Courseiva

CCNA Security Logging Questions

25 of 250 questions · Page 4/4 · Security Logging topic · Answers revealed

226
MCQhard

A company has a CloudTrail trail that logs management events for all regions. The security team notices that some S3 data events are not being logged. How should the team enable logging for all S3 data events?

A.Update the existing CloudTrail trail to include data events for S3
B.Create a new CloudTrail trail that logs only data events
C.Use Amazon GuardDuty to monitor S3 access
D.Enable S3 server access logging on each bucket
AnswerA

CloudTrail trails can be updated at any time to include data events for specific S3 buckets or all buckets, capturing object-level operations such as GetObject, PutObject, and DeleteObject in addition to the existing management events. This consolidates all API activity into a single audit stream, avoids the operational overhead of managing multiple trails, and is the direct, recommended way to meet the requirement for S3 access logging within CloudTrail.

Why this answer

CloudTrail trails can be configured to log data events for S3 in addition to management events. By updating the existing trail to include S3 data events (e.g., GetObject, PutObject), the security team can capture all object-level API activity without creating a separate trail. This ensures comprehensive logging while maintaining the existing management event logging for all regions.

Exam trap

The trap here is that candidates may think S3 server access logging (Option D) is equivalent to CloudTrail data events, but server access logs are separate, bucket-specific logs that lack the centralized management, API-level detail, and integration with CloudTrail Insights or other monitoring services.

How to eliminate wrong answers

Option B is wrong because creating a new CloudTrail trail that logs only data events would duplicate logging infrastructure and incur additional costs, but the existing trail already logs management events; the correct approach is to modify the existing trail to include data events. Option C is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity using CloudTrail logs, VPC Flow Logs, and DNS logs, but it does not enable or configure CloudTrail data event logging itself. Option D is wrong because S3 server access logs are bucket-level logs that record requests made to the bucket, but they are not integrated with CloudTrail and do not provide the centralized, API-level data event logging that CloudTrail offers; they also require enabling on each bucket individually and do not support the same filtering or integration with other AWS services.

227
MCQhard

A company uses Amazon GuardDuty to monitor for threats. The security team receives a high-severity finding: 'UnauthorizedAccess:EC2/SSHBruteForce'. The finding indicates a single EC2 instance with a public IP is receiving SSH connection attempts from multiple external IPs. The instance is part of an Auto Scaling group and is fronted by an Application Load Balancer (ALB). The security team wants to block the attacking IPs without disrupting legitimate traffic. What is the MOST effective approach?

A.Stop the EC2 instance and launch a new one in a different subnet.
B.Modify the security group of the EC2 instance to deny inbound SSH from the attacking IPs.
C.Create a network ACL rule on the subnet to deny inbound traffic from the attacking IPs.
D.Configure AWS WAF on the ALB to block the attacking IPs using an IP set rule.
AnswerB

Modifying the security group to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance uses a security group that can be applied to all instances in the Auto Scaling group, this approach is effective and persistent.

Why this answer

Modifying the security group of the EC2 instance to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance is part of an Auto Scaling group, security group modifications will apply to all instances launched with that security group, and updates are immediate. Option D (AWS WAF on ALB) is ineffective because WAF only inspects HTTP/HTTPS traffic at Layer 7, while SSH traffic operates at Layer 4 and does not pass through the ALB; the ALB only handles HTTP/HTTPS, not SSH.

The attackers are targeting the instance's public IP directly over SSH, not through the ALB. Therefore, WAF cannot block SSH traffic. Option A (stop instance) is disruptive and unnecessary.

Option C (network ACL) would block traffic at the subnet level but would affect all instances in the subnet and is less granular than a security group.

Exam trap

The trap is that candidates assume AWS WAF can block any type of traffic when attached to an ALB, but WAF only inspects HTTP/HTTPS requests at Layer 7, not SSH traffic at Layer 4. The correct approach is to use a security group to block SSH at the instance level.

How to eliminate wrong answers

Option A is wrong because stopping the EC2 instance and launching a new one in a different subnet does not block the attacking IPs; it only changes the instance's IP address, and the attackers can still target the new instance. Option B is wrong because modifying the security group to deny inbound SSH from the attacking IPs would block SSH from those IPs but would also disrupt legitimate SSH traffic from those IPs if any existed, and it does not address the fact that the instance is behind an ALB where SSH traffic typically bypasses the ALB; moreover, security group rules are stateful and cannot block traffic at the application layer. Option C is wrong because creating a network ACL rule to deny inbound traffic from the attacking IPs would block all traffic from those IPs at the subnet level, including legitimate traffic (e.g., HTTP/HTTPS via the ALB), and network ACLs are stateless, requiring separate inbound and outbound rules, which complicates management and can disrupt legitimate traffic.

228
MCQhard

An organization has a requirement to retain all security logs for at least 7 years for compliance. The logs are stored in Amazon S3 and are rarely accessed. Which storage class is the MOST cost-effective for this retention period?

A.S3 Glacier Deep Archive
B.S3 Standard
C.S3 One Zone-IA
D.S3 Intelligent-Tiering
AnswerA

S3 Glacier Deep Archive is the correct choice for 7-year security log retention because it provides the lowest storage cost of any S3 storage class, designed specifically for long-term, rarely accessed archival data. It offers 99.999999999% durability across multiple Availability Zones and a standard retrieval time of 12 hours, which is acceptable for compliance-oriented logs that are seldom retrieved. The one-time retrieval fee and minimum 180-day storage period are outweighed by the dramatic per-GB savings over the full 7-year cycle.

Why this answer

S3 Glacier Deep Archive is the most cost-effective storage class for data that is rarely accessed and must be retained for 7 years. It offers the lowest storage cost among S3 classes, designed specifically for long-term retention of archival data where retrieval times of 12 hours are acceptable. The compliance requirement for 7-year retention aligns perfectly with Glacier Deep Archive's intended use case, minimizing costs while meeting the retention mandate.

