled.

77
MCQmedium

A security engineer is reviewing AWS CloudTrail logs and finds that an IAM user 'developer1' deleted an S3 bucket. The engineer needs to determine the source IP address of the delete operation. Which field in the CloudTrail log record contains this information?

A.userIdentity
B.requestParameters
C.eventTime
D.sourceIPAddress
AnswerD

sourceIPAddress is the dedicated top-level field in CloudTrail log events that holds the IP address from which the API call was made. This is the exact field a security engineer should examine to identify the origin of a request, whether it comes from a user's public IP, a NAT gateway address, or an AWS service's internal IP. For console-session actions, CloudTrail populates this field with the IP of the user's browser, making it the authoritative source for network origin in log review.

Why this answer

The `sourceIPAddress` field in a CloudTrail log record captures the IP address from which the API call was made. For S3 bucket deletion via the AWS Management Console, AWS CLI, or SDK, this field records the originating IP address, enabling the security engineer to trace the delete operation back to its source.

Exam trap

The trap here is that candidates may confuse `sourceIPAddress` with `userIdentity` or `requestParameters`, mistakenly thinking the IP address is embedded in the user details or request payload, when in fact it is a separate top-level field in the CloudTrail log record.

How to eliminate wrong answers

Option A is wrong because `userIdentity` contains details about the IAM user or role that made the request (e.g., ARN, type, access key ID), not the network source IP. Option B is wrong because `requestParameters` includes the bucket name and other parameters sent in the API call (e.g., `bucketName`), but not the IP address. Option C is wrong because `eventTime` records the timestamp of the API call (in UTC), which is useful for chronology but does not contain IP address information.

78
MCQmedium

A security engineer needs to monitor for unusual outbound network traffic from an EC2 instance. Which AWS service provides this capability?

A.Amazon CloudWatch Logs agent
B.VPC Flow Logs
C.Amazon Inspector
D.AWS Config
AnswerB

VPC Flow Logs are the native AWS feature that captures IP traffic information for network interfaces in a VPC, recording metadata such as source and destination IP addresses, source and destination ports, protocol, and whether the traffic was accepted or rejected. These logs can be published to Amazon CloudWatch Logs or Amazon S3, where they can be analyzed with CloudWatch Logs Insights, Athena, or third-party tools to detect anomalous outbound connections like data exfiltration or beaconing. Because they capture all network flows at the ENI level, they are the appropriate service for monitoring unusual outbound traffic.

Why this answer

VPC Flow Logs capture metadata about IP traffic going to and from network interfaces in a VPC, including source/destination IPs, ports, protocols, and packet counts. This allows a security engineer to analyze outbound traffic patterns from an EC2 instance and detect anomalies such as data exfiltration or communication with known malicious IPs. The logs can be published to Amazon CloudWatch Logs or Amazon S3 for further analysis with tools like Amazon Athena or third-party SIEMs.

Exam trap

The trap here is that candidates confuse the CloudWatch Logs agent (which sends application logs) with VPC Flow Logs (which capture network traffic metadata), leading them to select Option A because they think 'monitoring logs' implies network visibility.

How to eliminate wrong answers

Option A is wrong because the Amazon CloudWatch Logs agent is a software component installed on an EC2 instance to send application and OS logs (e.g., syslog, Apache logs) to CloudWatch Logs; it does not capture network traffic metadata or provide visibility into outbound network flows. Option C is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances for software vulnerabilities and unintended network exposure; it does not monitor real-time outbound network traffic or provide flow-level logs. Option D is wrong because AWS Config is a service for recording and evaluating configuration changes of AWS resources against desired policies; it does not capture or analyze network traffic data.

79
MCQhard

A security engineer needs to ensure that all objects uploaded to an S3 bucket are automatically scanned for malware before being made accessible to users. Which solution is MOST appropriate?

A.Enable VPC Flow Logs to capture all access to the bucket.
B.Enable S3 Object Lock on the bucket.
C.Configure Amazon CloudWatch Logs to monitor S3 access logs.
D.Use S3 event notifications to invoke an AWS Lambda function that runs a malware scanning solution.
AnswerD

S3 event notifications can be configured to publish PUT or POST events to AWS Lambda, triggering a function each time an object is uploaded. The Lambda function can then use GetObject to retrieve the object and run a malware scanning engine such as ClamAV, applying tags or deleting/quarantining the object based on the scan verdict. This serverless, event-driven pattern provides immediate, per-object inspection and scales automatically with upload volume.

Why this answer

S3 event notifications can be configured to trigger an AWS Lambda function upon object creation, allowing the Lambda function to run a malware scanning solution (e.g., using ClamAV or an AWS Marketplace partner) before the object is made accessible. This serverless approach ensures automated, near-real-time scanning without manual intervention, and the Lambda function can quarantine or delete malicious objects by adjusting S3 bucket policies or object ACLs.

Exam trap

The trap here is that candidates may confuse logging/monitoring services (VPC Flow Logs, CloudWatch Logs) with active security controls, failing to recognize that malware scanning requires compute-based content inspection, not just metadata or access logging.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IPs, ports, protocols) for network interfaces, not object-level operations or content within S3 buckets; they cannot scan objects for malware. Option B is wrong because S3 Object Lock prevents objects from being deleted or overwritten for a specified retention period, but it does not inspect or scan object content for malware. Option C is wrong because CloudWatch Logs can monitor S3 access logs (e.g., via AWS CloudTrail or server access logs) for auditing, but they cannot perform malware scanning on the uploaded objects themselves.

80
MCQmedium

A company uses AWS Organizations and wants to enable Amazon GuardDuty across all member accounts. The security team wants to centrally manage findings and automate responses. What is the MOST efficient way to achieve this?

A.Designate a Delegated Administrator account for GuardDuty in AWS Organizations and enable GuardDuty for all accounts from that account.
B.Use AWS CloudFormation StackSets to deploy a GuardDuty detector in each account.
C.Enable AWS Security Hub in the management account and configure it to ingest GuardDuty findings from member accounts.
D.Enable GuardDuty in each member account individually and configure cross-account access to a central S3 bucket.
AnswerA

By designating a delegated administrator for GuardDuty in AWS Organizations, you centralize management and allow GuardDuty to automatically enable itself for all existing and future accounts. This creates a single detector per region in the delegated admin account with all member accounts linked underneath, so findings are aggregated without manual per-account setup. This is the native, supported pattern for scaling GuardDuty across an organization.

Why this answer

AWS Organizations allows you to designate a Delegated Administrator account for GuardDuty, which can then enable GuardDuty and manage findings centrally across all member accounts without manual per-account setup. This approach is the most efficient as it leverages the Organizations integration to automatically enable GuardDuty in new accounts and centralize finding management, reducing operational overhead.

Exam trap

The trap here is that candidates often confuse Security Hub's ability to aggregate findings with the actual enablement of GuardDuty, leading them to choose Option C, which only addresses aggregation, not the initial enablement requirement.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation StackSets can deploy resources across accounts, but GuardDuty requires a detector to be enabled per account, and StackSets do not natively handle the centralized management of findings or automated responses as efficiently as the Delegated Administrator model. Option C is wrong because AWS Security Hub can ingest GuardDuty findings, but it does not enable GuardDuty itself; it only aggregates findings from already-enabled detectors, so it does not address the initial enablement requirement. Option D is wrong because enabling GuardDuty individually in each account and configuring cross-account access to an S3 bucket is manual, inefficient, and does not provide centralized management or automated response capabilities; it also introduces additional complexity with S3 bucket policies and cross-account roles.

81
MCQeasy

A security engineer needs to monitor for unauthorized changes to security group rules in an AWS account. Which AWS service can evaluate security group rules against a desired configuration and alert on changes?

A.AWS Security Hub
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerB

AWS Config is the correct choice because it continuously records configuration changes to your security groups, including additions or deletions of ingress and egress rules. By using managed or custom Config rules, you can define a desired security group configuration (for example, disallowing SSH access from 0.0.0.0/0) and AWS Config will evaluate each change against that baseline, generating compliance alerts and invoking remediation via EventBridge or Lambda when a noncompliant change occurs.

Why this answer

AWS Config is correct because it provides a managed rule called 'restricted-ssh' or custom rules using AWS Config managed rules or Lambda functions to evaluate security group rules against a desired configuration. When a security group rule is added, removed, or modified, AWS Config detects the configuration change, evaluates it against the defined rules, and can trigger an Amazon SNS notification to alert the security engineer. This makes AWS Config the appropriate service for continuous monitoring and alerting on unauthorized changes to security group rules.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with AWS Config (which evaluates the resulting configuration state), leading them to choose CloudTrail because they think logging API calls is sufficient for monitoring unauthorized changes, but CloudTrail does not evaluate the configuration against a desired state or provide alerting on noncompliant rules.

How to eliminate wrong answers

Option A is wrong because AWS Security Hub aggregates security findings from multiple services (like AWS Config, GuardDuty, and Inspector) and provides a comprehensive security posture view, but it does not directly evaluate security group rules against a desired configuration or generate alerts for unauthorized changes on its own. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, not for monitoring configuration changes to security group rules. Option D is wrong because AWS CloudTrail records API calls (including those that modify security groups) for auditing and forensic analysis, but it does not evaluate the resulting configuration against a desired state or provide alerting on unauthorized changes—it only logs the actions taken.

82
MCQmedium

A company has multiple AWS accounts and wants to centrally aggregate VPC Flow Logs from all accounts into a single S3 bucket in the logging account. What is the MOST secure way to configure cross-account delivery?

A.Use AWS CloudTrail to log flow logs and deliver to the central bucket.
B.Create VPC Flow Logs in each account, specifying the central S3 bucket ARN as the destination, and configure the bucket policy to allow the flow logs service principal to write.
C.Share the central bucket's access key with each account to write directly.
D.Use Amazon Kinesis Data Firehose to stream flow logs from each account to the central S3 bucket.
AnswerB

For each member account, you enable VPC Flow Logs and set the destination to the central S3 bucket's ARN (e.g., arn:aws:s3:::central-bucket/flowlogs). The central account must attach a bucket policy that grants s3:PutObject to the VPC Flow Logs service principal, typically vpc-flow-logs.amazonaws.com, with a resource condition that limits writes to the source account's AWSLogs prefix. Once configured, flow records are published directly and continuously from each account to the central bucket without any additional credentials or infrastructure, making this the native and correct cross-account delivery mechanism.

Why this answer

VPC Flow Logs can be published directly to an S3 bucket in another account by specifying the bucket ARN as the destination. The logging account's bucket policy must grant the `s3:PutObject` permission to the VPC Flow Logs service principal (`delivery.logs.amazonaws.com`) for the cross-account write to succeed. This approach avoids sharing credentials or introducing additional services, maintaining a secure and direct delivery path.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing a streaming service like Kinesis Firehose or misapply CloudTrail, not realizing that VPC Flow Logs have a native cross-account S3 delivery capability that is both secure and simple.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail logs API activity, not VPC Flow Logs; CloudTrail cannot capture or deliver network traffic logs. Option C is wrong because sharing an S3 bucket's access key (long-term credentials) violates the principle of least privilege and introduces a significant security risk of credential exposure or misuse. Option D is wrong because Amazon Kinesis Data Firehose is an unnecessary intermediary that adds complexity and cost; VPC Flow Logs can natively deliver to a cross-account S3 bucket without requiring Firehose.

83
MCQhard

A company has a multi-account AWS environment with 50 accounts. The security team uses AWS CloudTrail to log management events in each account and delivers logs to a centralized S3 bucket in the security account. Recently, the team noticed that some CloudTrail logs are missing from the central bucket for a few accounts. The logs appear to be delivered intermittently. The security engineer checks the CloudTrail configuration in one of the affected accounts and sees that the trail is configured to deliver to the central bucket. The bucket policy in the security account allows CloudTrail to write from all accounts. The engineer also checks the CloudTrail console and sees that the trail status is 'Logging'. What is the MOST likely cause of the intermittent log delivery?

A.The S3 bucket has default encryption enabled, which interferes with CloudTrail writes.
B.The S3 bucket has a Lifecycle policy that deletes objects prematurely.
C.The CloudTrail trail is using Kinesis Data Firehose for delivery, which has a throughput limit.
D.The CloudTrail trail in each account is not associated with an SQS queue, causing delivery failures.
AnswerC

When a CloudTrail trail is configured to deliver to Kinesis Data Firehose, the logs are sent to a delivered stream that has a default throughput limit of 5,000 records per second and 5 MB per second. If the trail produces records faster than the stream can accept, Firehose throttles the producer, and CloudTrail can drop logs or mark delivery as failed for that interval. This perfectly explains intermittent missing logs, unlike the other options that would cause all-or-nothing or delayed effects.

Why this answer

The most likely cause is that the CloudTrail trail is configured to deliver logs via Kinesis Data Firehose, which has a throughput limit. If the volume of log data exceeds the Firehose stream's capacity, some logs may fail to be delivered, resulting in intermittent missing logs. Option A is incorrect because S3 default encryption (SSE-S3) does not interfere with CloudTrail writes; CloudTrail can write to encrypted buckets.

Option B is incorrect because a lifecycle policy deletes objects after they are stored, not during delivery, so it would not cause intermittent missing logs. Option D is incorrect because CloudTrail does not use SQS for log delivery; it delivers directly to S3 or via Firehose.

84
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team has enabled AWS CloudTrail with an organization trail that delivers logs to a centralized S3 bucket in the management account. They have also enabled Amazon GuardDuty in all accounts. Recently, they noticed that some EC2 instances in a member account are exhibiting unusual network behavior, such as outbound traffic to known malicious IP addresses. The security engineer needs to quickly determine the source of the traffic and identify which EC2 instances are affected. The engineer has access to the management account and the member account. Which course of action should the engineer take to most efficiently investigate this incident?

A.Use AWS Config to review the configuration changes of the EC2 instances and identify any anomalies.
B.Use Amazon Detective to investigate the GuardDuty findings and analyze VPC Flow Logs to identify the affected instances.
C.Use Amazon Inspector to scan the EC2 instances for vulnerabilities and correlate with network traffic.
D.Query the VPC Flow Logs stored in the centralized S3 bucket using Amazon Athena to find the source IP and affected instances.
AnswerB

Amazon Detective is purpose-built for security investigations and natively integrates with GuardDuty findings. It automatically aggregates and correlates data from VPC Flow Logs, CloudTrail, and other sources, presenting a visual graph of resources, IP addresses, and behaviors. By launching an investigation from a GuardDuty finding, you can quickly scope the affected EC2 instances and analyze the associated flow log data without manual querying. This gives the most efficient and complete investigation pathway.

Why this answer

Amazon Detective is purpose-built to investigate and analyze GuardDuty findings, automatically ingesting VPC Flow Logs, CloudTrail, and GuardDuty data to build a behavior graph that pinpoints affected EC2 instances and traffic sources. It correlates the malicious-IP finding with the specific instance and network path in a few clicks, which is exactly the 'quickly determine source and affected instances' requirement. This is the most efficient investigative path because Detective already has the data pre-processed and linked to the finding.

Exam trap

SCS-C02 often tests whether candidates confuse vulnerability scanning (Inspector), configuration tracking (Config), and manual log querying (Athena) with the purpose-built threat investigation service (Detective) that automatically correlates GuardDuty findings with network and API activity.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and compliance, not network traffic or threat findings, so it cannot identify which instances are communicating with malicious IPs. Option C is wrong because Amazon Inspector performs vulnerability scanning of instances and does not analyze outbound network traffic or correlate with GuardDuty threat findings. Option D is wrong because querying VPC Flow Logs in S3 via Athena is a manual, slower approach that requires writing SQL, locating the right log partitions, and manually correlating IPs to instances — it lacks the automated finding-to-resource linkage that Detective provides.

85
MCQeasy

A company is required to audit all changes to IAM policies. Which AWS service should be used to record these changes?

A.AWS Config
B.Amazon CloudWatch Logs
C.Amazon S3
D.AWS CloudTrail
E.IAM Access Analyzer
AnswerD

AWS CloudTrail is the correct service because it captures management events as API activity, including all IAM policy changes such as PutRolePolicy, AttachUserPolicy, and CreatePolicyVersion. Each CloudTrail event records the requesting IAM principal, source IP address, event time, and request parameters, providing a complete, tamper-evident audit trail. You can query these events via the CloudTrail console, the LookupEvents API, or deliver them to S3 or CloudWatch Logs for long-term retention and automated alerting.

