Courseiva

CCNA Threat Detection Questions

65 of 215 questions · Page 3/3 · Threat Detection topic · Answers revealed

151
MCQeasy

A security engineer is investigating a potential compromise of an EC2 instance. The engineer wants to capture memory and disk forensics without shutting down the instance. Which service should the engineer use?

A.AWS Config
B.AWS Systems Manager
C.EC2 Instance Connect
D.Amazon CloudWatch Logs
AnswerB

AWS Systems Manager, especially via Run Command and Session Manager, gives you a controlled, auditable channel to execute arbitrary scripts on EC2 instances without opening SSH or RDP. You can run built-in SSM documents or custom scripts to capture memory dumps, collect disk evidence, and pull system logs for an investigation. Its agent is already installed on many instances, making it the standard tool for on-host forensic collection.

Why this answer

AWS Systems Manager (SSM) is the correct service because it provides the capability to perform forensic data collection on a running EC2 instance without shutting it down. Specifically, SSM Automation documents like AWS-RunShellScript or AWS-GatherEC2InstanceInfo can execute commands to capture memory (e.g., using LiME or fmem) and disk forensics (e.g., dd or volume snapshots) via the SSM Agent, which runs as a system service and does not require instance termination.

Exam trap

The trap here is that candidates may confuse AWS Systems Manager with EC2 Instance Connect, thinking that SSH access alone is sufficient for forensic collection, but Systems Manager provides the necessary automation and agent-based execution to capture memory and disk data without requiring the instance to be stopped or terminated.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for resource inventory, compliance auditing, and configuration change tracking, not for capturing memory or disk forensics on a running instance. Option C is wrong because EC2 Instance Connect only provides SSH access to the instance for interactive shell sessions; it does not have built-in capabilities to capture memory dumps or perform disk forensics without additional tools and manual intervention. Option D is wrong because Amazon CloudWatch Logs is a service for collecting, monitoring, and storing log files from EC2 instances and other sources; it cannot capture memory or disk forensics data directly.

152
MCQmedium

A security engineer receives an Amazon GuardDuty finding for 'UnauthorizedAccess:EC2/SSHBruteForce'. The engineer needs to automatically isolate the compromised EC2 instance and then perform forensic analysis. Which solution meets these requirements with the LEAST operational overhead?

A.Manually SSH into the instance, stop it, and create an AMI for analysis.
B.Create an Amazon EventBridge rule that triggers an AWS Lambda function to isolate the instance by modifying its security group and then take a forensic snapshot.
C.Use AWS Config rules to automatically stop the instance.
D.Configure an Auto Scaling lifecycle hook to terminate the instance and launch a new one.
AnswerB

This is the correct response because Amazon EventBridge can be configured to receive GuardDuty findings as events, triggering a Lambda function for immediate, automated response. The Lambda function can modify the instance's security group to deny all ingress and egress traffic, effectively isolating it while preserving the running state and memory for analysis. A subsequent snapshot of the EBS volumes provides a forensically sound copy for offline investigation, all without manual intervention or risk of contaminating the evidence.

Why this answer

It automates the isolation and forensic capture of the compromised EC2 instance with minimal operational overhead. An Amazon EventBridge rule listens for the specific GuardDuty finding and triggers an AWS Lambda function that modifies the instance's security group to deny all inbound/outbound traffic (isolation) and then creates an EBS snapshot for forensic analysis. This serverless, event-driven approach eliminates manual intervention and ensures consistent, rapid response.

Exam trap

The trap here is that candidates may assume manual SSH or AWS Config rules are sufficient for incident response, but they fail to recognize that GuardDuty findings require automated, event-driven isolation without human intervention, and that Config rules lack the ability to trigger real-time security group modifications or snapshots.

How to eliminate wrong answers

Option A is wrong because manually SSHing into a compromised instance is dangerous (the attacker may still have access), and manually stopping and creating an AMI introduces high operational overhead and delays, violating the 'least operational overhead' requirement. Option C is wrong because AWS Config rules are designed for compliance and resource configuration auditing, not for real-time incident response actions like stopping instances; they cannot directly trigger instance isolation based on GuardDuty findings. Option D is wrong because an Auto Scaling lifecycle hook terminates the instance and launches a new one, which destroys forensic evidence and does not allow for isolation or forensic analysis of the original compromised instance.

153
MCQhard

A security engineer is configuring an automated incident response workflow. When a GuardDuty finding of type 'UnauthorizedAccess:EC2/SSHBruteForce' is generated, the workflow should isolate the EC2 instance and snapshot its EBS volume. Which AWS service can coordinate these actions?

A.AWS Lambda functions invoked sequentially
B.AWS Step Functions
C.AWS CloudFormation
D.AWS Config rules with auto-remediation
AnswerB

AWS Step Functions is the correct choice because it models incident response as a state machine, allowing you to coordinate Lambda, ECS, SNS, DynamoDB, and other services with explicit transitions, choice states, and parallel branches. Its durable execution records the state of each step, and built-in retry/timeout policies handle transient failures, while Standard Workflows support long-running processes such as waiting for a security analyst to approve a containment action. This gives you auditable, repeatable automation that remains maintainable as the response plan evolves.

Why this answer

AWS Step Functions is the correct service because it is designed to orchestrate multi-step workflows by coordinating AWS services like Lambda, EC2, and EBS snapshots in a defined state machine. For the given GuardDuty finding, Step Functions can receive the event, invoke a Lambda function to isolate the EC2 instance (e.g., modify security groups or attach a deny-all NACL), and then trigger another Lambda or direct API call to snapshot the EBS volume, all with built-in error handling, retries, and sequencing.

Exam trap

The trap here is that candidates confuse Lambda's ability to run code with the need for orchestration, overlooking that Step Functions provides the necessary state management, sequencing, and error handling for multi-step incident response workflows.

How to eliminate wrong answers

Option A is wrong because AWS Lambda functions invoked sequentially lack native orchestration features like branching, parallel execution, or built-in error handling; you would need to write custom code to chain them, which is less maintainable and not the recommended approach for complex workflows. Option C is wrong because AWS CloudFormation is an Infrastructure as Code (IaC) service for provisioning and managing resources, not for orchestrating real-time incident response actions triggered by GuardDuty findings. Option D is wrong because AWS Config rules with auto-remediation are designed for continuous compliance checks and corrective actions on resource configuration drift, not for responding to security findings like SSH brute force attempts; they cannot directly trigger an EC2 isolation and EBS snapshot workflow based on a GuardDuty finding.

154
MCQhard

A company's security team uses AWS Security Hub in a central security account. They want to ensure that when a critical finding is generated in any member account, the affected resource is automatically tagged with an incident identifier and the finding is routed to a third-party ticketing system. Which approach best meets these requirements?

A.Use AWS Config conformance packs to evaluate resources, and configure an Amazon SNS topic that invokes the tagging and ticketing Lambda function for noncompliant resources.
B.Configure Security Hub to send findings to EventBridge in each member account, create an EventBridge rule matching the critical severity, and target a Lambda function that tags the resource and calls the ticketing API.
C.Create a custom action in Security Hub that the analyst manually triggers for each critical finding, and configure the custom action to invoke a Lambda function that tags the resource and creates a ticket.
D.Enable cross-region aggregation in Security Hub and configure a single EventBridge rule in the aggregation Region to invoke the tagging and ticketing Lambda function for all findings.
AnswerB

Security Hub automatically sends all findings to EventBridge in the account where the finding is generated. An EventBridge rule matching ImportFindings or the severity field can invoke a Lambda function that applies the incident tag and integrates with the ticketing system, providing automatic response in every member account.

Why this answer

Security Hub publishes findings to EventBridge in the account where they are generated, so a rule in each member account can match critical severity and invoke a Lambda function that tags the resource and creates a ticket. This provides automatic, near real-time response in every account without manual intervention, and it scales across an organization when deployed consistently.

Exam trap

The trap here is expecting cross-region aggregation in Security Hub to also forward EventBridge events, when aggregation only consolidates findings for viewing.