Exam trap

The trap here is that candidates often choose S3 Intelligent-Tiering thinking it automatically optimizes costs for long-term storage, but they overlook the per-object monitoring fee and the fact that for data that is never accessed after initial storage, Glacier Deep Archive is cheaper because it has no automation overhead.

How to eliminate wrong answers

Option B (S3 Standard) is wrong because it is designed for frequently accessed data with millisecond retrieval, incurring high storage costs over 7 years for rarely accessed logs, making it cost-ineffective. Option C (S3 One Zone-IA) is wrong because it stores data in a single Availability Zone, which does not meet the durability and availability requirements for compliance logs that must be retained for 7 years; it also has higher storage costs than Glacier Deep Archive for long-term archival. Option D (S3 Intelligent-Tiering) is wrong because it is optimized for data with unknown or changing access patterns, automatically moving objects between tiers, but it incurs monitoring and automation fees that are unnecessary for logs that are rarely accessed and have a fixed retention period, making it less cost-effective than Glacier Deep Archive.

229
MCQmedium

A company is using Amazon GuardDuty to monitor for malicious activity. The security team wants to automatically isolate an EC2 instance that is flagged for outbound communication with a known malicious IP address. Which approach is the most efficient and scalable?

A.Use a CloudWatch Alarm to directly invoke a Lambda function to isolate the instance.
B.Use AWS Config to automatically terminate the instance when a GuardDuty finding is reported.
C.Use Amazon EventBridge to invoke an AWS Lambda function that modifies the instance's security group.
D.Create a CloudWatch alarm on GuardDuty findings and modify the subnet's network ACL to block the traffic.
AnswerC

GuardDuty publishes every finding as an event to Amazon EventBridge, where a rule with an event pattern matching specific finding types and severities can route to a Lambda function. That function can call ec2:RevokeSecurityGroupIngress or ec2:ModifyNetworkInterfaceAttribute to swap the instance onto a dedicated quarantine security group, removing internet-facing ingress rules. This approach is targeted to the exact resource in the finding, reversible, and scales across many findings without affecting the rest of the subnet.

Why this answer

Amazon EventBridge can directly capture GuardDuty findings as events and trigger an AWS Lambda function to modify the instance's security group, revoking outbound access to the malicious IP. This approach is event-driven, serverless, and scales automatically without polling or manual intervention, making it the most efficient and scalable solution.

Exam trap

The trap here is that candidates may confuse CloudWatch Alarms with EventBridge rules, not realizing that EventBridge provides native, real-time event filtering and direct Lambda invocation without the polling or metric-based delays inherent in CloudWatch Alarms.

How to eliminate wrong answers

Option A is wrong because CloudWatch Alarms cannot directly invoke Lambda functions; they can only trigger actions like SNS, Auto Scaling, or EC2 actions, and would require an additional intermediary (e.g., SNS to Lambda) adding latency and complexity. Option B is wrong because AWS Config is a configuration auditing and compliance service, not a real-time event-driven response system; it cannot automatically terminate instances based on GuardDuty findings, and termination is an overly destructive action that may not be appropriate for isolation. Option D is wrong because modifying a subnet's network ACL (NACL) is stateless and affects all instances in the subnet, not just the flagged instance, and CloudWatch alarms on GuardDuty findings would require custom metric filters and lack direct integration with NACL modifications.

230
MCQhard

Refer to the exhibit. A security engineer reviews IAM permissions for the 'admin' user. The user is a member of the 'Administrators' group, which has the 'AdministratorAccess' managed policy attached. Additionally, the user has an inline policy named 'AllowSSH'. The engineer wants to ensure that the user can only start SSM sessions on instances with the tag 'SSH: enabled'. However, the user can still start sessions on any instance. What is the most likely reason?

A.The inline policy does not include 'ec2:DescribeInstances' for the SSM session, so it cannot start sessions.
B.The condition 'aws:ResourceTag/SSH' should be 'aws:RequestTag/SSH' to check the request tag.
C.The inline policy uses 'Allow' instead of 'Deny' for instances without the tag, so it does not restrict access.
D.The inline policy 'AllowSSH' is not effective because it is overridden by the group policy 'AdministratorAccess'.
AnswerC

The inline policy allows SSM StartSession only on tagged instances, but since the group policy allows all actions, the effective permission is still 'Allow' on all instances. To restrict, a 'Deny' statement is needed for instances without the tag.

Why this answer

In AWS IAM, an explicit Allow in any attached policy grants access — there is no 'most restrictive wins' rule for Allow statements. Because the user already has AdministratorAccess (which allows ssm:StartSession on *), the inline AllowSSH policy's Allow statement cannot restrict anything; it only adds permissions. To restrict the user to tagged instances, the inline policy must contain an explicit Deny for ssm:StartSession when the resource tag condition is not met (or the AdministratorAccess policy must be removed/scoped).

Exam trap

SCS-C02 often tests the misconception that a more specific Allow policy can restrict a broader Allow — in IAM, only an explicit Deny can override an Allow, so candidates who pick 'policy precedence' answers fall for this trap.

How to eliminate wrong answers

Option A is wrong because ec2:DescribeInstances is not required to call ssm:StartSession — SSM session authorization is evaluated against the managed instance resource ARN, not EC2 describe permissions. Option B is wrong because aws:ResourceTag/SSH is the correct condition key for evaluating the tag on the target managed instance; aws:RequestTag is used when tagging resources during creation, not when starting a session. Option D is wrong because inline policies are not 'overridden' by managed policies — IAM evaluates the union of all policies, and any Allow grants access; the issue is the absence of a Deny, not policy precedence.

231
Multi-Selecteasy

Which TWO AWS services can be used to monitor network traffic for malicious activity? (Select TWO.)