Why this answer

AWS CloudTrail is the correct service because it records API activity in your AWS account, including all IAM policy changes made via the AWS Management Console, SDKs, CLI, or AWS services. Each event is captured as a CloudTrail event with details such as the identity making the request, the time of the request, and the request parameters, enabling a complete audit trail of IAM policy modifications.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to track configuration changes with CloudTrail's ability to record API-level audit trails, but Config only shows the state of resources over time without the identity and context of who made the change.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration management service that evaluates resource configurations against desired policies and records configuration changes, but it does not capture the API-level audit trail of who made the change and when. Option B is wrong because Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from various sources, but it does not natively record IAM policy changes unless CloudTrail logs are sent to it. Option C is wrong because Amazon S3 is an object storage service that can store CloudTrail log files, but it does not itself record or generate audit logs of IAM policy changes.

Option E is wrong because IAM Access Analyzer helps identify resources shared with external entities by analyzing resource-based policies, but it does not record a history of policy changes.

86
MCQhard

A security engineer is configuring Amazon Inspector to assess EC2 instances for software vulnerabilities. The engineer has installed the SSM Agent on all instances and ensured that the instances have internet access. However, Amazon Inspector shows the instances as 'Unmanaged'. What is the MOST likely cause?

A.The IAM role attached to the EC2 instance does not have permissions to publish metrics to CloudWatch.
B.The security group attached to the instance blocks outbound traffic to the Amazon Inspector service.
C.The instance does not have the EC2 instance metadata service enabled.
D.The SSM Agent is not running or is not registered with AWS Systems Manager.
AnswerD

Amazon Inspector is integrated with AWS Systems Manager Agent, which is responsible for collecting inventory and system configuration data from EC2 instances for assessment. For an instance to appear as 'Managed,' the SSM Agent must be running and registered with the Systems Manager service. If the agent is not running or not registered, Inspector cannot obtain the necessary telemetry and therefore reports the instance as 'Unmanaged.' This is the correct condition that explains the issue.

Why this answer

Amazon Inspector requires EC2 instances to be managed by AWS Systems Manager (SSM) to install the SSM Agent and register it with the Systems Manager service. If the SSM Agent is not running or not registered, the instance cannot communicate with Systems Manager, and Inspector will report it as 'Unmanaged'. Even with internet access and the agent installed, the agent must be actively running and registered for the instance to be properly managed.

Exam trap

The trap here is that candidates may assume internet access alone is sufficient for Inspector to work, overlooking the critical requirement that the SSM Agent must be actively running and registered with Systems Manager for the instance to be considered managed.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector does not require CloudWatch metrics publishing; it relies on Systems Manager for agent communication and assessment data. Option B is wrong because while outbound traffic to the Inspector service endpoints is necessary, the primary cause of 'Unmanaged' status is the SSM Agent registration failure, not security group rules blocking Inspector traffic specifically. Option C is wrong because the EC2 instance metadata service is used for instance identity and credentials, but its absence does not directly cause an 'Unmanaged' status in Inspector; the SSM Agent registration is the critical factor.

87
MCQmedium

A security engineer is investigating a potential data exfiltration incident. The engineer needs to determine whether an IAM user in account A accessed an S3 bucket in account B. The engineer has access to both accounts. Which combination of steps should the engineer take to identify the cross-account access?

A.Enable S3 server access logging on the bucket in account B and check the logs.
B.Enable CloudTrail in account B and check the S3 event history for the bucket.
C.Enable CloudTrail in account A and check the S3 event history.
D.Enable CloudWatch Logs in account A and check the S3 access logs.
AnswerB

CloudTrail in account B, the bucket owner account, is the authoritative audit trail for S3 API calls made against the bucket. When you enable CloudTrail with S3 data events for the bucket, every cross-account request from account A generates an event that includes the full userIdentity ARN of the calling IAM user or role. The event record also contains the source IP address, the event name (e.g., GetObject), and the bucket ARN, allowing you to trace exactly which IAM identity performed the suspected exfiltration. This is the only option that gives you the complete identity-level detail required for the investigation.

Why this answer

To identify cross-account access to an S3 bucket, enable CloudTrail in the account that owns the bucket (account B) and configure a trail with data events for S3 object-level operations. This captures the IAM user ARN from account A in the CloudTrail event. S3 server access logging (Option A) can also provide similar details, but CloudTrail is the recommended approach for auditing API calls.

Ensure data events are enabled for the bucket.

Exam trap

Candidates often think enabling CloudTrail in the source account (account A) will capture cross-account S3 access, but CloudTrail logs are per-account and per-region, so the data event must be logged in the account that owns the resource (account B). Additionally, remember to enable S3 data events in CloudTrail; otherwise, object-level operations will not be logged.

How to eliminate wrong answers

Option A is wrong because enabling S3 server access logging on the bucket in account B would capture the access, but it requires configuring a target bucket and waiting for logs to be delivered, which is not the immediate step described; the question asks for a combination of steps, and CloudTrail is the more direct and commonly used method for cross-account access identification. Option C is wrong because CloudTrail in account A logs API calls made by users in account A, but it does not capture the S3 data plane events on the bucket in account B; those events are logged in account B's CloudTrail. Option D is wrong because CloudWatch Logs in account A does not natively capture S3 access logs; S3 access logs are delivered to a target S3 bucket, not directly to CloudWatch Logs, and even if they were, they would be in account B's logs, not account A's.

88
MCQmedium

A security engineer is investigating a potential security incident involving an EC2 instance. The engineer needs to capture network traffic to and from the instance for analysis. Which method should be used to capture this traffic without installing any software on the instance?

A.Enable VPC Flow Logs for the subnet.
B.Configure AWS Network Firewall in the VPC.
C.Install the Amazon CloudWatch agent on the instance.
D.Use VPC Traffic Mirroring.
AnswerD

VPC Traffic Mirroring copies live traffic from Elastic Network Interfaces and forwards it to a chosen monitoring appliance or security tool, such as a customer-managed NGFW or packet analyzer, using VXLAN-encapsulated tunnels. It captures full packet content, including headers and payload, without requiring any software installation on the source instance and without impacting the production traffic path. This makes it the correct choice for deep packet inspection and forensic analysis of network traffic.

Why this answer

VPC Traffic Mirroring captures and inspects network traffic at the Elastic Network Interface (ENI) level without requiring any software installation on the EC2 instance. It copies traffic from a source ENI to a target, such as a Network Load Balancer or another ENI, for analysis by security appliances. This meets the requirement of capturing traffic without installing software on the instance.

Exam trap

The trap here is confusing VPC Flow Logs (metadata only) with full packet capture; candidates often pick VPC Flow Logs because they are a familiar logging feature, but they lack the payload data needed for deep packet analysis.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture metadata (source/destination IP, ports, protocol, packet count) but not the actual packet payload, so they cannot provide full network traffic for analysis. Option B is wrong because AWS Network Firewall inspects traffic passing through the firewall but does not capture or mirror traffic to/from a specific EC2 instance for out-of-band analysis. Option C is wrong because the Amazon CloudWatch agent collects OS-level metrics and logs, not network packet captures, and installing it would violate the 'without installing any software' constraint.

89
MCQmedium

A company has enabled AWS Config to record resource changes. The security team needs to be notified when a security group is modified to allow inbound SSH from 0.0.0.0/0. Which AWS service should be used to evaluate the Config rules and trigger notifications?

A.AWS Lambda
B.AWS Security Hub
C.Amazon GuardDuty
D.AWS CloudTrail
E.AWS Config with a custom rule that triggers an SNS notification
AnswerE

AWS Config records resource configuration changes and can evaluate those changes against rules that define desired configurations. A custom rule implemented as a Lambda function returns a compliance status based on a configuration item, and AWS Config can publish the result to an SNS topic when a resource becomes noncompliant. This combination enables real-time notification and corrective workflow each time a configuration change occurs, which is exactly what the requirement needs.

Why this answer

AWS Config with a custom rule is the correct choice because it allows you to define a custom Lambda-backed rule that evaluates security group configurations against the condition of allowing inbound SSH (port 22) from 0.0.0.0/0. When the rule detects non-compliance, it can directly trigger an Amazon SNS notification to alert the security team. This is the native AWS Config mechanism for custom evaluations and notifications, without requiring additional services.

Exam trap

The trap here is that candidates often confuse AWS Config's built-in managed rules (which do not support custom SNS triggers) with the need for a separate service like Lambda or Security Hub, but the correct answer is AWS Config with a custom rule that directly integrates SNS notifications.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service that can run code but does not itself evaluate Config rules or trigger notifications; it would need to be integrated as part of a custom Config rule or invoked separately. Option B is wrong because AWS Security Hub aggregates security findings from multiple services but does not evaluate AWS Config rules or directly trigger notifications for specific resource changes. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes network traffic and logs for malicious activity, not for evaluating security group configuration changes.

Option D is wrong because AWS CloudTrail records API activity for auditing but does not evaluate resource configurations or trigger notifications based on compliance rules.

90
MCQmedium

Refer to the exhibit. An IAM policy is attached to an IAM user. The user reports that they can upload objects to the S3 bucket but cannot list the contents of the bucket. Which statement explains this behavior?

A.The policy does not include the s3:ListBucket action.
B.The policy includes s3:ListBucket but is missing the bucket ARN.
C.The policy denies the s3:ListBucket action.
D.The policy explicitly denies s3:ListBucket.
AnswerA

The attached IAM policy only grants s3:PutObject and s3:GetObject; it does not contain a statement allowing s3:ListBucket. Listing the objects in an S3 bucket is a bucket-level permission that requires s3:ListBucket on the bucket ARN (e.g., arn:aws:s3:::example-bucket). Because no Allow exists for that action, IAM's default-deny rule causes list requests to fail, even though the user can still upload and download objects.

Why this answer

The IAM policy grants the s3:PutObject action, which allows the user to upload objects, but it does not include the s3:ListBucket action. The s3:ListBucket action is required to list the contents of an S3 bucket (e.g., via the ListObjects API call). Without this permission, the user can upload but cannot see the bucket's object listing.

Exam trap

The trap here is that candidates often confuse an implicit deny (missing allow) with an explicit deny, or assume that the s3:PutObject action implicitly grants listing permissions, which it does not.

How to eliminate wrong answers

Option B is wrong because if the policy included s3:ListBucket but was missing the bucket ARN, the action would not apply to the specific bucket, resulting in a deny by default (implicit deny), not a successful upload with failed listing. Option C is wrong because an implicit deny (lack of allow) is not the same as an explicit deny; the policy does not contain a Deny statement for s3:ListBucket. Option D is wrong because an explicit deny would require a Deny effect statement for s3:ListBucket, which is not present in the policy; the behavior is due to missing allow, not an explicit deny.

91
MCQmedium

A company uses Amazon GuardDuty for threat detection. The security team wants to automatically isolate an EC2 instance that is communicating with a known malicious IP address. Which combination of services should be used?

A.GuardDuty -> AWS Config -> Lambda -> modify security group
B.GuardDuty -> CloudWatch Alarm -> Lambda -> modify security group
C.GuardDuty -> EventBridge -> Lambda -> modify security group
D.GuardDuty -> AWS Shield -> modify security group
E.GuardDuty -> AWS Systems Manager -> modify security group
AnswerC

GuardDuty findings are delivered as events to Amazon EventBridge, which matches the malicious-IP finding type and invokes a Lambda function. Lambda then modifies the instance's security group, removing outbound access and satisfying the automated isolation requirement without terminating the instance or disrupting forensic evidence.

Why this answer

Amazon GuardDuty generates findings that can be sent to Amazon EventBridge as events. EventBridge can then trigger an AWS Lambda function that modifies the security group associated with the EC2 instance to deny traffic to/from the malicious IP address. This architecture provides a serverless, event-driven response mechanism without polling or additional services.

Exam trap

The trap here is that candidates confuse CloudWatch Alarms with EventBridge, not realizing that GuardDuty findings are event-driven and require a rule-based event bus (EventBridge) rather than a metric-based alarm (CloudWatch Alarm) to trigger remediation.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration compliance and resource inventory service, not an event-driven trigger for real-time threat response; it cannot directly forward GuardDuty findings to Lambda. Option B is wrong because CloudWatch Alarms are designed for metric-based thresholds (e.g., CPU utilization), not for receiving structured JSON findings from GuardDuty; GuardDuty does not natively publish to CloudWatch Alarms. Option D is wrong because AWS Shield is a DDoS protection service and does not process GuardDuty findings or modify security groups.

Option E is wrong because AWS Systems Manager is an operations management service for patching and automation, not designed to consume GuardDuty findings in real time for security group modifications.

92
Multi-Selectmedium

A company is designing a centralized logging solution for multiple AWS accounts. The solution must meet the following requirements: 1) Logs from all accounts must be stored in a centralized S3 bucket. 2) The logs must be encrypted at rest using AWS KMS. 3) Access to the logs must be logged and monitored. Which TWO services should be used to meet the requirements? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon Macie
D.S3 server access logs
E.AWS Config
AnswersB, D

CloudTrail is the correct service for centralized logging because it can be configured in an organization to deliver management (and optionally data) events from all member accounts into a single organization-level S3 bucket, providing a durable, immutable, and centralized audit trail. With CloudTrail organization trails, log files from every account are delivered to a common prefix structure, enabling unified compliance analysis and searchable history. This direct S3 delivery is the standard pattern for building a centralized multi-account logging solution.

Why this answer

AWS CloudTrail is correct because it can be configured to deliver log files from multiple AWS accounts into a single centralized S3 bucket, meeting the requirement for centralized logging. It also integrates with AWS KMS to encrypt the log files at rest using customer-managed keys, satisfying the encryption requirement.

Exam trap

The trap here is that candidates often confuse services that generate logs (like CloudTrail) with services that monitor or analyze logs (like GuardDuty or Macie), or they overlook that S3 server access logs are needed specifically to meet the requirement for logging and monitoring access to the centralized bucket.

93
MCQeasy

A security analyst wants to receive a notification whenever a new security group is created in their AWS account. Which AWS service should they use to trigger an SNS notification based on the CloudTrail event?

A.Amazon GuardDuty
B.AWS Config
C.Amazon EventBridge (CloudWatch Events)
D.AWS Lambda
AnswerC

Amazon EventBridge (formerly CloudWatch Events) is a serverless event bus that ingests events from AWS services, including CloudTrail API call events, and uses rules to filter and route them to targets such as SNS topics. You can create an event rule with a pattern that matches specific API events (e.g., eventName, eventSource) and immediately invoke an SNS topic to send a notification. This is the correct service for real-time, event-driven alerts based on API activity, as it directly supports the required notification workflow.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) can monitor CloudTrail API calls in real time and trigger an SNS notification when a specific event, such as CreateSecurityGroup, occurs. By creating a rule that matches the event source and detail type, EventBridge evaluates incoming events and routes matching ones to an SNS topic, enabling the desired notification.

Exam trap

The trap here is that candidates often confuse AWS Config with EventBridge, thinking Config can trigger notifications on API events, but Config only evaluates resource state changes, not real-time API calls, and requires a custom Lambda rule to react to events, whereas EventBridge natively supports CloudTrail event patterns.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide custom event-driven notifications based on specific CloudTrail API calls like CreateSecurityGroup. Option B is wrong because AWS Config is a resource inventory and compliance service that evaluates resource configurations against rules, but it cannot directly trigger SNS notifications from CloudTrail events; it uses its own config rules and remediation actions, not event-driven triggers. Option D is wrong because AWS Lambda is a compute service that can process events, but it is not the service that triggers the SNS notification; Lambda would be a target of an EventBridge rule, not the service that monitors CloudTrail events and initiates the notification.

94
MCQeasy

A company wants to receive real-time notifications when specific API calls are made in their AWS account, such as IAM user creation or S3 bucket policy changes. Which AWS service should be used to trigger notifications based on these API events?