155
Multi-Selectmedium

A company uses Amazon GuardDuty to monitor its AWS environment. The security team has received a GuardDuty finding of type 'Recon:EC2/PortProbeUnprotectedPort'. The finding indicates that an EC2 instance has an open SSH port that is being probed from the internet. The team wants to reduce the attack surface and prevent future probes. Which THREE actions should the team take? (Choose THREE.)

Select 3 answers
A.Suppress the GuardDuty finding to reduce noise.
B.Modify the security group to allow SSH only from specific IP addresses.
C.Terminate the EC2 instance and launch a new one.
D.Move the instance to a private subnet and use a NAT gateway for outbound internet access.
E.Use AWS Systems Manager Session Manager to access the instance instead of SSH.
AnswersB, D, E

Restricting the security group source to a specific IP CIDR for port 22 ensures that only authorized administrative workstations can open SSH connections, while all other public access is denied at the network layer. This directly reduces the attack surface because the instance is no longer reachable from the entire internet, and it also preserves the existing instance, its data, and its DNS name. This is a minimal, reversible change that addresses the identified risk without disrupting running workloads.

Why this answer

Modifying the security group to allow SSH only from specific IP addresses directly restricts inbound traffic to trusted sources, eliminating the open exposure that triggers the GuardDuty 'Recon:EC2/PortProbeUnprotectedPort' finding. This is a fundamental network access control that reduces the attack surface by applying the principle of least privilege at the security group level.

Exam trap

The trap here is that candidates may think suppressing the finding (Option A) is a valid remediation step, but AWS explicitly distinguishes between 'suppression' (hiding alerts) and 'remediation' (fixing the root cause), and the question asks for actions to 'prevent future probes,' not just reduce alert noise.

156
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centrally aggregate and analyze VPC Flow Logs from all accounts. Which solution is MOST efficient and scalable?

A.Configure VPC Flow Logs to send to an S3 bucket in each account and use S3 Cross-Region Replication to a central bucket.
B.Launch Amazon EC2 instances in each account to run tcpdump and send logs to a central S3 bucket.
C.Configure VPC Flow Logs to send to CloudWatch Logs in each account and use cross-account CloudWatch dashboards.
D.Configure VPC Flow Logs to send to Amazon Kinesis Data Firehose in each account, which delivers to a central Amazon OpenSearch Service domain.
AnswerD

VPC Flow Logs can be streamed directly to Amazon Kinesis Data Firehose in each account, and Firehose can then deliver nearly real-time data to a centrally owned Amazon OpenSearch Service domain cross-account. This is a fully managed, serverless pipeline that scales automatically with flow-log volume and avoids installing agents or operating log forwarders. A central OpenSearch cluster provides unified querying and visualization across all accounts' VPC traffic, making it the correct architecture for centralized real-time network analysis.

Why this answer

Amazon Kinesis Data Firehose can directly receive VPC Flow Logs from each account and deliver them to a centralized Amazon OpenSearch Service domain, enabling near-real-time aggregation and analysis without intermediate storage or replication overhead. This architecture is serverless, scales automatically, and avoids the complexity of managing cross-account S3 replication or EC2 instances, making it the most efficient and scalable solution for centralized log analysis.

Exam trap

The trap here is that candidates often default to S3-based solutions (Option A) because they are familiar with S3 for log storage, but they overlook that Kinesis Data Firehose provides a more direct, serverless pipeline for real-time analysis without the latency and complexity of S3 replication.

How to eliminate wrong answers

Option A is wrong because S3 Cross-Region Replication adds latency, requires managing replication rules and IAM permissions across accounts, and does not provide native querying or analysis capabilities—logs would need additional services like Athena or OpenSearch for analysis. Option B is wrong because launching EC2 instances to run tcpdump is inefficient, introduces management overhead, scales poorly across many accounts, and tcpdump captures raw packets rather than VPC Flow Logs, which are already a structured log format. Option C is wrong because cross-account CloudWatch dashboards only visualize logs stored in each account's CloudWatch Logs; they do not centrally aggregate the logs into a single store, and querying across accounts requires complex cross-account log group subscriptions or additional infrastructure.

157
MCQeasy

A startup uses a single AWS account for development. The security engineer wants to detect if any EC2 instances have been compromised and are performing reconnaissance by probing open ports on other internal instances. The engineer has enabled VPC Flow Logs for all subnets. What is the most cost-effective way to detect this behavior?

A.Enable Amazon GuardDuty and review the findings.
B.Install a third-party intrusion detection system on each EC2 instance.
C.Use Amazon CloudWatch Logs Insights to query VPC Flow Logs for rejected traffic patterns.
D.Use AWS Config rules to check for security group changes.
AnswerA

Amazon GuardDuty is a managed threat detection service that continuously analyzes AWS account activity from VPC Flow Logs, DNS logs, CloudTrail management events, and S3 data events. It uses threat intelligence feeds and machine learning to automatically identify reconnaissance behavior such as port scans, SSH brute-force attempts, or unusual API calls from a suspicious IP range. Enabling GuardDuty and reviewing its severity-ranked findings gives a startup immediate, operational visibility into the attack without deploying agents or writing detection queries, and the findings can be integrated with AWS Security Hub or EventBridge for automated response.

Why this answer

Amazon GuardDuty is a managed threat detection service that uses machine learning and integrated threat intelligence to analyze VPC Flow Logs, DNS logs, and other data sources. It can automatically detect reconnaissance behavior such as port probing or port scanning from compromised EC2 instances without requiring any additional infrastructure or manual query setup. This makes it the most cost-effective solution because it operates on a pay-per-volume basis and eliminates the need for custom log analysis or per-instance agents.

Exam trap

The trap here is that candidates often assume querying VPC Flow Logs directly with CloudWatch Logs Insights is the most cost-effective approach, but they overlook the operational cost and lack of automation, while GuardDuty provides automated, managed detection with no manual query overhead.

How to eliminate wrong answers

Option B is wrong because installing a third-party intrusion detection system on each EC2 instance incurs significant overhead in terms of licensing, management, and compute resources, and it is not cost-effective compared to a managed service like GuardDuty. Option C is wrong because while CloudWatch Logs Insights can query VPC Flow Logs, it requires manual creation and tuning of queries to detect port scanning patterns, and it does not provide automated, continuous detection or threat intelligence integration, leading to higher operational cost and potential missed detections. Option D is wrong because AWS Config rules monitor changes to security group configurations, not network traffic patterns; they cannot detect active reconnaissance behavior such as port probing or scanning.

158
MCQeasy

A company has an incident response (IR) process that includes isolating compromised EC2 instances. During a security incident, the IR team needs to block all traffic to and from a compromised instance while preserving the instance for forensic analysis. Which approach should the team take?

A.Detach the instance from the Auto Scaling group and stop it.
B.Modify the security group associated with the instance to remove all inbound and outbound rules.
C.Update the network ACL for the subnet to deny all traffic.
D.Terminate the instance immediately.
AnswerB

Modifying the instance's security group to remove all inbound and outbound rules is the correct containment step because security groups are instance-level stateful firewalls, and deleting every rule immediately terminates existing and new connections while leaving the instance powered on. This preserves volatile memory and running processes for live forensics, and because the change applies only to that security group, other instances and the overall subnet remain unaffected. It is preferable to a NACL change, which would block traffic to the entire subnet.

Why this answer

Modifying the security group to remove all inbound and outbound rules effectively blocks all traffic to and from the EC2 instance because security groups act as a stateful virtual firewall at the instance level. This approach preserves the instance in its current running state, allowing the IR team to perform forensic analysis without the risk of the instance being tampered with or communicating with external systems.

Exam trap

The trap here is that candidates often confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and incorrectly assume that updating the NACL is the correct way to isolate a single instance without affecting other instances in the subnet.