Select 2 answers
A.AWS Network Firewall
B.Amazon GuardDuty
C.AWS Shield
D.AWS WAF
E.Amazon Inspector
AnswersA, B

AWS Network Firewall inspects inbound, outbound and east-west traffic using Suricata-compatible stateful rules, enabling signature-based detection of malicious activity across VPC subnets. It satisfies the monitoring requirement by logging alerts and flow data to CloudWatch, S3 or Kinesis Firehose, giving the visibility needed to identify threats rather than merely filtering them.

Why this answer

AWS Network Firewall (A) is correct because it is a managed, stateful network firewall and intrusion prevention service that inspects VPC traffic (including VPC-to-VPC, egress, and ingress) and can alert on or block malicious activity using Suricata-compatible rules and managed threat signatures. Amazon GuardDuty (B) is correct because it continuously monitors network traffic and account activity—analyzing VPC Flow Logs, DNS logs, and CloudTrail events—to detect malicious or unauthorized behavior such as crypto-mining, port scanning, and communication with known malicious IPs. AWS Shield (C) is not the right answer because it is a managed DDoS protection service that mitigates volumetric and layer 3/4 attacks but does not provide general network traffic monitoring for malicious activity.

AWS WAF (D) is not the right answer because it filters HTTP(S) requests at layer 7 against web exploits like SQL injection and XSS, not network traffic monitoring. Amazon Inspector (E) is not the right answer because it is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure, rather than monitoring live network traffic.

Exam trap

The trap here is that candidates confuse AWS Shield (DDoS protection) or AWS WAF (web application firewall) with network traffic monitoring, but neither performs deep packet inspection or threat detection for general malicious network activity beyond their specific scopes.

232
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs to ensure that all accounts have CloudTrail enabled and that logs are delivered to a centralized S3 bucket in the management account. Which solution meets these requirements?

A.Write a script that runs in each account using AWS Lambda to enable CloudTrail and point to the central bucket.
B.Use AWS Config rules in each account to check CloudTrail status and remediate via Lambda.
C.Use AWS CloudTrail with Organizations to create an organization trail that logs all accounts to the central bucket.
D.Create an IAM role that each account assumes to enable CloudTrail and log to the central bucket.
AnswerC

Creating an organization trail in the management account (with isOrganizationTrail set to true) automatically provisions CloudTrail for every current and future member account in AWS Organizations, delivering logs to a single central S3 bucket. Member account users—even those with administrative rights—cannot disable or alter the trail because ownership rests with the management account, eliminating the need for per-account configuration or remediation. This native, centralized governance model is exactly why recommended architectures consistently select this option over per-account scripts, roles, or Config checks.

Why this answer

AWS CloudTrail supports integration with AWS Organizations, allowing you to create an organization trail that automatically logs events for all accounts in the organization. This trail delivers log files to a single centralized S3 bucket in the management account without requiring per-account configuration, ensuring compliance with the security team's requirement.

Exam trap

The trap here is that candidates often assume they must enable CloudTrail individually in each account or use complex cross-account IAM roles, overlooking the native AWS Organizations integration that automatically applies a single trail to all accounts.

How to eliminate wrong answers

Option A is wrong because it relies on a script running in each account via Lambda, which is operationally complex, not scalable, and does not leverage the native multi-account capabilities of CloudTrail; it also risks missing accounts or failing to maintain consistent configuration. Option B is wrong because AWS Config rules can only detect and remediate non-compliance after the fact, not proactively enable CloudTrail across all accounts, and the remediation Lambda would need to be deployed in each account, adding overhead and potential latency. Option D is wrong because creating an IAM role for each account to assume does not automatically enable CloudTrail; it only provides permissions, and the actual enabling would still require manual or scripted actions in each account, failing to meet the requirement for a centralized, automated solution.

233
MCQmedium

A company is using AWS CloudTrail to log API calls and wants to ensure that log files are not tampered with after delivery to S3. Which feature should be enabled to validate the integrity of CloudTrail log files?

A.Enable CloudTrail log file validation
B.Enable MFA Delete on the S3 bucket
C.Enable S3 Versioning on the bucket
D.Enable S3 bucket default encryption
AnswerA

CloudTrail log file validation creates a SHA-256 hash of each log file and stores it in a digest file in the same S3 bucket. When enabled, you can use the AWS CLI or API to validate that log files were not modified or deleted after delivery. It uses a private key to sign the digest files, providing cryptographic assurance that the logs themselves are authentic and intact. This directly detects any tampering with log integrity, unlike the other options.

Why this answer

Enabling CloudTrail log file validation creates a digest file for each log file delivery, which includes a SHA-256 hash of the log file. This digest is signed using the private key of a dedicated CloudTrail key pair, allowing you to verify the integrity and authenticity of the log files by comparing the hash against the digest, ensuring no tampering occurred after delivery to S3.

Exam trap

The trap here is that candidates confuse data integrity validation with data protection features like encryption or versioning, mistakenly thinking that preventing deletion or encrypting data also ensures the data hasn't been tampered with.

How to eliminate wrong answers

Option B is wrong because MFA Delete on the S3 bucket protects against accidental or unauthorized deletion of objects by requiring multi-factor authentication for delete operations, but it does not validate the integrity or detect tampering of already-delivered log files. Option C is wrong because S3 Versioning preserves multiple versions of objects, which can help recover from accidental overwrites or deletions, but it does not provide cryptographic verification that the log file content has not been altered. Option D is wrong because S3 bucket default encryption ensures data is encrypted at rest, protecting confidentiality, but it does not provide any mechanism to verify that the log file has not been tampered with after delivery.

234
MCQeasy

A company wants to centralize CloudTrail logs from multiple AWS accounts into a single S3 bucket for security analysis. The logs must be encrypted at rest and access must be logged. What is the MOST secure way to grant cross-account access to the central S3 bucket?