A.Amazon CloudWatch Events (Amazon EventBridge)
B.Amazon GuardDuty
C.Amazon Simple Notification Service (SNS)
D.AWS Config
AnswerA

Amazon CloudWatch Events (Amazon EventBridge) is the correct choice because it natively ingests AWS CloudTrail API activity as event patterns and can filter for specific API calls (e.g., by eventName, awsRegion, or userIdentity) in real time. Once a rule matches, EventBridge invokes a target such as AWS Lambda, Amazon SNS, or Step Functions to deliver the notification, giving you low-latency, event-driven responses to the exact API activity you care about.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) is the correct service because it can capture AWS API calls in real time via CloudTrail integration. You can create a rule that matches specific API calls (e.g., CreateUser, PutBucketPolicy) and route those events to a target such as an SNS topic or Lambda function for immediate notification. This provides the real-time, event-driven notification required by the scenario.

Exam trap

The trap here is that candidates often pick Amazon SNS because they think of 'notifications' first, but they overlook that SNS cannot directly consume AWS API events without an intermediary like EventBridge or CloudTrail.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (e.g., CloudTrail, VPC Flow Logs, DNS logs) for malicious activity, but it does not provide a mechanism to trigger custom notifications based on specific API calls. Option C is wrong because Amazon Simple Notification Service (SNS) is a pub/sub messaging service that can deliver notifications, but it cannot directly capture or filter API calls; it requires an event source like EventBridge to send it events. Option D is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it does not provide real-time event-driven notifications for specific API calls; it operates on configuration changes and periodic evaluations.

95
Multi-Selectmedium

A company wants to monitor for suspicious IAM activity, such as a user creating access keys without authorization. Which THREE AWS services can be used together to detect and alert on this activity in real-time? (Choose THREE.)

Select 3 answers
A.Amazon CloudWatch Logs
B.Amazon Inspector
C.AWS CloudTrail
D.AWS Trusted Advisor
E.Amazon Simple Notification Service (SNS)
AnswersA, C, E

CloudWatch Logs is the service that turns CloudTrail log data into actionable alarms. By creating a metric filter on a log group for events such as CreateAccessKey or ConsoleLogin failures, you can define a CloudWatch alarm that evaluates the metric and triggers an SNS notification when the count exceeds a threshold. This makes CloudWatch Logs the central monitoring component for detecting suspicious IAM activity in near real time.

Why this answer

Amazon CloudWatch Logs is correct because it can ingest and monitor log data from AWS CloudTrail in real-time. By creating a CloudWatch Logs metric filter on CloudTrail logs for events like CreateAccessKey, you can trigger an alarm that sends notifications via SNS when unauthorized access key creation occurs. This enables real-time detection and alerting for suspicious IAM activity.

Exam trap

The trap here is that candidates often confuse Amazon Inspector or Trusted Advisor as security monitoring services, but they lack the capability to monitor real-time IAM API activity, which requires CloudTrail, CloudWatch Logs, and SNS working together.

96
MCQeasy

A company wants to detect and alert on changes to IAM roles and policies in their AWS account. Which combination of AWS services should they use?

A.Amazon GuardDuty and AWS Shield
B.Amazon CloudWatch Logs and AWS Lambda
C.AWS CloudTrail and Amazon EventBridge (CloudWatch Events)
D.AWS Config and Amazon Inspector
AnswerC

AWS CloudTrail is the correct service to record all IAM API activity—such as CreateRole, UpdateAssumeRolePolicy, AttachRolePolicy, and DeleteRole—by generating event logs with details like the requesting principal, source IP, and timestamp. Amazon EventBridge (formerly CloudWatch Events) can be configured with rule patterns that match specific IAM events, then trigger actions like sending notifications to Amazon SNS or invoking a Lambda function. This combination enables near-real-time, event-driven alerting on exactly the IAM role changes that the company cares about, with no need for polling or custom log parsing.

Why this answer

AWS CloudTrail records all API calls, including changes to IAM roles and policies, and delivers log files to an S3 bucket or CloudWatch Logs. Amazon EventBridge (formerly CloudWatch Events) can then be used to create rules that match specific CloudTrail events (e.g., PutRolePolicy, CreateRole) and trigger alerts via SNS, Lambda, or other targets. This combination provides real-time detection and notification of IAM modifications.

Exam trap

The trap here is that candidates often confuse AWS Config (which evaluates resource compliance) with real-time event-driven alerting, or they mistakenly think GuardDuty’s threat detection includes IAM policy change alerts, when in fact CloudTrail + EventBridge is the correct pattern for custom event-based monitoring.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity using VPC Flow Logs, DNS logs, and CloudTrail events, but it does not directly alert on IAM policy changes; AWS Shield is a DDoS protection service and irrelevant here. Option B is wrong because CloudWatch Logs can store log data but cannot independently detect or alert on IAM changes without a rule engine like EventBridge; Lambda alone cannot trigger on CloudTrail events without an event source such as EventBridge or S3 notifications. Option D is wrong because AWS Config evaluates resource compliance against rules and can detect drift in IAM policies, but it does not provide real-time event-driven alerts; Amazon Inspector is a vulnerability assessment service for EC2 instances and container workloads, not for IAM change detection.

97
Multi-Selectmedium

Which TWO AWS services can be used to centrally collect and analyze logs from multiple AWS accounts? (Choose two.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.Amazon Kinesis Data Firehose
D.Amazon Athena
E.Amazon S3
AnswersA, E

Amazon CloudWatch Logs is a central service that can aggregate logs from multiple AWS accounts and on-premises sources via cross-account subscriptions and log destinations. It provides a unified view for monitoring, querying, and setting metric filters on log data, making it a true central collection point for operational logs.

Why this answer

Amazon CloudWatch Logs can centrally collect logs from multiple AWS accounts by using cross-account subscription filters or by aggregating logs into a central account via CloudWatch Logs destination. This enables centralized monitoring and analysis of log data from various sources, meeting the requirement for a multi-account log collection and analysis solution.

Exam trap

The trap here is that candidates often confuse log collection services (CloudWatch Logs, S3) with analysis-only services (Athena) or event-recording services (CloudTrail), failing to recognize that CloudTrail generates logs but does not centrally collect them from multiple accounts without additional configuration.

98
MCQhard

A company uses AWS CloudTrail to log all management events and data events for S3. The security team wants to detect any PutObject API calls that upload objects with server-side encryption disabled. Which solution is MOST efficient?

A.Use Amazon GuardDuty to detect unencrypted uploads.
B.Use Amazon Macie to scan S3 objects for missing encryption.
C.Enable S3 server access logs and parse them with Amazon Athena.
D.Enable CloudTrail data events for S3 and create a CloudWatch metric filter to alert on PutObject calls without the x-amz-server-side-encryption header.
AnswerD

The correct approach is to enable CloudTrail data events for the S3 bucket, because S3 data events record each PutObject API call, including request parameters such as the x-amz-server-side-encryption header when the caller supplies it. You can send those events to CloudWatch Logs and create a metric filter that matches PutObject events where that header is absent, then attach a CloudWatch alarm to notify the security team. This directly captures the encryption intent of the caller at upload time, which is exactly what the requirement asks for.

Why this answer

CloudTrail data events for S3 capture PutObject API calls, including request parameters. A CloudWatch metric filter can be configured to match PutObject events that lack the 'x-amz-server-side-encryption' header, indicating the object was uploaded without server-side encryption. This approach is efficient as it uses existing logging infrastructure without additional scanning or parsing overhead.

Exam trap

The trap here is that candidates may confuse GuardDuty or Macie as encryption compliance tools, but they are designed for threat detection and data classification, respectively, not for verifying encryption headers on API calls.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty does not inspect S3 object-level encryption headers; it focuses on threat detection (e.g., unusual API activity, credential compromise) rather than compliance checks for encryption. Option B is wrong because Amazon Macie is designed to discover sensitive data (e.g., PII) in S3 objects, not to detect missing server-side encryption on uploads; it operates on stored objects, not API calls. Option C is wrong because S3 server access logs are object-level logs that record requests but require parsing with Athena, which is less efficient than real-time CloudWatch metric filtering and does not natively filter on encryption headers without custom queries.

99
MCQeasy

A company needs to monitor for unauthorized S3 bucket deletions. Which CloudWatch Logs metric filter should be used on CloudTrail logs?

A.eventName = GetBucketAcl
B.eventName = DeleteBucket
C.eventName = PutBucketPolicy
D.eventName = ListBuckets
AnswerB

DeleteBucket is the exact S3 management API invoked when a bucket is removed, and CloudTrail records it as eventName = DeleteBucket for each deletion attempt. An EventBridge rule or CloudWatch Logs metric filter targeting this event name catches both successful and failed deletion attempts, depending on the response elements. This is the only option that corresponds to the actual bucket deletion operation, making it the correct value to monitor.

Why this answer

The CloudTrail event `DeleteBucket` is logged when an S3 bucket is deleted. By creating a CloudWatch Logs metric filter that matches `eventName = DeleteBucket` on the CloudTrail log group, you can trigger an alarm or automated response to detect unauthorized bucket deletions. This directly addresses the monitoring requirement.

Exam trap

The trap here is that candidates may confuse read-only or policy-modifying events (like `GetBucketAcl`, `PutBucketPolicy`, or `ListBuckets`) with the actual deletion event, failing to recognize that only `DeleteBucket` directly corresponds to bucket removal.

How to eliminate wrong answers

Option A is wrong because `GetBucketAcl` retrieves the bucket's access control list, not a deletion event, so it would not detect bucket deletions. Option C is wrong because `PutBucketPolicy` modifies the bucket policy, which could lead to unauthorized access but is not a deletion action. Option D is wrong because `ListBuckets` enumerates all buckets in the account and is a read-only operation, not a deletion.

100
MCQeasy

A security engineer is configuring CloudTrail to log all management events across all regions. The engineer wants to ensure that log files are delivered to an S3 bucket owned by a separate AWS account for centralized auditing. Which additional configuration is required to allow the S3 bucket in the other account to receive these logs?

A.Create an S3 bucket policy on the source account's bucket to allow cross-account access.
B.Enable S3 server-side encryption with KMS on the destination bucket.
C.Create an IAM role in the source account and attach a trust policy for CloudTrail.
D.Add a bucket policy to the destination S3 bucket that allows CloudTrail to write objects.
AnswerD

The destination bucket must have a resource-based policy that explicitly allows CloudTrail's service principal (`cloudtrail.amazonaws.com`) to write objects into that bucket, typically with `s3:PutObject` permission and a condition restricting access to the source account's trail. This bucket policy is the only mechanism that authorizes the cross-account write path because CloudTrail in the source account presents no IAM role or source-account user credentials to S3. For a complete setup, the trail in the source account references the destination bucket ARN, and the bucket policy also includes `s3:GetBucketAcl` or `s3:GetBucketLocation` as needed for CloudTrail to verify bucket ownership. Without this policy, CloudTrail will fail with an access denied error during delivery.

Why this answer

CloudTrail delivers log files to an S3 bucket in a separate account by writing objects across accounts. The destination bucket must have a bucket policy that explicitly grants CloudTrail (the service principal `cloudtrail.amazonaws.com`) permission to write objects (e.g., `s3:PutObject`). Without this policy, CloudTrail cannot deliver logs to the cross-account bucket, even if the source account has proper CloudTrail configuration.

Exam trap

The trap here is that candidates confuse cross-account S3 access with IAM roles, assuming CloudTrail needs an IAM role in the source account to assume permissions, when in fact CloudTrail uses a service principal and a resource-based bucket policy on the destination bucket.

How to eliminate wrong answers

Option A is wrong because the source account does not own the destination bucket; the bucket policy must be on the destination bucket (owned by the separate account), not on a source account bucket. Option B is wrong because enabling S3 server-side encryption with KMS on the destination bucket is optional and not required for cross-account log delivery; it addresses encryption, not access control. Option C is wrong because CloudTrail does not use an IAM role in the source account to write to a cross-account S3 bucket; it relies on a resource-based policy (bucket policy) on the destination bucket, not a trust policy for CloudTrail.

101
Multi-Selecteasy

A company wants to receive notifications when AWS CloudTrail logs are delivered to an S3 bucket. Which TWO AWS services can be used together to achieve this? (Choose TWO.)

Select 2 answers
A.Amazon S3 Event Notifications
B.AWS CloudTrail
C.AWS Lambda
D.Amazon Simple Queue Service (SQS)
E.Amazon Simple Notification Service (SNS)
AnswersA, E

S3 Event Notifications are generated by the S3 service when an object is created (s3:ObjectCreated:*) and can be delivered to SNS, SQS, or Lambda. Placing this configuration on the CloudTrail log bucket triggers a notification each time CloudTrail writes a new log file, enabling downstream alerting without polling.

Why this answer

Amazon S3 Event Notifications can be configured to publish events (like `s3:ObjectCreated:*`) when CloudTrail logs are delivered to the S3 bucket. These notifications can be sent directly to Amazon SNS, which then delivers the notification to subscribers (e.g., email, SMS, or HTTP endpoints). Together, S3 Event Notifications and SNS provide a serverless, real-time notification pipeline without needing custom polling or compute resources.

Exam trap

The trap here is that candidates often think Lambda is mandatory to process S3 events and send notifications, but S3 Event Notifications can directly target SNS without any compute layer, making Lambda an unnecessary third service for this specific requirement.

102
MCQeasy

A security analyst wants to monitor unsuccessful login attempts to the AWS Management Console. Which AWS service and log combination should be used?

A.Amazon S3 server access logs.
B.VPC Flow Logs.
C.Amazon CloudWatch Logs.
D.AWS CloudTrail.
AnswerD

AWS CloudTrail records the ConsoleLogin management event for every AWS Management Console sign-in attempt, including both successful and failed authentications. A failed login appears as an event with the eventName ConsoleLogin and responseElements.ConsoleLogin.LoginResult set to Failure, along with details like the IAM user or root principal, source IP address, user agent, and MFA usage. Security analysts can query these events with the AWS CLI lookup-events command, the CloudTrail console, or by analyzing the JSON log files delivered to S3 or CloudWatch Logs.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS Management Console, including failed login attempts (ConsoleLogin events with an 'errorMessage' field). CloudTrail logs these events as management events, which can be delivered to Amazon CloudWatch Logs or an S3 bucket for monitoring and alerting. This makes it the only option that captures authentication failures at the console level.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (a log destination) with a log source, forgetting that CloudWatch Logs cannot capture console login events without CloudTrail delivering them first.

How to eliminate wrong answers

Option A is wrong because Amazon S3 server access logs record requests made to an S3 bucket (e.g., GET, PUT, DELETE), not AWS Management Console login attempts. Option B is wrong because VPC Flow Logs capture metadata about IP traffic flowing through a VPC (e.g., source/destination IPs, ports, protocols), not authentication events. Option C is wrong because Amazon CloudWatch Logs is a log storage and monitoring service, not a log source; it cannot generate logs of console login attempts on its own—it requires a service like CloudTrail to deliver those logs.

103
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team needs to implement a centralized logging solution where all VPC Flow Logs from all accounts are sent to a central S3 bucket in the security account. The flow logs must be encrypted with a customer-managed KMS key (CMK) that is owned by the security account. The security engineer has enabled VPC Flow Logs in each account and configured the destination to be the central S3 bucket. However, the flow logs are not being delivered. The engineer checks the S3 bucket policy and confirms that it grants the required permissions to the Flow Logs service principal. What is the MOST likely cause of the failure?

A.The VPC Flow Logs service does not support cross-account delivery.
B.The KMS key policy does not grant the Flow Logs service principal permission to use the key.
C.CloudTrail must be enabled in the source account for Flow Logs to work.
D.The S3 bucket policy is missing a condition for source account.
AnswerB

VPC Flow Logs encrypts delivered records using the destination CMK, so the Flow Logs service principal needs kms:GenerateDataKey and kms:Decrypt in the key policy. The S3 bucket policy alone cannot grant that KMS access, blocking delivery.

Why this answer

When VPC Flow Logs are delivered to an S3 bucket encrypted with a customer-managed KMS key, the Flow Logs service principal must have permission to use that key. Even if the S3 bucket policy grants access, the KMS key policy must also allow the Flow Logs service to encrypt data. Without this, the delivery fails.

This is the most likely cause given the scenario.