How to eliminate wrong answers

Option A is wrong because detaching the instance from the Auto Scaling group and stopping it will halt the operating system and may trigger lifecycle hooks or termination policies, but it does not immediately block all network traffic during the stop process; additionally, stopping an instance can cause loss of volatile memory data critical for forensic analysis. Option C is wrong because updating the network ACL for the subnet denies traffic at the subnet level, but network ACLs are stateless and require explicit rules for both inbound and outbound traffic; moreover, the compromised instance could still communicate with other instances within the same subnet if the subnet's default rules allow it, and NACL changes affect all instances in the subnet, potentially disrupting other workloads. Option D is wrong because terminating the instance immediately destroys the instance and its attached EBS volumes (unless termination protection is enabled and volume deletion is disabled), making forensic analysis impossible and violating the requirement to preserve the instance for investigation.

159
MCQmedium

The above condition is added to an S3 bucket policy to restrict access to a specific VPC endpoint. An EC2 instance in the same VPC is unable to access the bucket. What is the most likely reason?

A.The condition should use aws:SourceVpc instead of aws:SourceVpce
B.The EC2 instance does not have a public IP address
C.The VPC endpoint policy does not allow the s3:GetObject action
D.The resource ARN in the policy is for EC2, not for S3
AnswerD

S3 bucket policies are resource-based policies attached to a bucket, so the Resource field must use the S3 ARN format arn:aws:s3:::bucket-name (or an object key pattern). Using an EC2 resource ARN, such as arn:aws:ec2:region:account-id:instance/instance-id, makes the policy invalid for S3 and therefore it does not grant or restrict access. This is the fundamental reason the bucket policy fails, regardless of any condition keys or endpoint configuration.

Why this answer

The resource ARN in the policy must reference the S3 bucket (e.g., arn:aws:s3:::bucket-name/*), not an EC2 resource. If the ARN is for EC2, the policy will not apply to S3 operations, causing the EC2 instance to be denied access regardless of the VPC endpoint condition. S3 bucket policies only take effect when the Resource element specifies the S3 bucket ARN.

Exam trap

The trap here is that candidates focus on the VPC endpoint condition (aws:SourceVpce vs aws:SourceVpc) and overlook the fundamental requirement that the Resource ARN must match the S3 bucket, not the EC2 instance.

How to eliminate wrong answers

Option A is wrong because aws:SourceVpce is the correct condition key to restrict access to a specific VPC endpoint; aws:SourceVpc is used to restrict to an entire VPC, not a specific endpoint, so using aws:SourceVpce is valid and not the cause of the failure. Option B is wrong because an EC2 instance accessing S3 via a VPC endpoint does not require a public IP address; traffic stays within the AWS network and uses private IPs. Option C is wrong because the VPC endpoint policy, if not explicitly denying s3:GetObject, would default to allowing it; the issue is with the bucket policy, not the endpoint policy.

160
Multi-Selectmedium

A security engineer is configuring Amazon GuardDuty to generate alerts for specific threat types. The engineer wants to ensure that alerts are sent to the security team's email distribution list and also trigger an automated Lambda function for immediate response. Which two actions should the engineer take? (Select TWO.)

Select 2 answers
A.Create an Amazon EventBridge rule that matches GuardDuty findings and triggers a Lambda function.
B.Configure Amazon CloudWatch Logs to send log events to an email distribution list.
C.Create an Amazon CloudWatch Events rule to route findings to a Lambda function.
D.Create an Amazon Simple Notification Service (SNS) topic and subscribe the email distribution list.
E.Create an Amazon Simple Queue Service (SQS) queue and have the Lambda function poll the queue.
AnswersA, D

Amazon GuardDuty publishes a `GuardDuty Finding` event to the default EventBridge event bus whenever a finding is generated. An EventBridge rule with an event pattern that matches finding types, account IDs, or severity can directly invoke a Lambda function as a target, giving you a serverless, near-real-time response path. This is the most idiomatic native integration for GuardDuty because it requires no polling, no extra queue, and gives you full filtering and transformation logic inside Lambda.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) can be configured with a rule that matches GuardDuty finding events. When a finding matches the rule pattern, EventBridge can directly invoke a Lambda function for automated incident response, such as isolating a compromised instance or updating security groups.

Exam trap

The trap here is that candidates may confuse CloudWatch Events (now EventBridge) with CloudWatch Logs or think that SQS alone can handle email notifications, overlooking the need for SNS to deliver messages to email distribution lists.

161
MCQhard

A company has a multi-account AWS environment with hundreds of accounts. The security team needs to ensure that all security findings from GuardDuty, Security Hub, and Detective are centrally collected and correlated. Which architecture is the MOST scalable and cost-effective?

A.Deploy a central Lambda function that polls each account's GuardDuty, Security Hub, and Detective APIs and stores findings in DynamoDB.
B.Enable AWS Security Hub as the central aggregator, with GuardDuty and Detective integrated. Use Security Hub cross-account aggregation.
C.Configure each account to send findings to a central CloudWatch Logs log group and use CloudWatch Logs Insights to correlate.
D.Stream all findings from all services to a central Amazon S3 bucket and use Amazon Athena to query them.
AnswerB

Security Hub natively acts as the central aggregator by ingesting GuardDuty findings and Detective investigation data as standard findings in the AWS Security Finding Format. Once you designate an administrator account and enable cross-account aggregation via AWS Organizations, all member accounts' findings flow into one dashboard with automatic deduplication, enrichment, and integration with EventBridge for remediation. This purpose-built architecture scales to hundreds of accounts without custom polling or log shipping.

Why this answer

AWS Security Hub natively supports cross-account aggregation via a delegated administrator, allowing findings from GuardDuty, Security Hub, and Detective to be centrally collected without custom code. This architecture is both scalable (handles hundreds of accounts without polling or custom infrastructure) and cost-effective (no additional Lambda, DynamoDB, or S3 query costs), leveraging built-in integrations and consolidated findings views.

Exam trap

The trap here is that candidates may over-engineer a solution with Lambda, DynamoDB, or S3/Athena, overlooking that Security Hub's built-in cross-account aggregation is the simplest, most scalable, and most cost-effective approach for centralizing security findings.

How to eliminate wrong answers

Option A is wrong because polling each account's APIs with a central Lambda function introduces latency, single points of failure, and significant cost at scale (Lambda invocations, DynamoDB read/write capacity), and does not leverage native cross-account aggregation features. Option C is wrong because CloudWatch Logs is not designed to receive structured findings from GuardDuty, Security Hub, or Detective natively; it would require custom log shipping and parsing, and CloudWatch Logs Insights is not optimized for correlating security findings across hundreds of accounts. Option D is wrong because streaming all findings to a central S3 bucket and querying with Athena incurs high storage and query costs, adds latency for real-time correlation, and misses native deduplication and enrichment provided by Security Hub's consolidated findings view.

162
MCQhard

A security engineer is configuring automated incident response for an Amazon EC2 instance that has been compromised. The engineer needs to isolate the instance while preserving forensic data. Which solution meets these requirements?

A.Detach the EBS volumes and attach them to a new instance in a different VPC.
B.Terminate the instance immediately to prevent further damage.
C.Create an AMI of the instance, then remove the instance from the security group to isolate it.
D.Stop the instance and change the security group to deny all traffic.
AnswerC

Creating an AMI of the running instance captures point-in-time snapshots of its EBS volumes, preserving the full disk state without requiring a stop; this enables offline forensic analysis of the root volume and any additional data volumes. Removing the instance from its security group—or applying an empty security group—immediately blocks all inbound and outbound traffic to the instance, containing the compromise while the instance remains powered on with its memory, processes, and network flows intact. This approach gives responders the ability to perform live forensics (such as memory capture) while ensuring the attacker cannot use the instance to move laterally, and it is fully reversible if the instance is later cleared.

Why this answer

Creating an AMI preserves the EBS volumes and their forensic data, while removing the instance from the security group effectively isolates it by denying all network traffic. This approach allows the engineer to later launch a forensic instance from the AMI in a controlled environment for analysis, without losing the compromised instance's state.

Exam trap

The trap here is that candidates may think stopping the instance (Option D) is sufficient for isolation, but they overlook that stopping does not prevent an attacker from restarting the instance, and it can destroy volatile forensic data.