A.Create an S3 bucket policy that grants s3:PutObject to everyone, and rely on CloudTrail to restrict access.
B.Create an IAM role in the central account that each member account can assume to write logs.
C.Create an S3 bucket policy that grants CloudTrail service principal permission to write objects, with a condition checking the source account ID.
D.Use an S3 bucket with default encryption enabled and share the KMS key with the other accounts.
AnswerC

This is the documented pattern for aggregating CloudTrail logs: the bucket policy grants s3:PutObject (and s3:GetBucketAcl if not using bucket owner enforcement) to the CloudTrail service principal, and the aws:SourceAccount condition restricts the service request to CloudTrail accounts explicitly allowed. The service principal cloudtrail.amazonaws.com prevents individuals or other AWS services from writing, while the condition blocks confused-deputy attacks from accounts not in the allow list. The central account then receives trail logs from all member accounts.

Why this answer

It uses an S3 bucket policy that grants the CloudTrail service principal (cloudtrail.amazonaws.com) permission to write objects, with a condition that checks the source account ID. This ensures that only CloudTrail from authorized accounts can deliver logs, and the service principal approach avoids the need for IAM roles or sharing credentials. The bucket policy also allows encryption at rest via S3 default encryption or a KMS key, and access logging can be enabled separately on the bucket.

Exam trap

The trap here is that candidates often confuse IAM roles with service principals, thinking that cross-account access always requires an IAM role, but CloudTrail uses service principals and bucket policies for cross-account log delivery, making option B a common distractor.

How to eliminate wrong answers

Option A is wrong because granting s3:PutObject to everyone allows any AWS principal or unauthenticated user to write objects, which is insecure and violates the principle of least privilege; CloudTrail cannot restrict access after the policy allows it. Option B is wrong because creating an IAM role in the central account for each member account to assume is not the most secure or efficient method for CloudTrail log delivery—CloudTrail uses service principals, not IAM roles, to write logs cross-account, and this approach adds complexity and potential for misconfiguration. Option D is wrong because sharing the KMS key with other accounts does not grant the necessary S3 write permissions; the bucket policy must explicitly allow CloudTrail to write, and simply enabling default encryption does not control access—also, sharing KMS keys with multiple accounts increases the attack surface and is not the primary mechanism for cross-account access.

235
Multi-Selecthard

A security engineer is configuring a new AWS account and wants to ensure that all API activity is logged and that logs are protected from deletion. The engineer plans to use AWS CloudTrail and Amazon S3. Which TWO actions should the engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable CloudTrail log file validation to ensure logs are not tampered with.
B.Configure the S3 bucket policy to deny deletion of objects by any principal except the security engineer's IAM role.
C.Enable S3 Object Lock in compliance mode on the S3 bucket used for CloudTrail logs.
D.Use AWS Key Management Service (AWS KMS) to encrypt the CloudTrail logs in the S3 bucket.
E.Create a CloudTrail trail that applies to all regions and logs management events.
AnswersC, E

S3 Object Lock in compliance mode prevents objects from being deleted or overwritten for a specified retention period, even by the root user. This protects CloudTrail logs from tampering or deletion, satisfying the immutability requirement. It is a strong control that ensures logs cannot be altered, which is critical for security and compliance.

Why this answer

To log all API activity, a multi-region trail that logs management events is necessary. To protect logs from deletion, S3 Object Lock in compliance mode provides immutability. Other options either do not prevent deletion, provide only detection, or address confidentiality rather than integrity.

Together, these two actions meet the requirements for logging and protection.

Exam trap

The trap here is confusing log file validation or encryption with immutability; they do not prevent deletion, whereas S3 Object Lock does.

236
Multi-Selecthard

A security engineer is investigating a potential security incident. The engineer has enabled CloudTrail and VPC Flow Logs. Which THREE pieces of information can the engineer obtain from CloudTrail logs that are NOT available in VPC Flow Logs? (Choose three.)

Select 3 answers
A.The payload of the API request.
B.The AWS Region where the API call was made.
C.The destination IP address and port of the network traffic.
D.The IAM user or role that performed the API call.
E.The source IP address of the API call.
AnswersB, D, E

The AWS Region where the API call was made is a definitive field in CloudTrail's event history (the awsRegion attribute), whereas VPC Flow Logs are tied to a specific VPC and only describe traffic within that VPC's region. An API call's endpoint region may differ from the region of the VPC through which the traffic flows, so only CloudTrail provides this region information.

Why this answer

CloudTrail logs capture management-plane API calls, including the AWS Region where the call was made (via the 'awsRegion' field). VPC Flow Logs only capture network-level metadata (IP addresses, ports, protocols) and have no visibility into the AWS Region of an API call because they operate at Layer 3/4 of the OSI model and do not log control-plane events. Therefore, the Region information is uniquely available in CloudTrail.

Exam trap

The trap here is that candidates assume CloudTrail logs contain the full request payload (Option A) because they confuse CloudTrail with AWS Config or data-plane logging, but CloudTrail explicitly excludes payload data to avoid storing sensitive information.

237
MCQmedium

A security engineer needs to ensure that all API activity in an AWS account is logged and that the logs are retained for 10 years for compliance. The engineer enables AWS CloudTrail with a multi-Region trail and delivers logs to an Amazon S3 bucket. The engineer must prevent any user, including administrators, from deleting or altering the logs during the retention period. Which solution meets these requirements?

A.Enable S3 Object Lock in compliance mode on the S3 bucket with a retention period of 10 years.
B.Apply an S3 bucket policy that denies s3:DeleteObject and s3:PutObject for all principals except the CloudTrail service.
C.Configure AWS CloudTrail to use a customer-managed AWS KMS key to encrypt the logs and enable key rotation.
D.Enable S3 Versioning and configure a lifecycle rule to transition objects to S3 Glacier Deep Archive after 30 days.
AnswerA

S3 Object Lock in compliance mode prevents any user, including the root user, from deleting or overwriting objects until the retention period expires. This satisfies the requirement for immutability for 10 years. The other options either do not prevent deletion by administrators or do not provide the required retention guarantee.