Exam trap

SCS-C02 often tests the misconception that S3 bucket policy alone is sufficient for encrypted delivery — candidates forget that KMS key policies are separate and must explicitly grant the service principal access.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs do support cross-account delivery to an S3 bucket in another account, provided the bucket policy and KMS key policy allow it. Option C is wrong because CloudTrail is not required for VPC Flow Logs to function; they are independent services. Option D is wrong because while a condition for source account might be needed in some cases, the scenario already states the bucket policy grants required permissions, and the more specific issue with KMS key policy is the likely cause.

104
Drag & Dropmedium

Drag and drop the steps to respond to a suspected AWS IAM credential compromise in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Credential compromise response starts with rotation, log review, disabling user, revoking temp creds, and notification.

105
MCQeasy

A security engineer needs to centralize logs from multiple AWS accounts into a single S3 bucket. Which solution is most secure?

A.Deliver logs to separate buckets per account and use S3 replication to copy them to a central bucket.
B.Use a single S3 bucket in the management account and have each account write logs directly without additional permissions.
C.Configure each account's CloudTrail to deliver to a centralized S3 bucket in a logging account, with a bucket policy allowing CloudTrail from source accounts.
D.Stream logs to Amazon Kinesis Data Firehose in each account and consolidate into a single S3 bucket via cross-account delivery.
AnswerC

This is correct because CloudTrail can be configured as a single trail (or one per source account) to deliver to a centralized S3 bucket in a dedicated logging account. The logging account's S3 bucket policy must explicitly authorize cloudtrail.amazonaws.com for each source account, usually with a source account and source ARN condition, so CloudTrail can write objects to a per-source prefix. This creates an immutable, central log store that source-account administrators cannot modify or delete, and it is a standard, well-supported pattern for centralized logging.

Why this answer

It uses a centralized S3 bucket in a dedicated logging account with a bucket policy that explicitly grants CloudTrail from source accounts the s3:PutObject permission. This ensures logs are written directly to a single location without intermediate replication or cross-account delivery that could introduce latency or complexity. The bucket policy can restrict access to only CloudTrail service principals and specific source account ARNs, maintaining a secure, auditable log trail.

Exam trap

The trap here is that candidates assume S3 replication (Option A) is the simplest centralized solution, but they overlook that CloudTrail can deliver directly to a cross-account bucket with a properly scoped bucket policy, which is more secure and avoids the overhead of replication or streaming services.

How to eliminate wrong answers

Option A is wrong because S3 replication introduces a time delay and requires the source bucket to have versioning enabled, which adds complexity and potential for log loss if replication fails; it also duplicates storage costs and does not prevent the source account from modifying logs before replication. Option B is wrong because having each account write logs directly to a bucket in the management account without additional permissions is insecure—CloudTrail requires explicit cross-account permissions via a bucket policy, and without them, the write will fail; this option also violates the principle of least privilege by allowing all accounts to write to a single bucket without restriction. Option D is wrong because streaming logs through Kinesis Data Firehose introduces an additional service that can fail or throttle, adds latency, and requires managing cross-account delivery policies for Firehose, which is more complex and less secure than direct CloudTrail delivery to S3 with a bucket policy.

106
MCQeasy

A security engineer needs to be alerted when an IAM user attempts to modify an S3 bucket policy. Which method is the MOST efficient?

A.Enable VPC Flow Logs and analyze for S3 API traffic
B.Configure an AWS Config rule to detect changes and invoke a Lambda function
C.Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification
D.Enable S3 server access logs and parse them for PutBucketPolicy entries
AnswerC

Create an Amazon CloudWatch Events (now Amazon EventBridge) rule with an event pattern matching the `detail-type` of `AWS API Call via CloudTrail`, the `eventSource` as `s3.amazonaws.com`, and `eventName` as `PutBucketPolicy`. When CloudTrail logs that IAM API call, the rule triggers an SNS topic to notify the security engineer in near real time. This is the native AWS approach for reacting to control-plane actions.

Why this answer

Amazon CloudWatch Events (now Amazon EventBridge) can directly capture the PutBucketPolicy API call as a real-time event and trigger an SNS notification without any additional compute or polling. This is the most efficient method as it requires no log parsing, no custom code, and no additional infrastructure, providing immediate alerting with minimal overhead.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing log-based methods (A or D) or evaluation-based methods (B), missing that CloudWatch Events provides the simplest and most direct real-time alerting for specific API calls without additional overhead.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log API-level operations like PutBucketPolicy; they cannot identify the specific S3 API call being made. Option B is wrong because an AWS Config rule detects configuration changes after they occur via periodic evaluations or configuration item changes, which introduces latency and requires a Lambda function for notification, making it less efficient than a direct event-driven approach. Option D is wrong because S3 server access logs are delivered on a best-effort basis with delays (often hours), require parsing to extract PutBucketPolicy entries, and are not designed for real-time alerting.

107
MCQhard

A company uses AWS Config to track resource changes. They notice that a weekly compliance report shows an S3 bucket as non-compliant with a rule that checks for server-side encryption. However, the bucket has default encryption enabled. What is the MOST likely reason for this discrepancy?

A.The Config rule checks for SSE on objects, not default bucket encryption.
B.The Config rule was deleted and recreated without re-evaluating existing resources.
C.The Config rule is only evaluating resources in a single AWS Region.
D.The S3 bucket is not tagged with a required tag for the Config rule.
AnswerA

The managed AWS Config rule s3-bucket-server-side-encryption-enabled is deliberately designed to verify that an S3 bucket policy requires the x-amz-server-side-encryption header on uploads — it does not inspect the bucket's default encryption configuration. Setting 'Amazon S3 default encryption' only applies SSE to objects uploaded without explicit encryption headers; those headers can be omitted or overridden by the client, so the bucket remains NON_COMPLIANT unless a bucket policy explicitly denies requests lacking the required encryption header. Therefore, seeing a bucket with default encryption flagged as NON_COMPLIANT is the rule's expected behavior, not a misconfiguration of Config.

Why this answer

The AWS Config managed rule `s3-bucket-server-side-encryption-enabled` specifically checks whether the bucket policy enforces server-side encryption on objects uploaded to the bucket, not whether the bucket has default encryption configured. Default encryption only applies to objects that do not have an encryption setting at the time of upload, but the rule evaluates the bucket's policy for a condition that requires SSE for all PUT requests. Therefore, a bucket with default encryption enabled but without a policy enforcing SSE will be reported as non-compliant.

Exam trap

The trap here is that candidates confuse default bucket encryption with server-side encryption enforcement, assuming that enabling default encryption automatically satisfies the Config rule, when in fact the rule requires a bucket policy to deny unencrypted uploads.

How to eliminate wrong answers

Option B is wrong because deleting and recreating a Config rule without re-evaluating existing resources would cause the rule to evaluate only new resources, but the bucket would still be evaluated if it existed before the recreation; the discrepancy is not due to a missing re-evaluation. Option C is wrong because S3 is a global service, and AWS Config rules for S3 buckets evaluate resources across all regions by default; the rule is not limited to a single region unless explicitly scoped. Option D is wrong because the `s3-bucket-server-side-encryption-enabled` rule does not require any specific tags; it checks for encryption enforcement, not tagging.

108
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centralize security logs (CloudTrail, VPC Flow Logs, AWS Config) from all accounts into a single S3 bucket for analysis. What is the MOST secure way to set up this centralized logging?

A.Create a dedicated S3 bucket in the management account, enable S3 default encryption, and configure service delivery for each account.
B.Create a dedicated S3 bucket in the security account with a bucket policy that grants write access to the logging services of all accounts and enforces encryption in transit and at rest.
C.Configure each account to deliver logs to the same S3 bucket used for other data.
D.Create an S3 bucket in each account and use S3 replication to copy logs to a central bucket.
AnswerB

This approach aligns with AWS best practices by placing logs in a dedicated security account that is isolated from production workloads and the management account. The bucket policy grants write access only to the logging services of all accounts, using service principals like logging.s3.amazonaws.com, while condition keys such as aws:SecureTransport force TLS and a deny statement without s3:x-amz-server-side-encryption ensures all objects are encrypted at rest. This centralizes auditability, enforces least privilege, and provides a single source of truth for compliance and incident investigation.

Why this answer

It uses a dedicated S3 bucket in a security account (not the management account) with a bucket policy that explicitly grants write access to the logging services (CloudTrail, VPC Flow Logs, AWS Config) from all accounts, while enforcing encryption in transit (aws:SecureTransport) and at rest (default SSE-S3 or SSE-KMS). This follows the security best practice of isolating logs in a separate account and using resource-based policies to restrict access, preventing accidental deletion or modification by other accounts.

Exam trap

The trap here is that candidates often assume the management account is the safest place for centralized logs, but AWS best practices recommend using a dedicated security account to isolate logs and avoid compromising the management account's administrative boundaries.

How to eliminate wrong answers

Option A is wrong because placing the S3 bucket in the management account violates the principle of least privilege and separation of duties; the management account should not be used for operational workloads, and service delivery configuration alone does not enforce encryption in transit or restrict access to only logging services. Option C is wrong because using the same S3 bucket for other data increases the attack surface and risk of unauthorized access or log tampering, and it does not enforce encryption or proper access controls for logging services. Option D is wrong because S3 replication introduces complexity, potential latency, and does not enforce encryption in transit or at rest at the source; it also requires additional permissions and does not centralize logs directly from the logging services.

109
Multi-Selecteasy

A security engineer is designing a monitoring solution for a multi-account AWS environment using AWS Organizations. The solution must provide a centralized view of all API activities and send alerts for suspicious events. Which TWO services together can achieve this? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty
B.AWS Lambda
C.AWS CloudTrail
D.Amazon CloudWatch Logs
E.AWS Config
AnswersC, D

AWS CloudTrail records management events (and optionally data events) for every API call made in an AWS account, capturing the identity, source IP, time, request parameters, and response elements. When enabled for an AWS Organization, you can create an organization trail that logs events for all accounts and delivers them to a single Amazon S3 bucket, enabling centralized auditing. This makes CloudTrail the definitive source of API activity for security monitoring, compliance, and forensic investigation.

Why this answer

AWS CloudTrail is correct because it records all API activity across an AWS environment, and when integrated with AWS Organizations, it can deliver a centralized view of API calls from all accounts into a single CloudTrail trail. Amazon CloudWatch Logs is correct because it can ingest CloudTrail logs from a centralized logging account, allowing the security engineer to create metric filters and alarms that trigger alerts for suspicious events based on specific API patterns.

Exam trap

The trap here is that candidates often pick GuardDuty (A) because it is a security service, but they overlook that GuardDuty does not provide a centralized view of all API activities or allow custom alerting on specific API events, which requires CloudTrail and CloudWatch Logs.

110
Multi-Selecteasy

Which TWO AWS services can be used to monitor and detect unauthorized changes to Amazon S3 bucket policies? (Choose two.)

Select 2 answers
A.AWS CloudTrail
B.Amazon GuardDuty
C.Amazon CloudWatch Logs
D.AWS Config
E.Amazon VPC Flow Logs
AnswersA, D

AWS CloudTrail records management events in your account, including the PutBucketPolicy API call that modifies an S3 bucket policy. This gives you a complete, auditable history of who made the change, from which IP address, and when, making it a primary service for detecting and investigating policy changes.

Why this answer

AWS CloudTrail is correct because it records all API calls made to Amazon S3, including changes to bucket policies (e.g., PutBucketPolicy, DeleteBucketPolicy). By enabling CloudTrail on the S3 bucket or using a trail that logs data events for S3, you can monitor and detect unauthorized policy modifications in near real-time through the CloudTrail event history or by delivering logs to Amazon CloudWatch Logs for further analysis.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's ability to analyze CloudTrail logs for threat detection with direct monitoring of S3 policy changes, but GuardDuty does not have built-in rules to detect unauthorized policy modifications; it focuses on anomalous behavior like unusual API patterns, not specific resource-level changes.

111
Multi-Selectmedium

Which TWO actions are valid ways to send application logs from an EC2 instance to Amazon CloudWatch Logs? (Select TWO.)

Select 2 answers
A.Configure the EC2 instance to stream syslog to AWS CloudTrail.
B.Write logs to an S3 bucket and use S3 event notifications to send to CloudWatch Logs.
C.Install and configure the unified CloudWatch agent on the EC2 instance.
D.Enable VPC Flow Logs to capture application traffic.
E.Install and configure the legacy CloudWatch Logs agent.
AnswersC, E

The unified CloudWatch agent (amazon-cloudwatch-agent) is the recommended method for collecting both custom metrics and log files from EC2 instances. It tails configured log files and forwards each line to a CloudWatch Logs group and stream using the PutLogEvents API, with options for multi-line logs, timestamp formats, and rotation. This directly and reliably satisfies the requirement to send application logs to CloudWatch Logs, making it a correct answer.

Why this answer

The unified CloudWatch agent (option C) is a valid and recommended method for collecting application logs from EC2 instances and sending them to CloudWatch Logs. It supports collecting logs from various sources, including syslog, and can also collect metrics, providing a single agent for both monitoring and logging.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (which capture network traffic metadata) with application-level logging, or assume that S3 event notifications can directly forward log data to CloudWatch Logs without an intermediary service like Lambda.

112
MCQmedium

A company has a requirement to retain AWS CloudTrail logs for 7 years for compliance. The logs are stored in an S3 bucket. The company wants to reduce storage costs by automatically moving older logs to a cheaper storage class. Which solution should the company implement?

A.Use S3 Intelligent-Tiering to automatically move logs to the most cost-effective access tier.
B.Configure an S3 Lifecycle policy to transition objects from S3 Standard to S3 Glacier after a specified number of days.
C.Move logs to S3 Standard-IA after 30 days.
D.Use S3 Batch Operations to manually copy logs to S3 Glacier.
AnswerB

Configure an S3 Lifecycle policy with a transition rule that moves CloudTrail logs from S3 Standard to S3 Glacier after a defined number of days, such as 30 or 90. This automated, deterministic approach aligns perfectly with typical log access patterns—logs are actively analyzed immediately after delivery, then only rarely needed for compliance or audit investigations. Glacier provides extremely low-cost, durable archival storage, which is cost-optimal for a 7-year retention requirement, and the lifecycle rule requires no ongoing operational effort once set.

Why this answer

An S3 Lifecycle policy can automatically transition CloudTrail logs from S3 Standard to S3 Glacier after a specified number of days, meeting the 7-year retention requirement while reducing storage costs. S3 Glacier is designed for long-term archival at low cost, and lifecycle rules can be configured to transition objects directly or through intermediate classes like S3 Standard-IA. S3 Intelligent-Tiering (Option A) also automatically optimizes costs and supports archival tiers, but it works based on access patterns, not fixed age-based rules, and incurs per-object monitoring fees.

For compliance-driven, age-based retention, a Lifecycle policy is the more direct and cost-effective solution.

Exam trap

The trap is that candidates may choose S3 Intelligent-Tiering (Option A) thinking it automatically optimizes costs for all scenarios, but Intelligent-Tiering monitors access patterns, not ages, and while it does support Glacier tiers, it is not designed for fixed retention periods. For age-based archival to Glacier, an S3 Lifecycle policy is the appropriate control.

How to eliminate wrong answers

Option A is wrong because S3 Intelligent-Tiering is designed for unpredictable access patterns and does not guarantee cost savings for long-term archival; it also does not transition to Glacier, which is needed for 7-year retention. Option C is wrong because moving logs to S3 Standard-IA after 30 days reduces cost for infrequent access but does not address the 7-year retention requirement; Standard-IA is not a long-term archival class and would still incur higher costs over 7 years compared to Glacier. Option D is wrong because S3 Batch Operations is a manual, one-time process that does not automate ongoing transitions, and manually copying logs to Glacier is inefficient and error-prone for a continuous compliance requirement.

113
Multi-Selecteasy

A security engineer is investigating a possible data exfiltration from an S3 bucket. Which THREE AWS services can be used to detect and alert on suspicious activity? (Choose THREE.)

Select 3 answers
A.Amazon CloudWatch Logs
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
E.Amazon Macie
AnswersB, C, E

Amazon GuardDuty is a managed threat detection service that continuously analyzes AWS account activity, including CloudTrail management and S3 data events, VPC Flow Logs, and DNS query logs, using integrated threat intelligence and anomaly-detection machine learning. It can generate findings such as an S3 bucket compromised finding or unusual data-access patterns that strongly indicate data exfiltration, and it alerts security engineers without requiring manually defined thresholds. This makes it the most direct, purpose-built service for spotting suspicious S3 activity in near real time.