How to eliminate wrong answers

Option A is wrong because detaching EBS volumes and attaching them to a new instance in a different VPC does not isolate the original instance; the instance remains running and could still be accessed or cause further damage. Option B is wrong because terminating the instance immediately destroys the forensic data on the instance store and EBS volumes (unless snapshots were taken beforehand), violating the requirement to preserve forensic data. Option D is wrong because stopping the instance and changing the security group to deny all traffic does not prevent the instance from being started again by an attacker with access, and stopping an instance can cause loss of in-memory forensic data (e.g., running processes, network connections).

163
MCQhard

A security engineer creates an Amazon CloudWatch Events rule with this event pattern to trigger an AWS Lambda function for automated response to GuardDuty findings. However, the Lambda function is not triggered for new findings. What is the MOST likely cause?

A.The finding type is not specified in the pattern.
B.CloudTrail is not enabled in the account.
C.The event pattern does not match the actual structure of GuardDuty findings.
D.The Lambda function does not have permission to be invoked by CloudWatch Events.
AnswerC

In a GuardDuty finding event, `detail.resources` is an array of resource objects, each containing properties like `arn`, `type`, `id`, and `partition`, rather than a flat JSON object. If the event pattern is written with `resources` as an object, such as `detail.resources.arn`, it will not match because CloudWatch Events compares the pattern against the actual array structure. An array field must be matched using an array pattern, for example `"resources": [{"arn": []}]`, so the Lambda is never invoked when the pattern has the wrong shape.

Why this answer

The event pattern provided in the CloudWatch Events rule must exactly match the JSON structure of a GuardDuty finding as it is published to the default event bus. GuardDuty findings are delivered with a specific schema that includes a `detail` object containing `type`, `severity`, and other fields. If the event pattern uses incorrect field names, nesting, or missing required elements (e.g., `source` must be `aws.guardduty`), CloudWatch Events will not match the incoming events, and the Lambda function will not be triggered.

Exam trap

The trap here is that candidates often assume the issue is a missing permission (Option D) or a missing finding type (Option A), but AWS specifically designs this question to test whether you understand that CloudWatch Events pattern matching is strict and case-sensitive, and that GuardDuty findings have a predefined event structure that must be replicated exactly.

How to eliminate wrong answers

Option A is wrong because the finding type does not need to be specified in the pattern; you can use an empty pattern or a pattern that matches all GuardDuty findings, and the function will still trigger. Option B is wrong because CloudTrail is not required for GuardDuty to publish findings to CloudWatch Events; GuardDuty sends findings directly to the default event bus via its own integration. Option D is wrong because if the Lambda function lacked permission to be invoked by CloudWatch Events, you would see an explicit error in the CloudWatch Events rule's monitoring or the Lambda function's CloudWatch Logs, and the rule would show a failed invocation count; the question states the function is not triggered at all, which points to a pattern mismatch, not a permissions issue.

164
Multi-Selecthard

A security engineer is investigating a potential incident where an EC2 instance was compromised. The engineer has access to the following logs: CloudTrail, VPC Flow Logs, and OS-level logs from the instance. Which TWO log sources would be MOST useful to determine the initial attack vector? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch Metrics for the instance
B.OS-level authentication and system logs
C.AWS CloudTrail logs
D.AWS Config configuration history
E.VPC Flow Logs
AnswersB, C

OS-level authentication and system logs (e.g., /var/log/auth.log on Linux or the Security Event Log on Windows) record each successful and failed login attempt, source IP, user account, timestamp, and sudo/su command usage. These logs can directly expose the initial access vector, such as an SSH brute-force attack or a compromised credential, and also trace post-exploitation actions like privilege escalation. Because they reside on the instance itself, they contain ground-truth details about what actually occurred inside the compromised system, which no AWS service-level log can provide.

Why this answer

OS-level authentication and system logs (option B) are critical because they record local login attempts, sudo commands, and process executions that can reveal how an attacker gained initial access—such as via SSH brute force, a compromised user account, or a vulnerable service. CloudTrail logs (option C) are equally important because they capture API calls made to AWS services, including RunInstances, CreateKeyPair, and ModifySecurityGroup, which can show if the attacker launched the instance from a compromised AWS account or modified security groups to allow inbound traffic. Together, these two sources provide the evidence needed to trace the initial compromise vector, whether it originated from within the OS or through AWS API manipulation.

Exam trap

The trap here is that candidates often pick VPC Flow Logs (option E) thinking network traffic will show the attack vector, but flow logs only show metadata like IP addresses and ports, not the authentication success or API calls that actually prove how the attacker got in.

165
MCQhard

A financial services company uses a multi-account AWS organization with a centralized security account. The security team has enabled Amazon GuardDuty in all accounts and configured it to send findings to the security account via AWS Organizations. The team also uses AWS Security Hub in the security account to aggregate findings. They have set up automated response using AWS Systems Manager Automation documents to isolate compromised EC2 instances by applying a security group that denies all traffic. However, during a recent incident, the automation failed because the Systems Automation document did not have permission to modify the security group in the member account. The security team needs to design a solution that allows the security account to automatically isolate instances in any member account. What should they do?

A.Create a Lambda function in each member account that is triggered by GuardDuty findings and modifies the security group.
B.Create a single IAM role in the security account that has permissions to modify security groups in all member accounts.
C.Use AWS CloudFormation StackSets to deploy an IAM role in each member account with permissions to modify security groups. Then, in the security account, configure the Systems Manager Automation document to assume that role when running the isolation step.
D.Modify the IAM role used by Systems Manager Automation in the security account to include permissions to modify security groups in all member accounts.
AnswerC

AWS CloudFormation StackSets deploys the same IAM role template to every member account, and the role is configured with a trust policy that allows the Systems Manager Automation execution role in the security account to assume it. The automation document uses the 'assumeRole' parameter in a step such as aws:executeScript to switch to that member account role, then runs the EC2 ModifySecurityGroup API against local resources. Because StackSets is integrated with AWS Organizations, the role is automatically provisioned when new accounts are added, centralizing governance while keeping permissions scoped per account.

Why this answer

It uses AWS CloudFormation StackSets to deploy an IAM role in each member account with the necessary permissions to modify security groups. The Systems Manager Automation document in the security account can then assume this role via a cross-account IAM role assumption, allowing it to isolate EC2 instances in any member account without requiring a single monolithic role or per-account Lambda functions.

Exam trap

The trap here is that candidates often assume a single IAM role in the security account can be granted permissions across all member accounts via resource-based policies, but in reality, cross-account access requires a role in the target account that trusts the source account, not just permissions on the source role.

How to eliminate wrong answers

Option A is wrong because creating a Lambda function in each member account triggered by GuardDuty findings would bypass the existing Systems Manager Automation workflow and introduce unnecessary complexity and duplication, rather than enabling the existing automation to work cross-account. Option B is wrong because a single IAM role in the security account cannot directly modify resources in member accounts; cross-account access requires the member account to trust the security account role via an IAM role in the member account with a trust policy. Option D is wrong because modifying the IAM role used by Systems Manager Automation in the security account to include permissions to modify security groups in all member accounts violates the principle of least privilege and is not technically feasible—AWS IAM roles are scoped to a single account and cannot grant permissions to resources in other accounts without a trust relationship and role assumption.

166
MCQmedium

A security engineer is analyzing VPC Flow Logs and sees the entry above. The source IP 203.0.113.5 is flagged as suspicious. What additional information would help determine if this is malicious?

A.The source port used by 203.0.113.5.
B.CloudTrail logs for any `ConsoleLogin` or `AssumeRole` events from 203.0.113.5.
C.Network ACL changes associated with the destination subnet.
D.Amazon GuardDuty findings for the destination 10.0.1.5.
AnswerB

CloudTrail records identity-plane events such as `ConsoleLogin` (sign-in events) and `sts:AssumeRole` with the source IP address of the caller. If the same IP 203.0.113.5 appears in these events, it directly links the network traffic to authentication or authorization activity, suggesting the IP is an active user or an attacker leveraging compromised credentials. This correlation is the strongest indicator of malicious intent because VPC Flow Logs alone cannot attribute network flows to an IAM principal, whereas CloudTrail can.