Why this answer

S3 Object Lock in compliance mode provides immutable storage for a specified retention period, even preventing the root user from deleting objects. This is the only option that guarantees logs cannot be deleted or altered for 10 years. Other options either allow administrators to bypass protections or do not enforce retention.

Exam trap

The trap here is assuming that S3 Versioning or bucket policies alone provide immutability, but they can be bypassed by users with sufficient permissions.

238
MCQmedium

A company uses AWS CloudTrail and wants to ensure that all log files are encrypted at rest using a customer-managed AWS KMS key. The CloudTrail trail is configured to use a KMS key, but some log files appear to be encrypted with the default Amazon S3 managed key (SSE-S3). What is the most likely cause?

A.The KMS key policy does not grant CloudTrail permission to use the key.
B.The CloudTrail trail is configured to use SSE-S3 instead of SSE-KMS.
C.The KMS key is in a different AWS region than the S3 bucket.
D.The S3 bucket has default encryption set to SSE-S3.
AnswerA

The KMS key policy is the most likely root cause. When a trail is configured with SSE-KMS, CloudTrail must call kms:GenerateDataKey and kms:Decrypt on the customer-managed key to encrypt and decrypt log files. If the key policy does not grant these permissions to the `cloudtrail.amazonaws.com` service principal, CloudTrail cannot use that key and silently falls back to encrypting the log files with SSE-S3, which is exactly the observed behavior. You must add a policy statement that allows CloudTrail to use the key, and you may also need to grant the CloudTrail IAM role the corresponding kms:Decrypt permission.

Why this answer

The most likely cause is that the KMS key policy does not grant CloudTrail the necessary permissions to use the key for encryption. When a CloudTrail trail is configured with a customer-managed KMS key, the key policy must include a statement that allows the CloudTrail service principal (cloudtrail.amazonaws.com) to perform the kms:GenerateDataKey and kms:Decrypt actions. Without these permissions, CloudTrail falls back to encrypting log files with the default Amazon S3 managed key (SSE-S3), resulting in some logs appearing encrypted with SSE-S3 instead of SSE-KMS.

Exam trap

The trap here is that candidates often assume the S3 bucket's default encryption setting (SSE-S3) overrides the trail's KMS configuration, but in reality, CloudTrail explicitly requests encryption and only falls back to SSE-S3 when the KMS key cannot be used due to permission issues.

How to eliminate wrong answers

Option B is wrong because if the CloudTrail trail were configured to use SSE-S3 instead of SSE-KMS, then all log files would be encrypted with SSE-S3, not just some; the question states that some log files appear encrypted with SSE-S3, indicating a partial failure rather than a misconfiguration. Option C is wrong because CloudTrail and KMS keys can be in different regions as long as the S3 bucket is in the same region as the trail; cross-region KMS key usage is supported and would not cause a fallback to SSE-S3. Option D is wrong because S3 bucket default encryption settings do not override the encryption specified by CloudTrail; CloudTrail explicitly requests encryption using the configured KMS key, and if that fails, it falls back to SSE-S3, not because of bucket-level default encryption.

239
MCQeasy

Refer to the exhibit. A security engineer runs this CloudWatch Logs Insights query on a log group. What is the purpose of this query?

A.Retrieve the 20 most recent log events that contain only 'ERROR'.
B.Retrieve the 20 most recent log events that contain 'ERROR' or 'WARN'.
C.Display all log events grouped by log level.
D.Count the number of ERROR and WARN events in the last hour.
AnswerB

This is correct because the CloudWatch Logs Insights query uses `filter @message like /ERROR|WARN/` to match any log event containing either substring, and then `sort @timestamp desc | limit 20` orders by timestamp descending and returns the 20 newest matching events. That combination of a regex-style filter and a descending sort with a limit accomplishes exactly the stated goal, making it the only option that describes what the exhibited query does.

Why this answer

The CloudWatch Logs Insights query uses `filter @message like /(?i)(ERROR|WARN)/` to match log events containing either 'ERROR' or 'WARN' (case-insensitive), then `sort @timestamp desc` orders them by most recent first, and `limit 20` restricts the output to the top 20 results. This retrieves the 20 most recent log events that contain either term, making option B correct.

Exam trap

The trap here is that candidates may overlook the regex alternation `(ERROR|WARN)` and assume the query only filters for 'ERROR', or they may misinterpret the `limit` and `sort` as performing a count or grouping operation.

How to eliminate wrong answers

Option A is wrong because the query uses a regex alternation `(ERROR|WARN)`, which matches events containing 'ERROR' or 'WARN', not only 'ERROR'. Option C is wrong because the query does not include any `stats count(*) by @logLevel` or similar aggregation to group events by log level; it simply filters and sorts raw log events. Option D is wrong because the query does not use a time range filter (e.g., `filter @timestamp > ...`) to restrict to the last hour, nor does it use `stats count(*)` to count events; it retrieves up to 20 events without counting.

240
Multi-Selectmedium

A security engineer needs to monitor DNS query logs for malicious domain names. Which THREE services can be used together to collect, analyze, and alert on DNS logs? (Choose THREE.)

Select 3 answers
A.Amazon CloudWatch Logs
B.AWS Lambda
C.Amazon Route 53 Resolver Query Logs
D.Amazon GuardDuty
E.Amazon Athena
AnswersA, B, C

Amazon CloudWatch Logs acts as the aggregation and monitoring layer for Route 53 Resolver query logs. The resolver service can publish DNS query logs directly to a CloudWatch Logs log group, where you can create metric filters and subscription filters to detect suspicious queries. CloudWatch Logs supports near-real-time querying with Logs Insights, making it a central destination for ongoing monitoring.