Why this answer

Amazon GuardDuty (B) is correct because it continuously monitors CloudTrail management and S3 data events, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to generate findings such as Exfiltration:S3/ObjectRead.Unusual or Discovery:S3, which directly detect suspicious S3 access patterns. AWS CloudTrail (C) is correct because it records S3 data events (GetObject, PutObject, DeleteObject) and management events, providing the audit trail needed to identify anomalous API calls and feed GuardDuty and CloudWatch analysis. Amazon Macie (E) is correct because it uses machine learning and pattern matching to discover sensitive data in S3, and its findings (e.g., Policy:IAMUser/S3BucketPublic, SensitiveData:S3Object/Multiple) plus CloudWatch Events integration can alert on potential exfiltration of sensitive objects.

Amazon CloudWatch Logs (A) is not a detection service for S3 activity by itself; it stores and monitors log streams but requires CloudTrail or other sources to capture S3 API calls. AWS Config (D) tracks resource configuration changes and compliance but does not analyze S3 object access behavior or sensitive data movement, so it cannot detect exfiltration activity.

Exam trap

The trap here is that candidates often confuse AWS Config with a security detection service, but Config only tracks configuration changes and compliance, not the actual data access or network activity needed to detect exfiltration.

114
MCQhard

A security engineer is troubleshooting an issue where CloudTrail logs for a single AWS account are not being delivered to the centralized S3 bucket in the logging account. The engineer has verified that the CloudTrail trail is enabled, the S3 bucket policy allows CloudTrail to write, and the bucket exists. However, no log files have been delivered for the past 6 hours. The engineer checks the CloudTrail console and sees that the trail status shows 'Logging' but the latest log file time is from 8 hours ago. The engineer suspects a permission issue but cannot find any explicit deny in the bucket policy. What is the MOST likely cause of this issue?

A.The CloudTrail trail is not configured to deliver to a cross-account bucket.
B.The CloudTrail trail is configured with a role that does not have S3 full access.
C.The S3 bucket is in a different region than the CloudTrail trail.
D.The KMS key policy used by the S3 bucket does not grant CloudTrail permission to use the key.
AnswerD

When the destination S3 bucket is encrypted with SSE-KMS, CloudTrail must be explicitly allowed to use that customer-managed KMS key before it can write delivery files. The key policy must grant the CloudTrail service principal (or the trail's assumed role) kms:GenerateDataKey and kms:Decrypt actions; without these, CloudTrail will fail at the encryption step even though the trail is otherwise correctly configured. This is the most likely cause because the error is specific to SSE-KMS buckets — CloudTrail cannot silently assume IAM permissions across services for KMS operations and requires explicit key policy authorization. Therefore, a KMS key policy lacking CloudTrail permissions is exactly the kind of misconfiguration that would block log delivery.

Why this answer

If the S3 bucket is encrypted with SSE-KMS, CloudTrail must have permission to use the KMS key to encrypt the logs. If the KMS key policy does not grant CloudTrail the necessary permissions (kms:GenerateDataKey and kms:Decrypt), CloudTrail cannot write logs, even if the S3 bucket policy allows it. The trail status may still show 'Logging' because the trail is enabled, but delivery fails silently.

This is the most likely cause given the symptoms.

Exam trap

SCS-C02 often tests the hidden dependency on KMS key policies for encrypted S3 buckets; candidates focus on the S3 bucket policy and overlook the KMS key policy, leading to prolonged troubleshooting.

How to eliminate wrong answers

Option A is wrong because CloudTrail can deliver to a cross-account bucket if the bucket policy and KMS key policy allow it; the question states the bucket policy allows CloudTrail to write, so cross-account is not the issue. Option B is wrong because CloudTrail does not use an IAM role to write to S3; it uses the S3 bucket policy and, if encrypted, the KMS key policy. Option C is wrong because CloudTrail can deliver to an S3 bucket in a different region; there is no regional restriction.

115
Multi-Selecthard

A company has enabled Amazon GuardDuty in multiple AWS accounts. The security team wants to centralize GuardDuty findings into a single account for analysis. Which THREE steps are required to achieve this? (Choose THREE.)

Select 3 answers
A.Configure CloudWatch Logs cross-account subscription to aggregate findings.
B.Create an EventBridge rule to forward findings to the master account.
C.Invite member accounts to join the GuardDuty master account.
D.Accept the invitation in each member account.
E.Designate one account as the GuardDuty master account.
AnswersC, D, E

After designating a GuardDuty administrator (master) account, the administrator must send an invitation to each member account it wants to onboard. This invitation is the formal step that creates the GuardDuty account relationship, allowing the master account to access member findings, manage GuardDuty configurations, and generate usage reports. In an AWS Organizations environment, this step can be automated through delegated administration, but the manual invitation process is the correct and required approach when not using Organizations.

Why this answer

In Amazon GuardDuty, to centralize findings from multiple accounts, you must designate a master account and then invite member accounts to join. The invitation process establishes a trusted relationship where the master account can aggregate and analyze findings from all member accounts. Without this step, the master account cannot receive findings from other accounts.

Exam trap

The trap here is that candidates often confuse the GuardDuty multi-account setup with other cross-account aggregation methods (like CloudWatch Logs subscription filters or EventBridge cross-account rules), but GuardDuty has its own built-in master-member mechanism that does not require those services.

116
MCQeasy

A company wants to monitor for unauthorized changes to its Amazon S3 bucket policies. Which AWS service should be used to detect such changes?

A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.Amazon CloudWatch Logs Insights
AnswerA

AWS Config records configuration changes for supported resources and continuously evaluates those configurations against managed or custom rules. For S3 bucket policies, rules such as s3-bucket-policy-grant-check can detect unauthorized or noncompliant policy changes, flag the resource as noncompliant, and trigger remediation. It maintains a configuration history and timeline, making it the appropriate service for monitoring unauthorized changes to resource configuration.

Why this answer

AWS Config continuously records resource configurations and evaluates them against rules, so it can detect and alert on changes to S3 bucket policies via the s3-bucket-policy-not-more-permissive or custom Config rules. It provides a configuration timeline and compliance state, which is exactly what's needed to detect unauthorized policy modifications.

Exam trap

SCS-C02 often tests the difference between detecting configuration drift (AWS Config) and detecting API activity (CloudTrail) — candidates pick CloudTrail because it 'logs changes' but miss the compliance-evaluation requirement.

How to eliminate wrong answers

Option B is wrong because CloudTrail only records API calls — it logs that PutBucketPolicy was invoked but does not evaluate whether the resulting configuration is compliant or alert on drift. Option C is wrong because GuardDuty is a threat-detection service analyzing VPC flow logs, DNS logs, and CloudTrail for malicious activity; it does not monitor configuration compliance. Option D is wrong because CloudWatch Logs Insights is a query tool for log data — it can search CloudTrail logs but provides no configuration-state tracking or compliance evaluation.

117
Multi-Selectmedium

A security engineer is investigating a potential security incident. Which TWO AWS services can be used to analyze historical network traffic patterns? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.AWS CloudTrail
E.Amazon Athena
AnswersB, E

VPC Flow Logs capture IP traffic metadata—source and destination addresses, ports, protocol, packet and byte counts, and allow/deny actions—for traffic reaching network interfaces in your VPC. When published to Amazon S3, these logs become a durable, queryable history that can be analyzed with Athena using standard SQL to reconstruct past network behavior, such as whether an instance communicated with a suspicious host. This makes VPC Flow Logs the correct and most direct source for retrospective network traffic analysis.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, packet/byte counts) for network interfaces in a VPC. They are stored in Amazon CloudWatch Logs or Amazon S3, enabling historical analysis of network traffic patterns. Athena can query VPC Flow Logs stored in S3 using SQL, making it a powerful tool for analyzing historical traffic patterns at scale.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs (a storage/monitoring service) with Athena (a query service), or mistakenly think CloudTrail captures network traffic data instead of API activity, leading them to select CloudWatch Logs or CloudTrail instead of Athena.

118
MCQhard

A company is using Amazon GuardDuty to detect threats. The security team notices that GuardDuty findings are not triggering the intended automated response via a CloudWatch Events rule. What is the most likely reason?

A.The CloudWatch Events rule's event pattern does not match the GuardDuty finding event structure.
B.The GuardDuty detector is in a different region than the CloudWatch Events rule.
C.The Lambda function invoked by CloudWatch Events does not have an IAM role assigned.
D.VPC Flow Logs are not enabled.
AnswerA

GuardDuty emits findings to CloudWatch Events as structured events, and the rule's pattern must exactly match their JSON schema. Specifically, the pattern must use "source": ["aws.guardduty"] and "detail-type": ["GuardDuty Finding"]; otherwise the rule is never triggered. If the pattern mismatches, the Lambda function will not be invoked, even though the finding is visible in the GuardDuty console. This is the most common cause of a silent rule failure.

Why this answer

GuardDuty findings are sent to CloudWatch Events as events with a specific structure, including fields like 'detail-type' set to 'GuardDuty Finding' and 'source' set to 'aws.guardduty'. If the CloudWatch Events rule's event pattern does not match this exact structure—for example, if it filters on the wrong 'source' or 'detail-type'—the rule will not trigger the intended automated response. This is the most common reason for the described failure.

Exam trap

The trap here is that candidates often assume the issue is with permissions (Lambda role) or prerequisites (VPC Flow Logs), but the core problem is almost always a mismatch in the event pattern structure, which is a fundamental CloudWatch Events concept.

How to eliminate wrong answers

Option B is wrong because CloudWatch Events rules can be configured to receive events from any region by using a cross-region event bus or by setting up the rule in the same region as the GuardDuty detector; the detector and rule do not need to be in the same region for the rule to match events, but the default behavior is that events are regional unless explicitly configured otherwise. Option C is wrong because the Lambda function's IAM role is only relevant for execution permissions after the rule triggers; if the rule does not match the event, the Lambda function is never invoked, so its role is irrelevant to the triggering issue. Option D is wrong because VPC Flow Logs are not required for GuardDuty to generate findings or for CloudWatch Events to receive them; GuardDuty uses multiple data sources (DNS logs, VPC Flow Logs, CloudTrail logs) but the absence of VPC Flow Logs does not prevent findings from being sent to CloudWatch Events.

119
MCQhard

A Security Engineer is troubleshooting why AWS CloudTrail is not delivering logs to an S3 bucket. The bucket policy allows CloudTrail access. What is a likely cause of the issue?

A.The S3 bucket uses SSE-KMS and the key policy does not grant CloudTrail permission
B.The S3 bucket has a lifecycle policy that deletes objects too quickly
C.CloudTrail is not enabled in the region
D.The S3 bucket is in a different region than the trail
AnswerA

CloudTrail requires explicit kms:GenerateDataKey and kms:Decrypt permissions on the customer managed KMS key used for SSE-KMS encryption of the S3 bucket. If the key policy grants these actions only to the bucket owner or other principals, CloudTrail's delivery role is denied and PutObject calls fail with an access denied error. This is a common cause of CloudTrail logs not appearing while the trail itself remains active.

Why this answer

When an S3 bucket uses SSE-KMS (Server-Side Encryption with AWS KMS), CloudTrail must have explicit permissions in the KMS key policy to decrypt the key and encrypt log files. Even if the S3 bucket policy grants CloudTrail access, the KMS key policy is a separate authorization layer; without a statement allowing CloudTrail to use the kms:GenerateDataKey and kms:Decrypt actions, log delivery will fail silently or with access denied errors.

Exam trap

The trap here is that candidates assume the S3 bucket policy is the only authorization layer, overlooking that KMS key policies act as an independent permission boundary when SSE-KMS is used, leading them to choose incorrect options like cross-region or lifecycle issues.

How to eliminate wrong answers

Option B is wrong because a lifecycle policy that deletes objects too quickly would cause logs to be removed after delivery, not prevent delivery itself; CloudTrail would still successfully deliver logs initially. Option C is wrong because CloudTrail must be enabled in the region where the trail is created, but the question states the trail exists and is not delivering logs, implying it is enabled; the issue is not about enabling the service. Option D is wrong because CloudTrail can deliver logs to an S3 bucket in a different region; cross-region delivery is supported and not a cause of delivery failure.

120
MCQmedium

A company has enabled CloudTrail in all regions and is logging to a single S3 bucket. The security team needs to ensure that any attempted deletion of CloudTrail logs generates an immediate alert. Which solution meets this requirement?

A.Configure an S3 event notification on the bucket for s3:ObjectRemoved:* events, invoke a Lambda function to publish to an SNS topic.
B.Use AWS Config to create a rule that checks for deleted objects and sends an SNS notification.
C.Enable CloudTrail Insights to detect unusual deletion activity and send alerts.
D.Create a CloudWatch Logs metric filter on the CloudTrail log group for DeleteObject events and trigger an alarm.
AnswerA

S3 event notifications are delivered in near-real-time directly from the bucket for object-level actions. By subscribing to s3:ObjectRemoved:* events, the Lambda function is invoked immediately upon a delete or delete-marker creation, then publishes to SNS for alerting. This bypasses the multi-minute delivery latency of CloudTrail logs and does not require any additional monitoring infrastructure.

Why this answer

S3 event notifications can be configured to trigger a Lambda function on `s3:ObjectRemoved:*` events, which captures all object deletion actions (including DeleteObject and DeleteObjects API calls). The Lambda function can then publish a message to an SNS topic, enabling immediate alerting. This approach provides real-time, event-driven monitoring directly from S3, without relying on CloudTrail log ingestion delays.

Exam trap

The trap here is that candidates may assume CloudTrail Insights or CloudWatch Logs metric filters are the correct real-time alerting mechanisms, but they overlook the inherent latency in CloudTrail log delivery and the fact that S3 event notifications provide immediate, event-driven triggers for object deletions.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource configurations against desired policies, but they do not monitor real-time object deletion events; Config checks configuration changes periodically (e.g., every 10 minutes) and cannot provide immediate alerts for individual object deletions. Option C is wrong because CloudTrail Insights detects unusual API activity patterns (e.g., anomalous volume of calls) but does not generate alerts for every single deletion event; it is designed for anomaly detection, not real-time per-event alerting. Option D is wrong because CloudTrail logs are delivered to S3, not to a CloudWatch Logs log group by default; you would need to set up a separate CloudWatch Logs subscription to stream CloudTrail logs, and even then, metric filters on CloudWatch Logs introduce latency (up to several minutes) and do not provide immediate alerting for each deletion.

121
MCQhard

A security engineer is investigating a potential compromise. They notice that an IAM user 'svc-backup' has been making unusual API calls from an IP address outside the company's VPC. The engineer wants to ensure all future API calls from this user are logged with full event details. However, the current CloudTrail trail is set to log only management events. What should the engineer do to capture the required details?

A.Enable VPC Flow Logs and correlate with CloudTrail logs.
B.Update the existing trail to log data events for IAM.
C.Create a new trail that logs data events for S3 and configure it to deliver to a separate S3 bucket.
D.Enable CloudTrail Insights to detect unusual activity for the user.
AnswerB

Updating the existing trail to log data events for IAM captures the exact API calls needed for the investigation, including GetUser, ListAccessKeys, GetLoginProfile, and other IAM data-plane operations. By default, a trail only records management events, so these data events are absent unless you explicitly add an event selector for the IAM resource type. Doing this on the existing trail preserves the current delivery configuration and eliminates the need for a separate, redundant trail, giving investigators a direct, complete audit of the user's activity.

Why this answer

CloudTrail trails configured to log only management events do not capture IAM user activity such as API calls made by the user. By updating the existing trail to log data events for IAM, the engineer ensures that all future API calls from 'svc-backup' are logged with full event details, including the source IP address and request parameters. This directly addresses the requirement without creating unnecessary additional trails or services.

Exam trap

The trap here is that candidates often confuse 'data events' with only S3 object-level operations, forgetting that IAM also has data events that must be explicitly enabled to capture user-level API calls.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log IAM API call details or user identity information, so they cannot provide the required event details. Option C is wrong because the unusual API calls are from an IAM user, not from S3; logging data events for S3 would capture S3 object-level operations but not IAM API calls made by the user. Option D is wrong because CloudTrail Insights detects unusual activity patterns based on existing logged events, but it does not enable logging of data events; it only analyzes management events already being logged, so it would not capture the missing data event details.