Why this answer

VPC Flow Logs capture network traffic metadata (IPs, ports, protocols) but not the identity or authentication context of the source. CloudTrail logs record API calls, including ConsoleLogin and AssumeRole events, which can reveal whether 203.0.113.5 is associated with an authenticated user or role. If no such events exist, the traffic is likely from an unauthenticated external source, strengthening the case for malicious activity.

Exam trap

The trap here is that candidates focus on network-layer indicators (ports, ACLs, GuardDuty) instead of recognizing that VPC Flow Logs lack identity context, so CloudTrail is the only service that can tie an IP to an authenticated action.

How to eliminate wrong answers

Option A is wrong because the source port is ephemeral and dynamically assigned by the OS; it provides no meaningful security context for determining malicious intent. Option C is wrong because network ACL changes affect traffic filtering rules, not the identity or behavior of the source IP; they are irrelevant to assessing whether 203.0.113.5 is malicious. Option D is wrong because GuardDuty findings for the destination 10.0.1.5 would indicate threats targeting that host, but they do not directly confirm whether the source IP 203.0.113.5 is malicious—the source could be benign even if the destination is compromised.

167
Multi-Selectmedium

A security engineer is investigating a potential compromise of an EC2 instance. The engineer wants to capture volatile memory data and create a forensic image of the instance's EBS volumes. Which TWO actions should the engineer take? (Choose 2.)

Select 2 answers
A.Enable AWS CloudTrail for the instance.
B.Use AWS Systems Manager Run Command to execute a memory capture script.
C.Use AWS Backup to create a backup of the instance.
D.Create an Amazon EBS snapshot of the instance's root volume.
E.Use Amazon Inspector to scan the instance for vulnerabilities.
AnswersB, D

Run Command uses the AWS Systems Manager (SSM) agent already installed on the instance to execute a locally supplied script, so you can run a memory acquisition tool like LiME (Linux) or WinPmem (Windows), save the memory image to a file, and upload it to Amazon S3 for analysis. Because Run Command executes without terminating or rebooting the instance, the volatile state is preserved, which is crucial for retrieving running processes, loaded kernel modules, and open network connections. The SSM agent must be running, and the instance profile needs SSM permissions and access to the destination S3 bucket.

Why this answer

AWS Systems Manager Run Command allows you to remotely execute scripts on EC2 instances without needing SSH access, which is critical during incident response to capture volatile memory data before the instance is compromised further. Option D is correct because creating an EBS snapshot provides a point-in-time forensic image of the root volume that can be analyzed offline without altering the original evidence.

Exam trap

The trap here is that candidates confuse AWS Backup (a managed backup service) with EBS snapshots, not realizing that AWS Backup does not provide the immediate, point-in-time forensic snapshot needed for incident response and may introduce additional latency or metadata changes.

168
MCQmedium

A security analyst needs to detect and respond to suspicious API activity in a multi-account AWS environment. The analyst wants near real-time detection of anomalous IAM behavior and the ability to automatically invoke a remediation Lambda function when a specific finding occurs. Which combination of AWS services provides this with the least operational overhead?

A.Amazon GuardDuty with an AWS Organizations delegated administrator, an Amazon EventBridge rule matching the finding, and the remediation Lambda function as the rule target.
B.Amazon Detective with an organization-wide graph, Amazon EventBridge rules for each account, and AWS Systems Manager Automation documents to run remediation.
C.AWS Security Hub with custom insights, Amazon CloudWatch Logs metric filters on CloudTrail, and a CloudWatch alarm that invokes the remediation Lambda function.
D.AWS CloudTrail with an organization trail, Amazon Athena queries scheduled by AWS Glue, and an Amazon SNS topic that invokes the remediation Lambda function.
AnswerA

GuardDuty continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence to produce findings in near real-time. With a delegated administrator it centrally manages all accounts in the organization. EventBridge delivers findings as events, and a rule can invoke the Lambda function directly for automated remediation with minimal overhead.

Why this answer

GuardDuty provides managed, near real-time threat detection using CloudTrail, VPC Flow Logs, DNS logs, and threat intelligence, and it integrates with Organizations through a delegated administrator so all accounts are covered centrally. EventBridge receives GuardDuty findings as events, and a rule can target a Lambda function directly, enabling automated remediation without building custom detection logic or per-account rules.

Exam trap

The trap here is assuming Security Hub or Detective generates detections, when they aggregate or investigate findings that GuardDuty and other services produce.

169
MCQhard

A company has multiple AWS accounts in AWS Organizations. The security team wants to centralize threat detection and automate incident response. Which combination of services should they use?

A.GuardDuty + Security Hub + Step Functions
B.GuardDuty + Amazon EventBridge + AWS Lambda
C.Amazon Macie + AWS Config + SNS
D.CloudTrail + CloudWatch Logs + Lambda
AnswerB

GuardDuty continuously detects threats and generates findings that are automatically emitted as events to Amazon EventBridge. An EventBridge rule filters for the relevant GuardDuty finding types and delivers them to an AWS Lambda function, which runs the remediation logic, such as quarantining an EC2 instance or revoking IAM credentials. This serverless, event-driven design provides immediate, automated response without managing underlying infrastructure.

Why this answer

GuardDuty generates threat detection findings, which are sent to Amazon EventBridge as events. EventBridge then triggers an AWS Lambda function to automate incident response actions, such as isolating an EC2 instance or revoking IAM credentials. This combination provides a fully serverless, event-driven pipeline for centralized threat detection and automated remediation across multiple AWS accounts in Organizations.

Exam trap

The trap here is that candidates often confuse Security Hub with EventBridge, thinking Security Hub is required to aggregate findings before automation, but EventBridge can directly consume GuardDuty findings without Security Hub, and Security Hub is a separate service for multi-framework compliance and aggregation, not a prerequisite for automated incident response.

How to eliminate wrong answers

Option A is wrong because Step Functions is a workflow orchestration service, not a direct event trigger for GuardDuty findings; while it can be used for complex workflows, the standard pattern for automated incident response uses EventBridge to directly invoke Lambda, making Step Functions an unnecessary and less efficient intermediate layer for simple automation. Option C is wrong because Amazon Macie focuses on sensitive data discovery in S3, not threat detection, and AWS Config tracks resource configuration changes, not security threats; SNS alone cannot automate incident response actions. Option D is wrong because CloudTrail and CloudWatch Logs are logging and monitoring services, not dedicated threat detection services; while Lambda can be triggered from CloudWatch Logs, this setup lacks GuardDuty's intelligent threat detection and requires custom log analysis to identify threats, missing the centralized threat detection requirement.

170
MCQhard

An organization uses AWS Organizations with hundreds of accounts. The security team wants to automatically respond to a specific GuardDuty finding by isolating the affected EC2 instance. What is the recommended architecture?

A.Use EventBridge to trigger a Lambda function in the delegated administrator account, which assumes an IAM role in the affected account to isolate the instance.
B.Configure GuardDuty to invoke a Lambda function in the affected account directly.
C.Use EventBridge to send the finding to a Step Functions workflow that isolates the instance.
D.Use AWS Systems Manager Automation to isolate the instance across accounts.
AnswerA

This is the AWS-recommended architecture for automated, cross-account GuardDuty response. GuardDuty publishes findings as EventBridge events, and because you are using a delegated administrator, you can centralize an EventBridge rule in that administrator account to capture findings from all member accounts. The triggered Lambda then assumes an IAM role in the specific affected member account (via the role's trust policy) to make the EC2 'isolate' API calls (e.g., stopping the instance or applying a security group) without requiring credentials stored in the Lambda. This pattern keep the response logic centralized, avoids per-account Lambda copies, and follows the secure cross-account role assumption model.

Why this answer

It follows the recommended architecture for cross-account automated response to GuardDuty findings. EventBridge in the delegated administrator account captures the finding and triggers a Lambda function, which then assumes an IAM role (using STS AssumeRole) in the affected member account to perform the isolation. This pattern centralizes management while respecting the security boundary between accounts.