Why this answer

Amazon Route 53 Resolver Query Logs (C) is the correct source because it captures DNS queries made by resources in a VPC, including the queried domain name, query type, and response code, which is exactly the raw DNS log data needed for detecting malicious domains. Amazon CloudWatch Logs (A) is correct because Resolver query logs can be published to a CloudWatch Logs log group, where they are stored and made available for metric filters, subscriptions, and retention management. AWS Lambda (B) is correct because a CloudWatch Logs subscription filter can stream matching log events to a Lambda function, which can then parse the DNS records, check domains against threat intelligence, and trigger alerts via SNS or other services.

Amazon GuardDuty (D) is not part of this collection/analysis/alerting pipeline for raw DNS query logs; it is a managed threat detection service that analyzes its own findings rather than ingesting and processing Resolver query logs for custom alerting. Amazon Athena (E) is a query service for data in S3 and, while it can analyze logs stored in S3, it is not one of the three services used together here to collect, process, and alert on DNS logs in this scenario.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's DNS-based threat detection capabilities with the ability to directly collect and alert on custom DNS query logs, but GuardDuty operates on its own internal data sources and does not provide the same level of custom log monitoring and alerting as the combination of Route 53 Resolver Query Logs, CloudWatch Logs, and Lambda.

241
Multi-Selecteasy

A company wants to monitor for unauthorized changes to security group rules in their VPC. Which TWO AWS services can be used together to detect and alert on such changes?

Select 2 answers
A.AWS CloudTrail
B.AWS Config
C.VPC Flow Logs
D.Amazon GuardDuty
E.Amazon Macie
AnswersA, B

AWS CloudTrail is the correct answer because it records management events for all API calls made in your account, including ec2:AuthorizeSecurityGroupIngress, ec2:RevokeSecurityGroupIngress, and ec2:CreateSecurityGroup. Each event captures the identity of the caller, the source IP address, and a timestamp, giving you full attribution for who changed a security group rule and when. This makes CloudTrail the go-to service for auditing who took a specific action against a security group, which directly answers the requirement to monitor for unauthorized changes.

Why this answer

AWS CloudTrail is correct because it records API calls made to the EC2 service, including AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and CreateSecurityGroup. By monitoring CloudTrail events for these specific API actions, you can detect unauthorized changes to security group rules. AWS Config is correct because it provides a managed rule called 'restricted-common-ports' or custom rules that can evaluate security group configurations against desired policies, and it can trigger alerts via Amazon SNS when a security group rule is changed.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show traffic) with CloudTrail (which shows API calls), or think GuardDuty monitors configuration changes when it actually focuses on threat detection in network and account activity.

242
MCQmedium

A DevOps engineer notices that an EC2 instance's CloudWatch agent is not sending custom metrics to CloudWatch. The agent is installed and the configuration file is valid. The instance has an IAM role attached. What is the most likely reason for the failure?

A.The instance does not have internet access to reach CloudWatch endpoints.
B.The CloudWatch agent is not running as root.
C.The CloudWatch agent configuration file has a syntax error.
D.The IAM role attached to the instance does not have the cloudwatch:PutMetricData permission.
AnswerD

The CloudWatch agent needs IAM permissions to publish metrics to CloudWatch; specifically, the instance's attached IAM role must include cloudwatch:PutMetricData. The managed policy CloudWatchAgentServerPolicy grants this permission, and without it the agent can collect data but every publish attempt is denied by CloudWatch, resulting in no metrics appearing in the console.

Why this answer

The CloudWatch agent requires IAM permissions to publish custom metrics. Even if the agent is installed, running, and has a valid configuration, it will fail to send metrics if the attached IAM role lacks the `cloudwatch:PutMetricData` action. This is a common misconfiguration where the instance has an IAM role, but the role's policy does not explicitly grant the necessary CloudWatch write permissions.

Exam trap

The trap here is that candidates assume internet access is required for CloudWatch communication, but AWS services can be reached via VPC endpoints or private links without internet, and the question's focus on IAM permissions is the key differentiator.

How to eliminate wrong answers

Option A is wrong because the CloudWatch agent can send metrics to CloudWatch endpoints via the AWS public endpoint or a VPC endpoint (e.g., com.amazonaws.region.monitoring) without requiring general internet access; the instance only needs network connectivity to the specific CloudWatch service endpoint, which can be achieved through a VPC endpoint or NAT gateway. Option B is wrong because the CloudWatch agent does not require root privileges to run; it can run as any user with appropriate permissions, and the agent's default installation runs as the `cwagent` user. Option C is wrong because the question explicitly states that the configuration file is valid, eliminating syntax errors as the cause.

243
MCQmedium

A company uses AWS CloudTrail to log all API activity. A security analyst notices that some delete operations on S3 buckets are missing from the CloudTrail logs. What is the MOST likely reason?

A.The S3 bucket has server access logging enabled, which overrides CloudTrail.
B.The trail is configured to log only management events, not data events.
C.The delete operations are performed by a cross-account role, which CloudTrail does not log.
D.The root user of the account is excluded from CloudTrail logging.
AnswerB

A CloudTrail trail defaults to recording only management events, which cover control-plane operations such as creating or deleting buckets, not data-plane operations like deleting objects within an S3 bucket. Object-level S3 activities, including DeleteObject and PutObject, are classified as data events and must be explicitly enabled using data event selectors in the trail configuration. Since only management events are being logged, the DeleteObject API calls will not appear in CloudTrail event history, matching the scenario exactly.

Why this answer

CloudTrail trails can be configured to log management events (control plane operations like CreateBucket) and/or data events (data plane operations like GetObject, DeleteObject). By default, a trail logs only management events. S3 delete operations on objects within a bucket are data events, so if the trail is not configured to log data events, those delete operations will not appear in CloudTrail logs.

Exam trap

The trap here is that candidates often assume CloudTrail logs all API activity by default, failing to distinguish between management events and data events, which require separate configuration.