122
MCQeasy

A DevOps engineer needs to monitor failed SSH login attempts to Amazon EC2 instances. Which AWS service should the engineer use to collect and analyze the login events?

A.AWS Config
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.VPC Flow Logs
AnswerB

Amazon CloudWatch Logs is the correct choice because the CloudWatch agent (or the legacy Logs agent) can be installed on an EC2 instance to tail local system logs, including /var/log/auth.log on Amazon Linux or /var/log/secure on RHEL/CentOS. Once collected, you can define a metric filter to match patterns such as 'Failed password' or 'Connection refused' that sshd emits on failed attempts, and then trigger alarms based on those metrics. This directly captures the OS-level authentication events needed to monitor failed SSH logins.

Why this answer

Amazon CloudWatch Logs is the correct service because it can ingest, monitor, and analyze log data from EC2 instances, including SSH authentication logs (e.g., /var/log/secure or /var/log/auth.log). By installing the CloudWatch Logs agent on the EC2 instance, the engineer can stream these log events to CloudWatch Logs, where they can be searched, visualized, and used to trigger alarms on failed SSH attempts. AWS Config tracks resource configuration changes, not OS-level login events; CloudTrail records AWS API calls, not guest OS logs; and VPC Flow Logs capture network traffic metadata, not application or authentication logs.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs AWS API calls) with OS-level auditing, mistakenly thinking CloudTrail captures guest OS login events, when in fact CloudTrail only records control-plane actions and never sees inside the instance's operating system.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating and recording changes to AWS resource configurations (e.g., security group rules, instance types), not for collecting or analyzing OS-level login events like SSH attempts. Option C is wrong because AWS CloudTrail logs API calls made to the AWS control plane (e.g., RunInstances, DescribeInstances), not guest OS activities such as SSH logins, which occur within the instance's operating system. Option D is wrong because VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces (e.g., source/destination IP, ports, protocol), but they do not log application-layer events like SSH authentication successes or failures.

123
MCQeasy

A security engineer needs to monitor for suspicious API calls in near real-time and trigger an automated response. Which AWS service should be used to capture and analyze these API calls?

A.AWS CloudHSM
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
AnswerC

CloudTrail records API activity across the account, capturing who called which AWS API, from where, and when. Its event history and trail delivery to CloudWatch Logs or EventBridge enable near-real-time detection and automated response to suspicious calls.

Why this answer

AWS CloudTrail is the correct service because it captures all API calls made to the AWS environment, including those from the AWS Management Console, SDKs, CLI, and AWS services. By enabling CloudTrail Insights or using CloudWatch Events with CloudTrail logs, you can monitor for suspicious API calls in near real-time and trigger automated responses via Lambda functions or SNS notifications.

Exam trap

The trap here is that candidates confuse GuardDuty's threat detection capabilities with the actual capture of API calls, forgetting that GuardDuty consumes CloudTrail logs rather than generating them, so the service that captures the calls is CloudTrail, not GuardDuty.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware security modules for cryptographic key storage and operations, not for monitoring or analyzing API calls. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, but it does not natively capture API calls itself—it relies on CloudTrail as a data source, and the question asks for the service that captures and analyzes the calls, not just analyzes them. Option D is wrong because AWS Config evaluates resource configurations against desired policies and tracks configuration changes, but it does not capture or analyze API calls; it focuses on resource state, not the API actions that led to that state.

124
MCQeasy

A security engineer needs to monitor for failed SSH login attempts to EC2 instances and send alerts. Which combination of AWS services should be used?

A.VPC Flow Logs and Amazon Athena.
B.AWS CloudTrail and Amazon SNS.
C.Amazon S3 event notifications and AWS Lambda.
D.CloudWatch Logs agent on EC2, CloudWatch Logs metric filter, and CloudWatch Alarm.
AnswerD

The CloudWatch Logs agent installed on the EC2 instance can tail OS-level log files such as /var/log/secure or /var/log/auth.log and continuously stream those events to CloudWatch Logs. A CloudWatch Logs metric filter can then be configured with a pattern like 'Failed password for' or 'authentication failure' to count each failed SSH login attempt into a custom metric. A CloudWatch Alarm associated with that metric can trigger when the count breaches a threshold—for instance, 5 failures in 5 minutes—and then invoke an SNS topic or other action. This captures exactly the OS-level authentication signal needed to detect brute-force or failed SSH login events.

Why this answer

The CloudWatch Logs agent on EC2 can stream SSH auth logs (e.g., /var/log/secure or /var/log/auth.log) to CloudWatch Logs. A metric filter can then parse these logs for failed SSH login patterns (e.g., 'Failed password'), and a CloudWatch Alarm can trigger an SNS notification or other action when the metric exceeds a threshold. This combination directly monitors OS-level authentication events, which is required for detecting failed SSH attempts.

Exam trap

The trap here is that candidates confuse AWS-managed logging services (CloudTrail, VPC Flow Logs) with OS-level logging, assuming CloudTrail captures all security events, when in fact it only records AWS API calls, not guest OS authentication attempts.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network-level metadata (IP addresses, ports, protocols) but do not log application-layer authentication events like SSH login success or failure; Athena can query flow logs but cannot extract SSH auth outcomes. Option B is wrong because AWS CloudTrail records API calls to the AWS control plane (e.g., EC2 RunInstances) but does not log guest OS-level SSH login attempts within an EC2 instance. Option C is wrong because S3 event notifications trigger on object-level events in S3 buckets, not on EC2 instance logs; while Lambda could process logs, there is no mechanism to capture SSH auth logs from EC2 instances without an agent or direct log delivery.

125
Multi-Selecteasy

Which TWO AWS services can be used to centrally collect and analyze logs from multiple AWS accounts? (Select TWO.)

Select 2 answers
A.AWS Config
B.Amazon Athena (to query logs in S3)
C.Amazon S3 (as a central log repository)
D.Amazon Inspector
E.AWS Shield
AnswersB, C

Amazon Athena is an interactive serverless query service that runs standard SQL directly against data stored in Amazon S3. After logs from multiple accounts are centrally delivered to an S3 bucket, Athena can query those logs (e.g., CloudTrail, VPC Flow Logs, ALB logs) without loading them into a database or managing infrastructure. It complements S3 as the storage layer by providing the analysis capability needed to search and correlate log data, making it a correct answer for centrally collecting and analyzing logs.

Why this answer

Amazon S3 can serve as a centralized log repository by aggregating logs from multiple AWS accounts using cross-account S3 bucket policies. Amazon Athena can then query those logs directly in S3 using standard SQL, enabling centralized analysis without moving data. Together, they provide a scalable, serverless solution for multi-account log collection and analysis.

Exam trap

The trap here is that candidates often mistake AWS Config for a log collection service because it records configuration changes, but it does not aggregate or analyze logs from multiple accounts; it only provides per-account configuration history and compliance rules.

126
MCQhard

A company is using AWS CloudTrail to log all management events and has enabled log file validation. What additional security benefit does log file validation provide?

A.It ensures the integrity of the log files by detecting tampering.
B.It prevents anyone from deleting the log files.
C.It encrypts the log files at rest.
D.It provides real-time monitoring for API calls.
AnswerA

CloudTrail log file integrity validation uses a SHA-256 hash chain, where each delivered log file references the hash of the previous file. This cryptographic digest is computed on the log file and stored in a separate digest file (optionally encrypted with the customer's KMS key), allowing you to detect any tampering or modification of log files after delivery. It confirms authenticity and integrity, not prevention of actions.

Why this answer

Log file validation uses a digital signature (SHA-256 hash) created for each log file, which is stored in a separate digest file. When validation is enabled, CloudTrail automatically creates a hash for each log file and signs it with a private key, allowing you to verify that the log files have not been modified, deleted, or tampered with after they were delivered. This ensures the integrity of the log files by detecting any unauthorized changes.

Exam trap

The trap here is that candidates often confuse log file validation with other security features like encryption, deletion prevention, or real-time monitoring, but the exam specifically tests whether you understand that validation is solely about integrity (detecting tampering) and not about confidentiality, availability, or alerting.

How to eliminate wrong answers

Option B is wrong because log file validation does not prevent deletion of log files; deletion prevention is achieved through S3 bucket policies, MFA delete, or S3 Object Lock, not through CloudTrail's validation feature. Option C is wrong because encryption at rest is provided by S3 server-side encryption (SSE-S3, SSE-KMS, or SSE-C) or CloudTrail's optional SSE-KMS integration, not by log file validation. Option D is wrong because real-time monitoring for API calls is provided by CloudTrail Lake, CloudWatch Events, or EventBridge, not by log file validation, which is an integrity check performed after log delivery.

127
Multi-Selecteasy

A company needs to monitor its AWS environment for compliance with the CIS AWS Foundations Benchmark. The security team wants to automatically check for non-compliant resources and receive reports. Which THREE services should be used together to meet these requirements? (Choose THREE.)

Select 2 answers
A.Amazon Detective
B.AWS Security Hub
C.AWS Config
D.Amazon GuardDuty
E.Amazon Macie
AnswersB, C

Correct. Security Hub is the central hub for compliance status, aggregating findings from AWS Config and GuardDuty, and providing reports on CIS benchmark compliance.

Why this answer

AWS Security Hub (B) is correct because it natively supports the CIS AWS Foundations Benchmark as a security standard, aggregates findings from integrated services, and generates compliance scores and reports against that benchmark. AWS Config (C) is correct because it provides configuration recording and managed/custom rules that evaluate resource compliance, and Security Hub's CIS standard relies on AWS Config rules to assess many controls. Amazon GuardDuty (D) is not required for CIS AWS Foundations Benchmark compliance checking or reporting; it is a threat-detection service whose findings can be viewed in Security Hub but does not evaluate CIS controls.

Amazon Detective (A) is used for investigating and visualizing security findings after they occur, and Amazon Macie (E) discovers and classifies sensitive data in S3; neither is part of the CIS compliance-checking and reporting workflow.

Exam trap

The trap is that candidates often confuse threat-detection services (GuardDuty, Detective, Macie) with compliance monitoring services. Security Hub is the central place for aggregating and reporting on compliance standards like CIS, and AWS Config provides the underlying rule evaluation engine. GuardDuty findings do not check CIS controls or produce CIS compliance reports.

128
MCQmedium

Refer to the exhibit. A security engineer configured this S3 bucket policy for CloudTrail, but CloudTrail logs are not being delivered. What is the MOST likely missing permission?

A.Missing s3:GetBucketAcl permission.
B.The condition StringEquals should be StringLike.
C.Missing s3:PutObject permission for the bucket.
D.The bucket ARN is incorrect.
AnswerC

CloudTrail delivers log files by writing objects into the bucket, so the bucket policy must grant the CloudTrail service principal s3:PutObject on the target prefix. Without that write action, delivery fails regardless of ACLs or ownership controls, which only govern access to objects already written.

Why this answer

For CloudTrail to deliver logs to an S3 bucket, the bucket policy must grant CloudTrail the s3:PutObject permission on the bucket's objects (the /* ARN), in addition to s3:GetBucketAcl on the bucket itself. The exhibit's policy is missing the s3:PutObject statement, so CloudTrail cannot write log files even though it can check the bucket ACL. This is the most likely missing permission.

Exam trap

SCS-C02 often tests the misconception that s3:GetBucketAcl alone is sufficient for CloudTrail delivery, when the critical missing permission is s3:PutObject on the bucket objects ARN.

How to eliminate wrong answers

Option A is wrong because s3:GetBucketAcl is typically already present in a correct CloudTrail bucket policy and is not the missing piece — the exhibit shows the ACL check is not the blocker. Option B is wrong because the StringEquals vs StringLike condition is not the cause of delivery failure; the condition operator affects matching of the source ARN but the fundamental missing permission is PutObject. Option D is wrong because an incorrect bucket ARN would cause a different error and is not the most likely missing permission given the scenario focuses on permissions.

129
MCQhard

Refer to the exhibit. The security team is investigating a security incident in us-west-2 region. They notice that management events from us-west-2 are not appearing in the CloudTrail logs. Based on the exhibit, what is the most likely reason?

A.The S3 bucket is in a different region
B.The trail is not logging data events
C.The trail is not a multi-region trail
D.The trail does not have log file validation enabled
AnswerC

A single-region trail only records management events that occur in the same region where the trail is defined. Events happening in other regions are not captured at all unless the trail is configured as a multi-region trail, which creates equivalent trails in every region. Since the security team is investigating events from another region, the lack of a multi-region configuration directly explains the gap.

Why this answer

The exhibit shows a single-region CloudTrail trail. A single-region trail only logs events in the region where it is created. Since management events from us-west-2 are not appearing, the trail must have been created in a different region.

To capture events from us-west-2, the trail would need to be multi-region. Therefore, the most likely reason is that the trail is not a multi-region trail.

Exam trap

The trap is that candidates might assume a trail in the same region as the incident automatically captures all events, but the exhibit likely shows a trail in a different region. A single-region trail only captures events from its own region, so to capture events from us-west-2, the trail must be multi-region or a separate trail must exist in us-west-2.

How to eliminate wrong answers

Option A is wrong because an S3 bucket in a different region does not prevent CloudTrail from delivering logs; CloudTrail can deliver logs to an S3 bucket in any region, and the logs would still contain management events from us-west-2. Option B is wrong because data events are separate from management events; the trail not logging data events would not affect the delivery of management events, which are logged by default unless explicitly excluded. Option D is wrong because log file validation is a security feature that ensures log integrity but does not affect whether events are captured or delivered; it only validates that log files have not been tampered with after delivery.

130
MCQmedium

Refer to the exhibit. A security engineer configured this S3 bucket policy to allow CloudTrail to deliver logs. However, logs are not being delivered. What is the MOST likely reason?

A.The Resource should be arn:aws:s3:::my-trail-bucket/*, not with AWSLogs prefix.
B.The Principal is set to a service, but must be an AWS account ID.
C.The Action should be s3:GetObject, not s3:PutObject.
D.The policy is missing s3:GetBucketAcl permission for CloudTrail.
AnswerD

The missing permission is s3:GetBucketAcl, and without it CloudTrail will reject the bucket even though PutObject is allowed. Before writing its first log, CloudTrail calls GetBucketAcl on the destination bucket to confirm the bucket's owner, and the bucket policy must explicitly grant that action to the cloudtrail service principal. If the bucket ACL check fails, CloudTrail returns an error such as 'bucket does not exist or bucket ACL does not allow access' and log delivery halts. This permission is a separate, required statement from the object-write permission.

Why this answer

CloudTrail requires the s3:GetBucketAcl permission on the S3 bucket to verify that the bucket policy grants the necessary access for log delivery. Without this permission, CloudTrail cannot confirm it has write access, and log delivery fails even if s3:PutObject is allowed. Option D correctly identifies this missing permission as the root cause.

Exam trap

The trap here is that candidates focus on the obvious s3:PutObject action and overlook the prerequisite s3:GetBucketAcl permission, which CloudTrail requires for its initial access validation.

How to eliminate wrong answers

Option A is wrong because the Resource ARN with the AWSLogs prefix is correct for CloudTrail log delivery; CloudTrail writes logs to the AWSLogs/<account-id>/CloudTrail/ path, so the policy must restrict access to that prefix to follow security best practices. Option B is wrong because CloudTrail uses a service principal (cloudtrail.amazonaws.com) in the Principal field, not an AWS account ID, which is the standard and correct configuration. Option C is wrong because CloudTrail delivers logs by writing (putting) objects to the bucket, so s3:PutObject is the required action, not s3:GetObject.

131
MCQeasy

A company uses Amazon RDS for MySQL and wants to monitor database activity for security analysis. Which AWS service should be used to capture detailed database activity logs such as login attempts and query execution?

A.AWS CloudTrail
B.Amazon RDS Enhanced Monitoring
C.AWS Config
D.Amazon RDS Database Activity Streams
AnswerD

Amazon RDS Database Activity Streams captures database activity at the engine level, including every SQL statement, authenticated user, client IP, session ID, and execution timestamp, and pushes it as a near-real-time stream to Amazon Kinesis. From Kinesis, the stream can be consumed by external audit, security, or monitoring tools to alert on suspicious queries or maintain an audit trail. This is exactly the capability needed to monitor database queries in real time, making it the correct answer.