Exam trap

The trap here is that candidates may assume GuardDuty can directly trigger a Lambda in any account, but in reality, GuardDuty findings are centralized in the delegated administrator account and cross-account actions require explicit role assumption via EventBridge and Lambda.

How to eliminate wrong answers

Option B is wrong because GuardDuty cannot directly invoke Lambda functions in member accounts; it can only send findings to EventBridge or to the delegated administrator account. Option C is wrong because while Step Functions can orchestrate workflows, the recommended architecture uses a Lambda function to assume a role in the affected account, not a direct Step Functions cross-account invocation (which would require additional complexity and is not the standard pattern). Option D is wrong because AWS Systems Manager Automation does not natively support cross-account isolation of EC2 instances without first assuming a role via Lambda or similar; the recommended approach uses EventBridge and Lambda, not Systems Manager Automation directly.

171
MCQhard

During a security incident, a security engineer needs to collect EBS snapshots of multiple EC2 instances across different accounts in AWS Organizations. The snapshots must be copied to a central forensics account. Which combination of steps is MOST efficient?

A.Use Amazon Data Lifecycle Manager (DLM) to create snapshots and copy them to the forensics account using S3 cross-region replication.
B.Use AWS CloudFormation StackSets to deploy a stack that creates snapshots and copies them manually.
C.Use AWS Systems Manager Automation to run scripts in each account that create snapshots and copy them to the forensics account via Lambda.
D.Use AWS Backup to create backup plans in each account and enable cross-account backup copy to the forensics account.
AnswerD

AWS Backup is the correct choice because it natively supports scheduled backup plans, retention management, and cross-account backup copy in a single service. By enabling the AWS Backup organization feature, you can centrally define backup plans and automatically apply them to resources across all accounts, with copies delivered to the forensics account. The service also handles encryption with KMS keys, monitoring with CloudWatch, and audit trails via CloudTrail, which is essential for a defensible forensic process.

Why this answer

AWS Backup is the most efficient solution because it natively supports cross-account backup copy, allowing you to create backup plans in each account and automatically copy EBS snapshots to a central forensics account without custom scripting or manual intervention. This integrates directly with AWS Organizations, enabling centralized management of backup policies across multiple accounts, which is ideal for incident response scenarios requiring rapid, consistent snapshot collection.

Exam trap

The trap here is that candidates may choose DLM (Option A) because it is commonly used for snapshot automation, but they overlook that DLM cannot copy snapshots across accounts, which is a critical requirement for cross-account forensics.

How to eliminate wrong answers

Option A is wrong because Amazon Data Lifecycle Manager (DLM) does not support cross-account snapshot copying; it can only copy snapshots within the same account or across regions, not to a different AWS account. Option B is wrong because CloudFormation StackSets can deploy stacks across accounts, but they cannot create snapshots or copy them automatically; manual copying is required, which is inefficient during an incident. Option C is wrong because Systems Manager Automation with Lambda introduces unnecessary complexity and latency; it requires custom scripts and cross-account IAM roles, whereas AWS Backup provides a managed, policy-driven solution that is more reliable and efficient.

172
MCQeasy

A company needs to ensure that all API calls in their AWS account are logged and monitored for suspicious activity. Which service should be enabled first?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the native audit service that records API activity in your account. Every supported management event and, if enabled, data event is captured with details like the IAM user/role, source IP address, time, request parameters, and response elements. CloudTrail delivers encrypted log files to an S3 bucket and optionally CloudWatch Logs for long-term retention and analysis, making it the correct service for ensuring all API calls are logged.

Why this answer

AWS CloudTrail is the correct first service to enable because it records all API calls made in the AWS account, including the identity, source IP, and timestamp of each call. This audit log is foundational for detecting suspicious activity, as it provides the raw data needed for analysis by other services like Amazon GuardDuty or third-party tools. Without CloudTrail, there is no record of API activity to monitor.

Exam trap

The trap here is that candidates often choose Amazon GuardDuty (Option A) because it is a dedicated threat detection service, but they overlook that GuardDuty relies on CloudTrail as a data source and cannot log API calls itself.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for anomalies; it cannot function without CloudTrail being enabled first. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure, not API call logging. Option C is wrong because AWS Config is a resource inventory and compliance service that tracks configuration changes to AWS resources, not API call activity.

173
MCQhard

Refer to the exhibit. A security engineer reviews this CloudFormation template. The bucket is intended to be private. What is the security issue in the configuration?

A.The PublicAccessBlock configuration is missing the BlockPublicPolicy setting.
B.The bucket does not have versioning enabled.
C.The bucket policy grants public read access to the bucket, which overrides the PublicAccessBlock configuration.
D.The bucket policy uses an incorrect resource ARN.
AnswerA

The PublicAccessBlock configuration is missing the BlockPublicPolicy setting, so S3 does not reject the bucket policy that explicitly grants public read access. When BlockPublicPolicy is not enabled, a bucket policy allowing public access is evaluated as valid and takes effect, making the bucket publicly readable. Enabling BlockPublicPolicy would cause S3 to deny the policy request and preserve the bucket's private access, thereby eliminating the public exposure.

Why this answer

The PublicAccessBlock configuration in the template is missing the BlockPublicPolicy setting. Without BlockPublicPolicy enabled, a bucket policy that grants public read access (Effect: Allow, Principal: *, Action: s3:GetObject) can be applied to the bucket, overriding the intended private configuration. The other PublicAccessBlock settings (BlockPublicAcls, IgnorePublicAcls, RestrictPublicBuckets) do not block bucket policies; only BlockPublicPolicy does.

The security issue is that the bucket policy, though present, would be blocked if BlockPublicPolicy were enabled, but since it is missing, the bucket becomes publicly accessible.

Exam trap

The trap is that candidates assume any PublicAccessBlock setting prevents public access, but BlockPublicPolicy specifically blocks bucket policies. Without it, a bucket policy granting public access can be applied, making the bucket public despite other PublicAccessBlock settings.

How to eliminate wrong answers

Option A is wrong because the PublicAccessBlock configuration includes BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets; the template shows BlockPublicPolicy set to true, so it is not missing. Option B is wrong because versioning is a data protection and recovery feature, not a security control for preventing public access; its absence does not cause the bucket to be publicly readable. Option D is wrong because the resource ARN arn:aws:s3:::my-bucket/* correctly specifies all objects in the bucket, and the bucket name matches the logical ID; the ARN is valid for the policy statement.

174
MCQhard

Refer to the exhibit. A security engineer is analyzing a VPC Flow Logs entry for an EC2 instance with private IP 192.0.2.10. The log shows an accepted outbound connection from the instance to 203.0.113.50 on port 443. The instance is not expected to initiate outbound HTTPS connections. What should the engineer do next to investigate?

A.Log into the instance and check for unauthorized processes or malware.
B.Block the IP 203.0.113.50 in the security group immediately.
C.Check the security group rules to see if outbound HTTPS is allowed.
D.Check Amazon Route 53 DNS logs to see what domain was resolved.
AnswerA

The observed egress traffic to a suspicious external IP is an indicator, but the only way to determine whether the instance is actually compromised is to inspect the operating system itself. Using a secure channel such as AWS Systems Manager Session Manager, you can examine running processes, active network sockets, scheduled tasks, and persistence mechanisms for malware, crypto miners, or reverse shells. This host-level triage is the correct immediate next step because it directly establishes the root cause and preserves forensic evidence before taking any broader network or DNS-based action.

Why this answer

The VPC Flow Logs show an accepted outbound connection from the EC2 instance to an external IP on port 443, which is unexpected behavior. The immediate next step is to log into the instance and investigate for unauthorized processes, malware, or compromised credentials that could be initiating this outbound HTTPS traffic. This aligns with incident response best practices: verify the host before making network-level changes.

Exam trap

The trap here is that candidates assume the first step is to modify network controls (security groups or DNS logs) rather than performing host-level investigation, which is the correct incident response priority when the instance itself is the source of unexpected traffic.