How to eliminate wrong answers

Option A is wrong because server access logging logs HTTP requests to the bucket and does not override CloudTrail; both can operate independently. Option C is wrong because CloudTrail does log API calls made by cross-account roles, provided the trail is configured to capture those events. Option D is wrong because CloudTrail logs all root user activity by default; there is no exclusion for the root user in CloudTrail logging.

244
MCQmedium

A company uses AWS CloudTrail to log management events in all regions. The security team notices that some API calls made by an IAM user are not appearing in the CloudTrail event history. What is the most likely reason?

A.The user used the AWS Management Console, not the CLI
B.The trail is configured for a single region only
C.The API calls were read-only and excluded by default
D.CloudTrail event history only retains events for 90 days; older events are not visible
AnswerD

CloudTrail event history is a built-in feature that provides a view of the last 90 days of account activity, and this retention period is not configurable. Once an event is older than 90 days, it is no longer visible in event history, and the only way to retain it is to configure a trail that delivers CloudTrail log files to Amazon S3 (and optionally CloudWatch Logs) with a suitable lifecycle policy. This 90-day limit applies uniformly to all management events, regardless of the client, region scope, or whether the calls are read-only or write-only.

Why this answer

D is correct because CloudTrail event history only retains the last 90 days of events. If the API calls were made more than 90 days ago, they would no longer appear in the event history, even though the trail itself may still be delivering log files to an S3 bucket for longer-term storage. The security team is likely looking at the event history rather than querying the S3 bucket or using Athena for older events.

Exam trap

The trap here is that candidates often assume missing API calls are due to configuration issues (like single-region trails or console-only access) rather than the 90-day retention limit of the event history, which is a fundamental but easily overlooked CloudTrail behavior.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs API calls regardless of whether they are made via the AWS Management Console, CLI, or SDK; all management events are captured. Option B is wrong because the question states the trail is configured for all regions, so a single-region trail would not explain missing events across all regions. Option C is wrong because CloudTrail does not exclude read-only API calls by default; management events include both read and write events unless specifically filtered.

245
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centralize the collection of VPC Flow Logs and AWS CloudTrail logs from all accounts into a single Amazon S3 bucket in the management account. The S3 bucket policy must allow cross-account log delivery. Which condition in the bucket policy should be used to restrict log delivery to only the organization's accounts?

A.aws:SourceArn
B.aws:SourceOrgId
C.aws:SourceAccount
D.aws:PrincipalOrgID
AnswerD

aws:PrincipalOrgID is a global IAM condition key that compares the unique organization ID of the principal's AWS account to the value you specify. In an S3 bucket policy, setting "aws:PrincipalOrgID": "o-12345" allows any principal from any account within that organization to deliver logs, automatically covering new accounts as they join. Because it operates on the principal's organization rather than the request source, it is the most scalable and appropriate condition for this cross-account logging scenario.

Why this answer

The correct condition key is `aws:PrincipalOrgID`, which restricts access to principals (accounts, IAM roles, or users) that are members of the specified AWS Organization. When used in a bucket policy, it ensures that only accounts within the company's organization can deliver logs to the S3 bucket, even if the source account ID changes. Note that `aws:SourceOrgId` is not a valid AWS condition key; `aws:PrincipalOrgID` is the appropriate key for this purpose.

Exam trap

Candidates often confuse `aws:PrincipalOrgID` with `aws:SourceOrgId`. However, `aws:SourceOrgId` is not a valid AWS condition key. The correct key for restricting based on organization membership is `aws:PrincipalOrgID`.

For cross-account log delivery, `aws:PrincipalOrgID` ensures that only accounts within the specified organization can perform the action.

How to eliminate wrong answers

Option A is wrong because `aws:SourceArn` is used to restrict access based on the exact ARN of the resource making the request, which is not suitable for cross-account log delivery from multiple accounts where the source ARN varies. Option C is wrong because `aws:SourceAccount` restricts based on a single AWS account ID, which would require listing every account in the organization and would not automatically include new accounts added later. Option D is wrong because `aws:PrincipalOrgID` is the correct key, but the option is mislabeled as `aws:SourceOrgId` in the question; the actual correct key is `aws:PrincipalOrgID`, not `aws:SourceOrgId`.

246
MCQeasy

A company wants to receive real-time notifications when specific API calls are made in their AWS account, such as creating a new IAM user. Which AWS service should be used to trigger a notification based on CloudTrail events?

A.AWS Config
B.Amazon EventBridge
C.Amazon Inspector
D.Amazon VPC Flow Logs
AnswerB

Amazon EventBridge is a serverless event bus that can consume AWS service events, including CloudTrail API call events, via a custom or the default event bus. You can define fine-grained event patterns that match specific API actions, resources, or principals, and route matched events to targets like Lambda, SNS, or SQS with low latency. This event-driven mechanism is exactly what enables real-time notifications when a specified AWS API call occurs.

Why this answer

Amazon EventBridge is the correct service because it can ingest CloudTrail events in near real-time and use event rules to match specific API calls, such as CreateUser, and then route those events to targets like SNS topics to send notifications. EventBridge provides a serverless event bus that directly integrates with CloudTrail, enabling you to react to API activity without custom polling or additional infrastructure.

Exam trap

The trap here is that candidates often confuse AWS Config's configuration change detection with real-time event-driven monitoring, but Config operates on a compliance evaluation cycle and does not provide sub-second notification for specific API calls like EventBridge does.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against rules and tracking configuration changes over time, not for reacting to real-time API calls from CloudTrail. Option C is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not for monitoring API activity. Option D is wrong because VPC Flow Logs capture IP traffic metadata at the network interface level, not API calls or IAM user creation events.

247
MCQmedium

A security engineer needs to ensure that all API calls made to AWS are logged and retained for at least 7 years for compliance. Which AWS service should be enabled to meet this requirement?