Why this answer

Amazon RDS Database Activity Streams is the correct service because it captures a near-real-time stream of database activity, including login attempts, query execution, and other operations at the database engine level. It integrates with AWS CloudWatch and third-party monitoring tools, providing granular audit logs for security analysis that go beyond what CloudTrail or Enhanced Monitoring offer.

Exam trap

The trap here is confusing AWS CloudTrail (which logs control-plane API calls) with database-level activity logging, leading candidates to choose CloudTrail when they need internal database audit trails.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls made to the RDS service (e.g., creating or modifying DB instances), not the internal database activity like SQL queries or login attempts. Option B is wrong because Amazon RDS Enhanced Monitoring provides OS-level metrics (CPU, memory, disk I/O) from the hypervisor, not database-level audit logs. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not real-time database activity or query logs.

132
MCQeasy

A company wants to centralize logs from multiple AWS accounts into a single S3 bucket for analysis. The accounts are part of an AWS Organizations organization. Which set of steps will accomplish this?

A.Create an organization trail in the management account with logging enabled for all accounts.
B.Use AWS Config to aggregate logs from all accounts into a central S3 bucket.
C.Create a CloudTrail trail in each account and configure each to write to the same S3 bucket.
D.Set up Amazon Kinesis Data Firehose in each account to stream logs to a central S3 bucket.
AnswerA

CloudTrail organization trails are created in the management account and automatically apply to every account in AWS Organizations, delivering all account logs to a single S3 bucket without per-account configuration. This is the native mechanism for centralizing management-event logging across an organization, and the management account owns and controls the trail. Because the trail is organization-wide, you get consistent logging coverage and centralized governance.

Why this answer

AWS Organizations allows you to create an organization trail from the management account. When you enable logging for all accounts in the organization, CloudTrail automatically creates a trail that applies to every account in the organization, delivering log files from all accounts to a single S3 bucket without needing per-account configuration.

Exam trap

The trap here is that candidates often assume each account must individually configure CloudTrail to write to a shared bucket, overlooking the organization trail feature that automates multi-account log centralization through AWS Organizations.

How to eliminate wrong answers

Option B is wrong because AWS Config aggregates configuration items and compliance snapshots, not CloudTrail logs; it is designed for resource configuration tracking, not centralized log delivery. Option C is wrong because while each account can write to the same S3 bucket, this approach requires manual setup per account, does not leverage Organizations for automatic multi-account management, and can lead to permission conflicts or log delivery failures without proper bucket policies. Option D is wrong because Amazon Kinesis Data Firehose is a streaming data delivery service, not a native CloudTrail log destination; CloudTrail cannot directly send logs to Firehose without additional configuration, and this approach does not provide the centralized, automatic trail management that an organization trail offers.

133
MCQhard

A company is using AWS CloudTrail to monitor API activity. The security team wants to be alerted when an IAM user creates a new access key. Which CloudTrail event should be used to create a CloudWatch Events rule?

A.EnableMFADevice
B.UpdateAccessKey
C.UploadSigningCertificate
D.CreateAccessKey
AnswerD

The CreateAccessKey event is logged by CloudTrail when an IAM user or role calls the CreateAccessKey API to generate a new access key pair. This is precisely the event that indicates creation of a new access key, making it the correct answer. Note that while CloudTrail records the access key ID in the event, the secret access key is not logged; it is displayed only once at creation time. This event is also useful for detecting unauthorized credential creation.

Why this answer

The correct event is CreateAccessKey because this is the specific CloudTrail event that is logged when an IAM user creates a new access key. CloudTrail captures this API call as a management event, and a CloudWatch Events rule can be configured to match this event name to trigger an alert. The security team's requirement is to detect the creation of access keys, which is directly represented by the CreateAccessKey event.

Exam trap

The trap here is that candidates may confuse UpdateAccessKey with CreateAccessKey, thinking that updating a key includes creation, but UpdateAccessKey only modifies the key's status (e.g., Active/Inactive) and does not generate a new key pair.

How to eliminate wrong answers

Option A is wrong because EnableMFADevice is the event for enabling a multi-factor authentication device on an IAM user, not for creating an access key. Option B is wrong because UpdateAccessKey is the event for changing the status of an access key (e.g., Active to Inactive), not for creating a new one. Option C is wrong because UploadSigningCertificate is the event for uploading an X.509 signing certificate, which is unrelated to access key creation.

134
Multi-Selectmedium

Which TWO actions should a security engineer take to ensure that Amazon GuardDuty can effectively monitor for suspicious activity in a VPC? (Choose two.)

Select 2 answers
A.Enable DNS query logging and publish to CloudWatch Logs.
B.Enable VPC Flow Logs and publish to CloudWatch Logs.
C.Enable CloudTrail data events for S3.
D.Enable S3 server access logs.
E.Enable AWS Config configuration history.
AnswersA, B

GuardDuty uses DNS logs for domain-based threat detection.

Why this answer

Amazon GuardDuty relies on DNS query logs to detect suspicious domain name resolution patterns, such as DNS tunneling or communication with known malicious domains. By enabling DNS query logging and publishing to CloudWatch Logs, GuardDuty can ingest this data as a source for its threat detection algorithms. Without DNS logs, GuardDuty cannot analyze DNS-based attack vectors within the VPC.

Exam trap

The trap here is that candidates often think enabling CloudTrail or S3 logs is sufficient for VPC monitoring, but GuardDuty specifically requires VPC Flow Logs and DNS query logs as its primary network-based data sources for detecting suspicious VPC activity.

135
MCQeasy

A company wants to detect and alert on unauthorized API calls in their AWS account. Which AWS service can provide real-time notifications when specific API calls are made?

A.AWS Config
B.Amazon CloudWatch Events (EventBridge)
C.Amazon GuardDuty
D.AWS Trusted Advisor
AnswerB

Amazon EventBridge (formerly CloudTrail Events integration within CloudWatch Events) is the appropriate real-time service because it can consume CloudTrail API-call events and pattern-match on fields like eventName, userIdentity, errorCode, and sourceIPAddress. You can create a rule with a custom event pattern—for example, source: 'aws.cloudtrail' and eventName: 'DeleteBucket'—and route matching events to SNS, Lambda, or CloudWatch Logs to trigger alerts. This gives near-instant, event-driven detection of unauthorized API attempts, including filtered access-denied events.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture real-time API calls made to AWS services by using a rule that matches specific API calls via CloudTrail integration. When a matching API call occurs, EventBridge can trigger a target such as an SNS topic or Lambda function to send a notification, enabling immediate alerting on unauthorized API calls.

Exam trap

The trap here is that candidates often confuse AWS Config's configuration change detection with real-time API call monitoring, but Config evaluates resource state changes at intervals or on configuration changes, not the API calls themselves, whereas EventBridge provides immediate, event-driven notification of specific API actions.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes over time, not for real-time notification of specific API calls. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide direct, customizable real-time notifications for arbitrary API calls; it focuses on anomaly detection rather than event-driven alerting on specific API actions. Option D is wrong because AWS Trusted Advisor provides best-practice recommendations for cost optimization, performance, security, and fault tolerance, but it does not monitor or alert on real-time API calls.

136
MCQmedium

A company uses AWS CloudTrail to log all API calls. The security team wants to ensure that any attempt to disable CloudTrail logging is detected and alerted within minutes. Which solution should they implement?

A.Create a CloudWatch metric filter on CloudTrail logs for StopLogging or DeleteTrail events and set an alarm.
B.Use Amazon GuardDuty to monitor for disablement events.
C.Create an AWS Config rule to detect when CloudTrail is disabled.
D.Configure S3 event notifications on the CloudTrail bucket.
AnswerA

A CloudWatch metric filter can inspect CloudTrail events as they are streamed to a CloudWatch Logs log group and match the eventName field for StopLogging or DeleteTrail API calls. When the filter's metric value changes, a CloudWatch alarm triggers immediately, enabling a real-time response before the trail is completely stopped or deleted. This approach directly monitors the management events that disable auditing, without relying on secondary indicators like object delivery. It also supports optional SNS notifications and Lambda actions for automated remediation.

Why this answer

CloudTrail logs API calls like `StopLogging` and `DeleteTrail` to CloudWatch Logs. By creating a metric filter on these specific event names and setting a CloudWatch alarm, the security team can receive near-real-time alerts within minutes of any attempt to disable CloudTrail logging, meeting the detection requirement.

Exam trap

The trap here is that candidates often confuse AWS Config's periodic evaluation with real-time CloudWatch alarm capabilities, or mistakenly think GuardDuty's threat detection includes specific API-level alerts for CloudTrail disablement, when in fact GuardDuty does not generate findings for these specific management events by default.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail management events for malicious activity, but it does not provide a native, configurable alarm for specific CloudTrail disablement events like StopLogging or DeleteTrail; it focuses on broader threats rather than this specific compliance alert. Option C is wrong because AWS Config rules are designed for continuous compliance evaluation of resource configurations (e.g., whether CloudTrail is enabled) and typically run on a periodic basis (e.g., every hour or on configuration changes), not for real-time alerting within minutes of an API call. Option D is wrong because S3 event notifications on the CloudTrail bucket can trigger on object creation (e.g., new log files), but they cannot directly detect the CloudTrail API calls that disable logging; they only react to log file delivery, not the disabling action itself.

137
MCQhard

A security engineer is investigating a potential security incident. They suspect that an IAM user's credentials were compromised and used to launch EC2 instances in a region where the user normally does not operate. Which AWS service can help the engineer identify the source IP address and user agent of the API calls that launched the instances?

A.AWS CloudHSM
B.AWS CloudTrail
C.Amazon Inspector
D.AWS Artifact
AnswerB

CloudTrail is the correct answer because it records API activity across AWS accounts, capturing details like source IP address, user agent, request parameters, and response elements. This enables security engineers to investigate potential security incidents by correlating who made the call, from what IP, and with what tool. CloudTrail events provide the forensic evidence needed to trace actions.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including the source IP address, user agent, and the identity of the caller. By examining CloudTrail logs for the `RunInstances` event, the engineer can identify the exact source IP address and user agent used to launch the EC2 instances, even if the region is unusual for the user.

Exam trap

The trap here is that candidates may confuse CloudTrail with CloudWatch or other monitoring services, but CloudTrail is the only service that records the source IP and user agent of API calls, while CloudWatch focuses on metrics and logs from resources, not API call metadata.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM is a hardware security module service for managing encryption keys, not a logging or monitoring service; it cannot capture API call metadata like source IP or user agent. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and workloads for software vulnerabilities and unintended network exposure, but it does not record API call history or source IP addresses. Option D is wrong because AWS Artifact is a self-service portal for downloading AWS compliance reports and agreements, such as SOC and PCI reports; it provides no operational logging or API call tracking capabilities.

138
MCQeasy

A security engineer wants to receive real-time notifications when an AWS API call is made to delete an S3 bucket. Which service should be used to capture and forward these events to an Amazon SNS topic?

A.AWS CloudTrail with CloudWatch Events
B.AWS Trusted Advisor
C.Amazon GuardDuty
D.AWS Config
AnswerA

AWS CloudTrail with CloudWatch Events is the correct choice because CloudTrail records all AWS API calls as events, and CloudWatch Events (now Amazon EventBridge) can evaluate those events in near real time using an event pattern that matches specific actions like S3 DeleteBucket. When the pattern matches, it immediately triggers an SNS topic to send notifications. This architecture gives you direct, low-latency alerting on API activity, which is exactly what the security engineer needs. Unlike the other options, it is purpose-built for reacting to individual API calls as they happen.

Why this answer

AWS CloudTrail captures all API calls made to S3, including DeleteBucket. By sending these CloudTrail events to Amazon CloudWatch Events (now part of Amazon EventBridge), you can create a rule that matches the specific API call and forwards it to an SNS topic for real-time notification. This combination provides the exact event-driven pipeline needed for immediate alerting on S3 bucket deletions.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to detect configuration changes with the need for real-time API call capture, leading them to choose AWS Config instead of CloudTrail with CloudWatch Events.

How to eliminate wrong answers

Option B is wrong because AWS Trusted Advisor provides best-practice recommendations and cost optimization checks, but it does not capture or forward real-time API events. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not directly forward specific API calls to SNS topics. Option D is wrong because AWS Config evaluates resource configurations and compliance rules, but it does not capture real-time API calls or forward them to SNS; it focuses on configuration changes and drift detection.

139
MCQeasy

A security engineer needs to detect when an IAM access key is created for a user and then used from an unusual location. The engineer wants to receive an alert when such activity occurs. Which AWS service should be used to meet this requirement?

A.Amazon Inspector
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerC

GuardDuty continuously monitors CloudTrail management events, VPC Flow Logs, and DNS logs to detect threats. It can identify anomalous behavior such as an IAM access key being used from an unusual geographic location. GuardDuty generates findings that can trigger alerts via CloudWatch Events or SNS, meeting the requirement.

Why this answer

Amazon GuardDuty is a threat detection service that analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to identify malicious or anomalous activity. It can detect unusual access key usage from unexpected locations and generate findings that can be routed to alerting systems. CloudTrail, AWS Config, and Amazon Inspector do not provide this threat detection and alerting capability.

Exam trap

The trap here is assuming that CloudTrail, which records the API calls, also performs the analysis and alerting; in fact, GuardDuty is the service that analyzes those logs and generates findings.

140
Multi-Selecthard

A security engineer is investigating a potential data breach. The engineer wants to analyze historical API calls made by a specific IAM user. Which TWO AWS services can be used together to achieve this? (Select TWO.)

Select 2 answers
A.S3 Server Access Logs
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs Insights
E.Amazon CloudWatch Logs
AnswersC, E

AWS CloudTrail is the authoritative audit service because it logs every supported AWS API call (management events, and optionally data events) with the caller's IAM identity, source IP address, user agent, request parameters, and response elements. A CloudTrail event history can be delivered to an S3 bucket and subsequently ingested into CloudWatch Logs or Amazon Security Lake, making it the primary evidence source for reconstructing who did what during a breach. It is the correct service to use when investigating suspicious API activity.

Why this answer

AWS CloudTrail is the service that records API activity across AWS accounts, including who made the call, the source IP address, and the time of the call. By enabling CloudTrail for the specific IAM user, the security engineer can retrieve a history of all API calls made by that user. CloudWatch Logs can then be used to store and query those CloudTrail logs for analysis, such as filtering by user ARN or event name.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs Insights (a query tool) with CloudWatch Logs (the storage service), or mistakenly think S3 Server Access Logs or VPC Flow Logs can capture IAM user API activity, when in fact only CloudTrail records management-plane API calls.

141
MCQeasy

A company uses AWS CloudTrail to log all API calls in their AWS account. They need to ensure that log files are not tampered with after they are delivered to the S3 bucket. Which feature should be enabled to provide integrity validation?

A.Enable S3 Versioning on the CloudTrail bucket.
B.Enable S3 server-side encryption with SSE-S3.
C.Enable CloudTrail log file integrity validation.
D.Enable S3 Object Lock on the CloudTrail bucket.
AnswerC

CloudTrail log file integrity validation is the correct choice because it provides cryptographic verification of the log files: every log file's SHA-256 hash is included in a separate, frequently issued digest file that is signed with a private key. This hash chain lets you detect whether a log file was modified, deleted, or replaced after CloudTrail delivered it, and you can verify digests using the public key that CloudTrail publishes. Because an attacker would need the private key to forge a valid digest, this feature directly satisfies the requirement to determine whether CloudTrail logs have been tampered with.

Why this answer

CloudTrail log file integrity validation uses a SHA-256 hash chain to detect if log files have been modified, deleted, or tampered with after delivery to S3. When enabled, CloudTrail delivers a digest file that contains hashes of the log files, allowing you to verify that no unauthorized changes have occurred. This is the only feature specifically designed for integrity validation of CloudTrail logs.

Exam trap

The trap here is that candidates often confuse data protection features like encryption or versioning with integrity validation, but only CloudTrail's built-in integrity validation provides cryptographic proof that log files have not been tampered with after delivery.