How to eliminate wrong answers

Option B is wrong because blocking the IP immediately without first confirming the instance is compromised could disrupt legitimate traffic or alert an attacker prematurely; security groups should be modified only after a thorough investigation. Option C is wrong because checking security group rules is unnecessary—the flow log already shows the connection was accepted, meaning outbound HTTPS is permitted; the question is why the instance is making the connection, not whether it can. Option D is wrong because Amazon Route 53 DNS logs would only show DNS queries made to Route 53, and the instance may be using an external DNS resolver or a hardcoded IP, so this step is not the immediate priority for investigating unexpected outbound traffic.

175
Drag & Dropmedium

Drag and drop the steps to configure AWS WAF with rate-based rules in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Rate-based rules require creating a web ACL first, then adding the rule, associating with a resource, testing, and monitoring.

176
MCQeasy

A security engineer is configuring an automated response to a GuardDuty finding that indicates a compromised EC2 instance. The engineer wants to isolate the instance by changing its security group to a 'quarantine' group. Which AWS service is BEST suited to automate this response?

A.AWS Step Functions
B.AWS Config
C.Amazon EventBridge
D.AWS Systems Manager Automation
AnswerC

Amazon EventBridge is the correct trigger because GuardDuty natively publishes all findings to the EventBridge default bus as events. A security engineer can create a rule with an event pattern matching GuardDuty finding types, then set a Lambda function as the target to automatically remediate or alert. EventBridge provides real-time, serverless event delivery without custom polling, making it the designed integration point for GuardDuty findings.

Why this answer

Amazon EventBridge is the best choice because it can directly receive GuardDuty findings as events and trigger an automated response, such as invoking a Lambda function or Systems Manager Automation runbook to change the EC2 instance's security group to a quarantine group. EventBridge provides native integration with GuardDuty via its default event bus, enabling real-time, event-driven automation without additional orchestration overhead.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Automation as the primary automation service, forgetting that it requires an event source like EventBridge to trigger it, making EventBridge the correct answer for the 'best suited' service to automate the response directly from GuardDuty.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service that requires an event source (like EventBridge) to trigger it; it is not the direct trigger for GuardDuty findings and adds unnecessary complexity for a simple one-step response. Option B is wrong because AWS Config is a configuration auditing and compliance service that can evaluate resource configurations and trigger remediation via Systems Manager Automation, but it cannot directly receive GuardDuty findings as events and is not designed for real-time threat response. Option D is wrong because AWS Systems Manager Automation is a runbook execution service that can perform remediation actions, but it requires an event trigger (such as EventBridge) to start; it is not the service that listens for GuardDuty findings directly.

177
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs a centralized solution to automatically initiate incident response runbooks across all accounts when a threat is detected. Which approach meets these requirements?

A.Use AWS Security Hub with cross-account aggregation and Amazon EventBridge to trigger AWS Systems Manager Automation runbooks.
B.Enable Amazon GuardDuty in all accounts and use its built-in remediation actions.
C.Configure AWS CloudFormation StackSets to deploy incident response stacks in all accounts.
D.Deploy an AWS Lambda function in each member account to respond to findings.
AnswerA

Security Hub's cross-account aggregation consolidates findings from all member accounts into a single delegated administrator account, enabling a central view of threats. You can then create EventBridge rules that match specific finding types and trigger Systems Manager Automation runbooks, which can execute remediation actions directly in the affected member account. This provides centralized, event-driven response without manually managing each account individually.

Why this answer

AWS Security Hub with cross-account aggregation collects findings from all accounts into a single administrator account. Amazon EventBridge can then be configured to match specific Security Hub findings (e.g., a GuardDuty threat detection) and trigger AWS Systems Manager Automation runbooks. This provides a centralized, automated incident response mechanism across all accounts without requiring per-account Lambda functions or manual remediation.

Exam trap

The trap here is that candidates often assume GuardDuty's built-in remediation actions are sufficient for centralized multi-account response, but those actions are per-account and lack the orchestration and customization of Security Hub + EventBridge + Systems Manager Automation.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty's built-in remediation actions are limited to predefined, account-specific responses (e.g., blocking IPs via network ACLs) and cannot be centrally orchestrated across all accounts or customized as runbooks. Option C is wrong because AWS CloudFormation StackSets deploy static infrastructure stacks, not dynamic incident response workflows triggered by real-time threats; they lack event-driven automation. Option D is wrong because deploying a Lambda function in each member account creates a decentralized, harder-to-manage solution that requires per-account IAM roles and lacks a single point of orchestration, contrary to the requirement for a centralized solution.

178
Multi-Selecthard

Which THREE services can be used to detect and alert on suspicious API activity across an AWS organization? (Choose three.)

Select 3 answers
A.Amazon Inspector
B.Amazon GuardDuty
C.AWS Config
D.AWS Security Hub
E.AWS CloudTrail
AnswersB, D, E

Amazon GuardDuty is a continuous threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS query logs. It identifies suspicious API calls, potential credential compromise, and malicious network traffic, and generates detailed findings that can be sent to CloudWatch Events to trigger automated notifications or responses. This directly enables detection and alerting on suspicious activity in near real-time.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including suspicious API activity. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS logs across an AWS organization, and can trigger alerts via Amazon EventBridge or Security Hub.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance monitoring (e.g., checking if CloudTrail is enabled) with actual threat detection, but Config does not analyze API calls for suspicious patterns—it only checks configuration state against rules.

179
MCQeasy

A security team wants to detect and alert on API calls that create or modify IAM roles in their AWS account. Which AWS service can be used to create a metric filter and alarm for these specific CloudTrail events?

A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon CloudWatch Logs
D.AWS Config
AnswerC

Amazon CloudWatch Logs can ingest CloudTrail events when a trail is configured to send events to CloudWatch Logs, and then you can create a metric filter that uses pattern matching to identify specific API calls such as 'StopInstances' or 'DeleteBucket'. The metric filter counts occurrences of matching events in near-real time, and a CloudWatch alarm on that metric can trigger an SNS notification or other action. This is a native, fully managed solution for custom API call detection and alerting, directly satisfying the security team's requirement.

Why this answer

Amazon CloudWatch Logs can create metric filters on CloudTrail log data to detect specific API calls, such as CreateRole or UpdateAssumeRolePolicy. These metric filters can then trigger CloudWatch alarms for real-time notification. CloudTrail delivers logs to CloudWatch Logs, but the metric filter and alarm capabilities reside in CloudWatch Logs, not in CloudTrail itself.

Exam trap

The trap here is that candidates often confuse CloudTrail's logging capability with CloudWatch Logs' metric and alarm features, assuming CloudTrail itself can create alarms, when in reality CloudTrail only delivers logs and CloudWatch Logs provides the filtering and alerting mechanism.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail events, VPC flow logs, and DNS logs for malicious activity, but it does not allow you to create custom metric filters or alarms for specific API calls. Option B is wrong because AWS CloudTrail records API calls and delivers log files to an S3 bucket or CloudWatch Logs, but it does not have native metric filter or alarm creation capabilities. Option D is wrong because AWS Config evaluates resource configurations against rules and tracks configuration changes, but it does not create metric filters or alarms on CloudTrail event patterns.

180
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to detect suspicious API activity across all accounts in real time. They have enabled AWS CloudTrail in all accounts and are sending logs to a centralized S3 bucket. However, they are receiving alerts only after a significant delay. What should the security team do to reduce the latency of threat detection?

A.Set up Amazon EventBridge rules in each account to send specific CloudTrail events to a centralized event bus for immediate processing.
B.Enable Amazon GuardDuty in each account and configure it to send findings to a centralized S3 bucket.
C.Configure CloudTrail to deliver logs to a single S3 bucket and use S3 Event Notifications to trigger a Lambda function.
D.Use Amazon CloudWatch Logs Insights to query CloudTrail logs across accounts in real time.
AnswerA

This is the correct approach because Amazon EventBridge can ingest CloudTrail API calls in near real time via the default event bus in each account. You can then attach a rule that matches specific CloudTrail event names (e.g., ConsoleLogin, CreateAccessKey) and routes them to a centralized event bus in a monitoring account using an EventBridge cross-account target. This enables immediate, event-driven processing through AWS Lambda, Step Functions, or SNS, and avoids the multi-minute batching delays inherent in CloudTrail S3 delivery.