A.Amazon GuardDuty
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the service designed to record API activity across AWS, capturing the identity of the caller, source IP address, event time, request parameters, and response elements for management events by default. You can create trails that deliver compressed event logs to an Amazon S3 bucket, CloudWatch Logs, or CloudTrail Lake for long-term retention and analysis. For complete coverage, use a multi-region trail with management events enabled and add data events for S3, Lambda, and other services as needed, because CloudTrail is the authoritative source for ensuring all API calls are auditable.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity of the caller, the time of the call, the source IP address, and the request parameters. CloudTrail logs can be stored in an S3 bucket with lifecycle policies to retain logs for exactly 7 years, meeting the compliance requirement for long-term retention.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), but Config does not record the API calls themselves—only the resulting state changes, which may not satisfy compliance requirements for full API audit trails.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself log API calls or provide long-term retention of API activity records. Option B is wrong because AWS Config is a configuration management and compliance service that records resource configuration changes and evaluates them against rules, but it does not log API calls; it focuses on resource state rather than API activity. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not for logging API calls.

248
MCQhard

A company is using Amazon CloudWatch Logs to collect logs from its EC2 instances. The security team wants to ensure that logs are encrypted at rest and that access to the logs is controlled. Which solution should the team implement?

A.Enable encryption using AWS KMS customer managed keys (CMK) and apply IAM policies to control access.
B.Use SSE-C with a customer-provided key to encrypt log data.
C.Use SSE-S3 to encrypt the log data in CloudWatch Logs.
D.Enable default encryption on the log group and use S3 bucket policies.
AnswerA

CloudWatch Logs supports server-side encryption with customer-managed KMS keys (CMKs). When you associate a CMK with a log group, the service uses envelope encryption: it calls KMS to generate a data key that encrypts your log data, and that data key is then encrypted by the CMK. To control access, you must configure both the KMS key policy and IAM policies that grant or deny actions such as kms:Decrypt and logs:DescribeLogGroups. This is the only method natively supported by CloudWatch Logs for customer-controlled encryption keys.

Why this answer

CloudWatch Logs supports encryption at rest using AWS KMS customer managed keys (CMK), which allows the security team to control access to the encrypted log data via IAM policies and key policies. This ensures both encryption and fine-grained access control, meeting the requirements.

Exam trap

The trap here is that candidates confuse S3 encryption options (SSE-S3, SSE-C) with CloudWatch Logs encryption, or assume that S3 bucket policies can be applied to CloudWatch Logs, when in fact CloudWatch Logs uses KMS for encryption and IAM for access control.

How to eliminate wrong answers

Option B is wrong because SSE-C (Server-Side Encryption with Customer-Provided Keys) is used with Amazon S3, not CloudWatch Logs; CloudWatch Logs does not support customer-provided keys for encryption. Option C is wrong because SSE-S3 (Server-Side Encryption with S3-Managed Keys) is an S3 feature, not applicable to CloudWatch Logs; CloudWatch Logs uses KMS for encryption, not SSE-S3. Option D is wrong because CloudWatch Logs does not support 'default encryption on the log group' as a setting, and S3 bucket policies cannot directly control access to CloudWatch Logs data; access to log groups is managed via IAM policies, not S3 bucket policies.

249
Matchingmedium

Match each AWS CloudTrail log type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Control plane operations

Resource operations like S3 object access

Unusual activity detection

Invocation of Lambda function URLs

Why these pairings

CloudTrail has three main log types: Management events (control plane, logged by default), Data events (data plane, optional), and Insight events (anomaly detection, optional). Common confusions include swapping management vs data definitions, or misunderstanding insight events as real-time logs.

250
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs to ensure that all accounts have CloudTrail enabled and that logs are delivered to a central S3 bucket. A new member account is created and the security engineer wants to enforce this configuration automatically. Which approach meets these requirements with the least operational overhead?

A.Use AWS Config rules to detect accounts without CloudTrail and trigger a remediation via Systems Manager Automation.
B.Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts in the organization.
C.Use an SCP to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail actions.
D.Create an AWS Lambda function that runs periodically to check and enable CloudTrail in each account.
AnswerB

AWS CloudFormation StackSets with automatic deployment is the proactive, organization-native solution because it deploys a CloudTrail template to all current accounts and automatically to any new accounts that are added later. Using service-managed permissions, StackSets creates the trail, the logging S3 bucket, and the necessary IAM role in each account without custom code or manual steps. This ensures CloudTrail is enabled before any activity can occur in a new account, since the stack set rollout happens as part of account creation and organization integration. It is declarative, idempotent, and centrally managed from the management account.

Why this answer

AWS CloudFormation StackSets allows you to deploy a CloudTrail template across all accounts in an AWS Organization from a single administrative account. This approach ensures that every new member account automatically receives the CloudTrail configuration as part of the StackSet's automatic deployment to accounts added to the organization, providing a fully automated, infrastructure-as-code solution with minimal operational overhead.

Exam trap

The trap here is that candidates often confuse preventive controls (SCPs) with provisioning controls, mistakenly thinking that denying stop/delete actions is sufficient to enforce CloudTrail, when in fact it does not create or enable the trail in the first place.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect non-compliant accounts but require a remediation action (e.g., Systems Manager Automation) that adds complexity and latency; it is reactive rather than proactive and does not automatically enforce configuration on new accounts without additional setup. Option C is wrong because an SCP denying cloudtrail:StopLogging and cloudtrail:DeleteTrail only prevents disabling or deleting an existing trail but does not enable CloudTrail in the first place; it is a preventive control, not a provisioning mechanism. Option D is wrong because a periodic Lambda function introduces operational overhead for scheduling, error handling, and state management, and it is not a native, declarative, or organization-wide enforcement method; it also risks delays between account creation and log delivery.

← PreviousPage 4 of 4 · 250 questions total

Ready to test yourself?

Try a timed practice session using only Security Logging questions.