How to eliminate wrong answers

Option A is wrong because S3 Versioning preserves multiple versions of an object but does not validate the integrity or detect tampering of the log file content itself. Option B is wrong because S3 server-side encryption (SSE-S3) protects data at rest from unauthorized access but does not provide any mechanism to verify that the log files have not been altered after delivery. Option D is wrong because S3 Object Lock prevents objects from being deleted or overwritten for a fixed retention period, but it does not validate the integrity or detect modifications to the content of the log files.

142
Multi-Selecthard

A company wants to use AWS CloudTrail to monitor data events for all S3 buckets. Which THREE steps are necessary? (Choose THREE.)

Select 3 answers
A.Specify an S3 bucket to store the log files
B.Create a new CloudTrail trail
C.Create a CloudWatch Events rule to forward data events
D.Enable CloudTrail Insights to detect unusual data access
E.Enable data events for all S3 buckets in the trail configuration
AnswersA, B, E

CloudTrail delivers all log records, including the enabled S3 data events, to the S3 bucket you specify when creating the trail. This bucket is the required durable destination for log file storage, and without it, event history is limited to 90 days and cannot be exported or integrated with other analytics tools.

Why this answer

CloudTrail requires a destination S3 bucket to store the log files it generates. Without specifying a bucket, the trail cannot persist logs, and this bucket must have appropriate bucket policies to allow CloudTrail to write logs. This is a mandatory step when creating any trail, whether for management or data events.

Exam trap

The trap here is that candidates often confuse CloudTrail Insights (which analyzes management events for anomalies) with the ability to log data events, or mistakenly think a CloudWatch Events rule is needed to forward data events, when in fact data events are configured directly in the trail's event selector.

143
MCQhard

A company is using Amazon CloudWatch Logs to store application logs. The security team needs to retain logs for 7 years to comply with regulatory requirements. The logs are accessed infrequently after the first 90 days. What is the MOST cost-effective way to meet these retention and access requirements?

A.Export logs from CloudWatch Logs to an S3 bucket, then use S3 Lifecycle policies to transition logs to S3 Glacier Deep Archive after 90 days.
B.Stream logs to an S3 bucket using Kinesis, then use S3 Lifecycle policies to transition logs to S3 Standard-IA after 90 days.
C.Set a retention policy on the CloudWatch Logs log group to 7 years and use CloudWatch Logs Insights for queries.
D.Set a retention policy on the CloudWatch Logs log group to 7 years and use CloudWatch Logs lifecycle policies to transition to Amazon S3 Glacier.
AnswerA

Exporting log data from CloudWatch Logs to S3 via the CreateExportTask API is the native, recommended path for long-term archival. Once in S3, a lifecycle rule can transition objects from S3 Standard to S3 Glacier Deep Archive after 90 days, minimizing storage costs for data that is rarely, if ever, accessed while meeting the 7-year compliance requirement. This approach also lets you set a short retention on the original log group to avoid ongoing CloudWatch Logs storage fees after export completes.

Why this answer

Exporting logs from CloudWatch Logs to Amazon S3 and using S3 Lifecycle policies to transition them to S3 Glacier Deep Archive after 90 days is the most cost-effective solution. CloudWatch Logs storage costs are higher than S3, and Glacier Deep Archive offers the lowest storage cost for infrequently accessed data that must be retained for 7 years. This approach meets the retention requirement while minimizing costs for logs that are rarely accessed after the initial 90-day period.

Exam trap

The trap here is that candidates may incorrectly assume CloudWatch Logs can directly transition logs to Glacier via lifecycle policies, but CloudWatch Logs does not support lifecycle transitions to S3 storage classes; logs must first be exported to S3.

How to eliminate wrong answers

Option B is wrong because S3 Standard-IA is more expensive than Glacier Deep Archive for long-term archival storage, and streaming logs via Kinesis adds unnecessary cost and complexity when a direct export from CloudWatch Logs to S3 is available. Option C is wrong because retaining logs in CloudWatch Logs for 7 years is significantly more expensive than storing them in S3 Glacier Deep Archive, and CloudWatch Logs Insights queries incur additional costs for data scanning. Option D is wrong because CloudWatch Logs does not have lifecycle policies to transition logs directly to Amazon S3 Glacier; the correct mechanism is to export logs to S3 first and then use S3 Lifecycle policies to transition to Glacier storage classes.

144
MCQeasy

A company wants to monitor failed SSH login attempts to its EC2 instances. Which AWS service should be used to collect and analyze these logs?

A.VPC Flow Logs
B.Amazon CloudWatch Logs with the unified CloudWatch agent
C.AWS CloudTrail
D.AWS Config
AnswerB

The unified CloudWatch agent collects operating-system logs such as /var/log/secure or auth.log from EC2 instances and ships them to CloudWatch Logs, where metric filters and alarms can detect and alert on failed SSH login attempts.

Why this answer

Amazon CloudWatch Logs with the unified CloudWatch agent is the correct choice because the agent can be configured to collect and forward system log files, such as /var/log/secure (Amazon Linux) or /var/log/auth.log (Ubuntu), which record SSH authentication attempts including failures. This allows centralized monitoring and analysis of failed SSH logins via CloudWatch Logs Insights or metric filters.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (network-level) with OS-level logs, or assume CloudTrail captures all activity including guest OS events, when in fact CloudTrail only records AWS API calls, not in-OS authentication logs.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log application-level events like SSH authentication failures. Option C is wrong because AWS CloudTrail records API calls made to the AWS control plane (e.g., EC2 RunInstances) but does not capture guest OS-level logs such as SSH login attempts. Option D is wrong because AWS Config tracks resource configuration changes and compliance, not operating system log events.

145
Multi-Selectmedium

A company wants to detect and respond to potential security threats in near real-time. Which THREE AWS services should the company use together? (Select THREE.)

Select 3 answers
A.AWS Security Hub
B.Amazon Inspector
C.Amazon Detective
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersA, C, E

AWS Security Hub is the correct answer because it functions as a centralized cloud security posture management service that aggregates findings from multiple AWS detective and vulnerability services, including GuardDuty, Inspector, and Macie, into a single console. It enables detection by collecting these findings and facilitates response through event-driven automation using Amazon EventBridge, custom actions, and integration with SIEM or ticketing tools. While it does not generate its own raw detections, it provides the unified visibility and orchestration needed to both detect and respond to security issues across an entire AWS environment.

Why this answer

AWS Security Hub (A) aggregates security findings from multiple AWS services, including Amazon GuardDuty (E) and Amazon Detective (C), into a single dashboard. GuardDuty provides near real-time threat detection by analyzing VPC Flow Logs, DNS logs, and CloudTrail events using machine learning. Detective automates the investigation of those findings by correlating historical data to identify root causes.

Together, these three services enable near real-time detection and response to security threats.

Exam trap

The trap here is that candidates often select Amazon Inspector (B) thinking it provides real-time threat detection, but it is a vulnerability assessment tool that runs on a schedule, not a continuous threat detection service like GuardDuty.

146
MCQeasy

A security engineer needs to centrally collect and analyze AWS CloudTrail logs from multiple accounts. Which service is designed for this purpose?

A.Configure each account to send logs to a central S3 bucket
B.Enable Amazon GuardDuty in each account and aggregate findings
C.Use Amazon CloudWatch Logs to stream logs from each account to a central account
D.Use AWS Organizations to create a CloudTrail trail that applies to all accounts
AnswerD

Using AWS Organizations, you can create an organization trail from the management account that automatically logs CloudTrail management events for every account in the organization, including future accounts, with no per-account configuration. The trail delivers log files to a single designated S3 bucket in the management account, enabling centralized collection and analysis through Athena, QuickSight, or other tools. This is the native, designed method for centralizing CloudTrail logs across multiple accounts.

Why this answer

AWS Organizations allows you to create a single CloudTrail trail that applies to all accounts in the organization, centrally collecting management and data events into a single S3 bucket (and optionally CloudWatch Logs). This eliminates the need to manually configure trails in each account and ensures consistent logging across the entire organization, meeting the requirement for central collection and analysis.

Exam trap

The trap here is that candidates often confuse 'centralized logging' with simply sending logs to a central S3 bucket (Option A), missing the key requirement that AWS Organizations provides a single, managed trail that applies to all accounts automatically, rather than requiring per-account configuration.

How to eliminate wrong answers

Option A is wrong because simply configuring each account to send logs to a central S3 bucket requires manual setup per account, does not enforce consistent trail configuration, and lacks native aggregation of logs from multiple accounts into a single trail for analysis. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail logs for malicious activity, but it does not centrally collect or store raw CloudTrail logs for analysis; it only provides findings. Option C is wrong because Amazon CloudWatch Logs can stream logs from multiple accounts, but it requires each account to have its own CloudTrail trail configured and then stream to a central account, which adds complexity and does not provide a single, unified trail across all accounts.

147
MCQeasy

A company wants to centrally collect CloudTrail logs from multiple AWS accounts and enable real-time analysis. Which combination of services should be used?

A.CloudTrail, Amazon Kinesis Data Firehose, and Amazon Athena.
B.CloudTrail, Amazon S3, S3 Event Notifications, and AWS Lambda.
C.CloudTrail, Amazon CloudWatch Logs, and cross-account log subscription.
D.CloudTrail, Amazon S3, and Amazon Simple Queue Service (SQS).
AnswerB

This design works because CloudTrail delivers compressed log files as S3 objects, and S3 Event Notifications invoke Lambda for each new object. Lambda then unpacks the gzipped CloudTrail JSON, filters for key API activity, and writes normalized events to CloudWatch Logs or fires alerts, giving near-real-time analysis without managing servers or a streaming buffer. It is serverless, cost-effective, and tightly integrated with S3, making it the natural choice for a central log collection and analysis pipeline.

Why this answer

It enables centralized collection of CloudTrail logs from multiple accounts by delivering logs to a central S3 bucket, then using S3 Event Notifications to trigger a Lambda function for real-time analysis. This pattern allows near-instant processing of log events as they arrive, meeting the requirement for real-time analysis without polling or batching delays.

Exam trap

The trap here is that candidates often assume Kinesis Data Firehose or CloudWatch Logs are required for real-time analysis, but S3 Event Notifications with Lambda provide a simpler, cost-effective, and fully serverless solution for near-real-time processing of CloudTrail logs.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Firehose is designed for streaming data ingestion into destinations like S3 or Redshift, but it does not natively support cross-account CloudTrail log delivery or real-time analysis via Athena (which queries data at rest, not in real-time). Option C is wrong because cross-account log subscription to CloudWatch Logs requires CloudTrail to deliver logs to CloudWatch Logs, which incurs additional costs and does not inherently provide real-time analysis; it also lacks the event-driven trigger for immediate processing. Option D is wrong because Amazon SQS is a message queue service that would require additional components to process logs in real-time, and CloudTrail cannot directly deliver logs to SQS; this setup adds latency and complexity without a built-in processing trigger.

148
MCQeasy

A company is using Amazon CloudWatch Logs to store application logs. The security team needs to ensure that logs are encrypted at rest using a customer-managed KMS key (CMK). What configuration is required?

A.Add a KMS key policy that allows CloudWatch Logs to use the key.
B.Associate the CMK with the CloudWatch Logs log group by specifying the key ARN in the log group's encryption configuration.
C.Enable default encryption on the S3 bucket used for log export with a CMK.
D.Configure the S3 bucket policy to require SSE-KMS for log delivery.
AnswerB

To encrypt a CloudWatch Logs log group with a customer-managed CMK, you must use the AssociateKmsKey operation (or the console's encryption settings) and pass the key ARN for the log group. Once associated, CloudWatch Logs uses that CMK to encrypt all log data written to the log group. This is the action that actually fulfills the requirement; no other configuration changes the encryption of the log group's stored data.

Why this answer

CloudWatch Logs supports server-side encryption with a customer-managed KMS key (CMK) by associating the key ARN with the log group. This is done via the CloudWatch Logs console, AWS CLI, or SDK using the `associate-kms-key` operation, which encrypts all log data at rest within that log group. The KMS key policy must also grant the CloudWatch Logs service principal (`logs.region.amazonaws.com`) permission to use the key, but the core configuration step is associating the key with the log group.

Exam trap

The trap here is that candidates confuse the necessary KMS key policy (Option A) with the actual configuration step of associating the key with the log group, or they mistakenly think that encrypting the S3 export destination (Options C or D) encrypts the logs within CloudWatch Logs itself.

How to eliminate wrong answers

Option A is wrong because while a KMS key policy that allows CloudWatch Logs to use the key is necessary, it is not sufficient on its own; the key must also be explicitly associated with the log group via encryption configuration. Option C is wrong because enabling default encryption on an S3 bucket with a CMK only affects objects stored in that bucket, not the CloudWatch Logs log group itself; log export to S3 is a separate feature and does not encrypt logs at rest within CloudWatch. Option D is wrong because configuring an S3 bucket policy to require SSE-KMS for log delivery only applies to logs exported to S3, not to the encryption of logs stored natively in CloudWatch Logs.

149
MCQmedium

A security engineer needs to ensure that all S3 object-level API calls (e.g., GetObject, PutObject) on the bucket 'my-bucket' are logged. The current CloudTrail configuration is as shown in the exhibit. What change should the engineer make?

A.Remove the DataResources section and add an AdvancedEventSelector for S3.
B.Change the bucket ARN to 'arn:aws:s3:::my-bucket' without a trailing slash.
C.Enable management events by setting IncludeManagementEvents to true.
D.Change the data resource value to 'arn:aws:s3:::my-bucket/' to cover all objects.
AnswerD

Changing the data resource value to 'arn:aws:s3:::my-bucket/' correctly covers all objects within the bucket. In CloudTrail's DataResource configuration for S3, the ARN must specify a prefix; a trailing slash after the bucket name represents the root prefix, meaning all objects inside that bucket. Without the slash, CloudTrail does not match object-level operations. This is the standard pattern for logging all S3 data events for a single bucket.

Why this answer

To log all S3 object-level API calls (GetObject, PutObject, etc.) on the bucket 'my-bucket', the DataResources value must specify the bucket's ARN with a trailing slash (arn:aws:s3:::my-bucket/) to indicate all objects within the bucket. Without the trailing slash, CloudTrail interprets the ARN as referring to the bucket itself, not its objects, and thus object-level events are not captured. The trailing slash ensures the selector applies to all object keys under that bucket.

Exam trap

The trap here is that candidates often think the bucket ARN without a trailing slash is sufficient for object-level logging, not realizing that the trailing slash is required to match all objects within the bucket, a nuance that CloudTrail documentation explicitly states.

How to eliminate wrong answers

Option A is wrong because removing the DataResources section and adding an AdvancedEventSelector for S3 is unnecessary; the existing DataResources configuration can be corrected simply by appending a trailing slash, and AdvancedEventSelectors are not required for this basic S3 data event logging. Option B is wrong because changing the bucket ARN to 'arn:aws:s3:::my-bucket' without a trailing slash would still not cover object-level events; it would only match the bucket resource itself, not the objects. Option C is wrong because enabling management events (IncludeManagementEvents) controls logging of bucket-level management operations (e.g., CreateBucket, DeleteBucket), not object-level API calls like GetObject or PutObject, which are data events.

150
Multi-Selecteasy

A security engineer is setting up monitoring for AWS API calls. Which TWO AWS services can be used to capture and analyze API activity?

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersA, D

Amazon CloudWatch Logs is the monitoring and analysis layer that ingests CloudTrail events when a trail is configured to deliver to a log group. It enables real-time and historical inspection of API calls through metric filters, which can trigger CloudWatch Alarms based on specific API activity, and CloudWatch Logs Insights for ad-hoc querying. This makes it the correct service for actively monitoring and alerting on AWS API calls, rather than merely recording them.

Why this answer

Amazon CloudWatch Logs can capture and analyze API activity by ingesting log data from various AWS services, including AWS CloudTrail. You can configure CloudWatch Logs to monitor API calls in real time, set up metric filters to detect specific patterns, and trigger alarms based on API activity. This makes it a valid service for capturing and analyzing API calls, especially when combined with CloudTrail for detailed event records.

Exam trap

The trap here is that candidates often confuse AWS Config (which records resource configuration changes) with CloudTrail (which records API calls), or they think Amazon GuardDuty directly captures API logs, when in fact it only analyzes logs from other services like CloudTrail.

← PreviousPage 2 of 4 · 250 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Logging questions.