Why this answer

Amazon EventBridge can be configured with rules in each account to forward specific CloudTrail events to a centralized event bus in near real time, bypassing the latency introduced by CloudTrail log delivery to S3 (which can be up to 15 minutes). This allows the security team to process and alert on suspicious API activity immediately as events occur, rather than waiting for log files to be delivered and processed.

Exam trap

The trap here is that candidates often assume CloudTrail logs in S3 are the only source for threat detection, overlooking that EventBridge can ingest CloudTrail events in real time without waiting for S3 log delivery.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty generates findings based on its own threat detection models, not on real-time CloudTrail events, and sending findings to an S3 bucket introduces similar delivery latency (up to 5 minutes for GuardDuty findings). Option C is wrong because S3 Event Notifications are typically invoked after CloudTrail delivers log files to the bucket, which can have a delay of several minutes, and they are not designed for sub-second real-time event processing. Option D is wrong because Amazon CloudWatch Logs Insights is a query tool for historical log analysis, not a real-time streaming or alerting mechanism; it cannot reduce the latency of threat detection because it queries already-delivered logs.

181
Multi-Selectmedium

Which THREE steps should a security engineer take to ensure that an incident response plan for an AWS environment is effective? (Choose three.)

Select 3 answers
A.Regularly test the incident response plan through tabletop exercises and simulations.
B.Document and maintain an up-to-date list of incident response team members and their contact information.
C.Use the AWS account root user for incident response actions to ensure full permissions.
D.Store all evidence in an S3 bucket with public read access for easy sharing.
E.Automate containment actions using AWS Lambda and AWS Systems Manager.
AnswersA, B, E

Tabletop exercises and game days on AWS simulate realistic compromise scenarios (e.g., a compromised EC2 instance or leaked access key) so responders can validate runbooks, verify IAM escalation/containment steps, and identify gaps before a real event. AWS Well-Architected and Security Incident Response guides recommend periodic testing to improve procedural accuracy, tool effectiveness, and decision-making under stress. This is a core preparedness activity.

Why this answer

Regularly testing the incident response plan through tabletop exercises and simulations validates the plan's effectiveness, identifies gaps, and ensures team readiness. AWS recommends using Game Days and fault injection simulators to practice real-world scenarios without impacting production environments.

Exam trap

The trap here is that candidates may mistakenly believe the root user is necessary for incident response due to its full permissions, but AWS best practices and the SCS-C02 exam emphasize using IAM roles with just-in-time access and MFA for all response actions.

182
MCQeasy

A company wants to automate the response to a specific GuardDuty finding. When GuardDuty detects a finding of type `UnauthorizedAccess:EC2/SSHBruteForce`, they want to automatically block the offending IP address using a network ACL. Which AWS service can they use to orchestrate this response?

A.AWS Lambda
B.AWS Systems Manager Automation
C.AWS Config
D.AWS CloudFormation
AnswerB

Systems Manager Automation is the correct service because it runs SSM runbooks in response to events via Amazon EventBridge. A GuardDuty finding event can invoke a public or custom runbook, which then performs steps such as updating a VPC Network ACL with a deny rule for the offending IP address. This service provides built-in approval gates, rollback controls, and parameterized execution, making it the native orchestration layer for GuardDuty-driven incident response rather than a mere compute or provisioning tool.

Why this answer

AWS Systems Manager Automation is the correct service because it provides a runbook-based automation framework that can be triggered by Amazon EventBridge events from GuardDuty. When GuardDuty generates a finding of type `UnauthorizedAccess:EC2/SSHBruteForce`, an EventBridge rule can invoke an SSM Automation document that modifies the network ACL to block the offending IP address. This orchestration is natively supported by SSM Automation without requiring custom code, making it the ideal choice for automated incident response workflows.

Exam trap

The trap here is that candidates often assume AWS Lambda is the only option for custom automation, but the exam specifically tests knowledge of SSM Automation as a managed orchestration service that can perform remediation actions without writing code, especially when the question uses the word 'orchestrate'.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service for running custom code, not an orchestration service; while Lambda can be used to modify network ACLs via SDK calls, the question asks for a service to 'orchestrate' the response, and SSM Automation is purpose-built for runbook-based orchestration with built-in error handling and approval steps. Option C is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules; it cannot directly modify network ACLs or execute remediation actions without invoking another service like SSM Automation or Lambda. Option D is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning and managing AWS resources; it is not designed for real-time event-driven incident response and cannot dynamically modify a network ACL in response to a GuardDuty finding without additional services.

183
MCQmedium

A security engineer is investigating a potential compromise of an IAM user. The engineer sees that the user's access keys were used from an IP address outside the company's allowed geography. Which AWS service can provide the most immediate notification of such anomalous API calls?

A.AWS Trusted Advisor
B.Amazon GuardDuty
C.AWS CloudTrail
D.Amazon CloudWatch
AnswerB

GuardDuty is a continuous, intelligent threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to identify unexpected and potentially malicious activity within your AWS environment. It analyzes CloudTrail management and data events, VPC Flow Logs, and DNS query logs to detect suspicious API calls, unusual network traffic, and compromised credentials. Findings are generated with severity levels and can automatically trigger remediation workflows via EventBridge, making it the ideal service for investigating a potential compromise.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including anomalous API calls from unusual geographies. It uses machine learning and integrated threat intelligence to analyze CloudTrail events, VPC flow logs, and DNS logs in near real-time, enabling immediate notification of suspicious activity such as access key usage from an unexpected IP address.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, forgetting that CloudTrail only records events and requires an additional service like GuardDuty or a custom CloudWatch alarm to provide immediate notification of anomalous activity.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice recommendations for cost, performance, security, and fault tolerance, but it does not monitor or alert on anomalous API calls in real-time; it is a reactive advisory tool, not a threat detection service. Option C is wrong because AWS CloudTrail is a logging service that records API activity, but it does not analyze or alert on anomalous behavior; it requires an additional service like GuardDuty or a custom CloudWatch rule to generate notifications. Option D is wrong because Amazon CloudWatch can monitor metrics and logs and trigger alarms, but it lacks built-in threat detection intelligence; to detect anomalous geolocation-based API calls, you would need to manually create custom metrics and alarms from CloudTrail logs, which is not immediate or automated compared to GuardDuty's out-of-the-box anomaly detection.

184
MCQmedium

A security engineer is investigating a potential compromise. An EC2 instance running Amazon Linux 2 is sending outbound traffic to a known malicious IP address. The engineer needs to capture the network traffic for analysis without alerting the attacker. Which solution meets these requirements?

A.Enable VPC Flow Logs on the ENI and stream to Amazon S3 for analysis.
B.Attach a security group to the instance that logs all traffic to CloudWatch Logs.
C.Use VPC Traffic Mirroring to mirror the EC2 instance's ENI traffic to a monitoring appliance in a separate VPC.
D.Enable AWS Network Firewall on the VPC and configure a rule to log all traffic to the malicious IP.
AnswerC

VPC Traffic Mirroring copies the actual packet payloads from the EC2 instance's Elastic Network Interface and forwards them through a mirror session to a monitoring appliance—which can be hosted in a separate VPC via a Gateway Load Balancer or a Network Load Balancer. Because mirroring is out-of-band and does not insert in the data path, the original traffic is unaffected and the attacker is not alerted by any inline inspection or blocking. This provides full packet capture, enabling deep forensic analysis of the attacker's actions, commands, and any exfiltrated data with no impact on the live environment.

Why this answer

VPC Traffic Mirroring captures all network traffic at the packet level from the EC2 instance's Elastic Network Interface (ENI) and forwards it to a monitoring appliance without any inline processing or modification of the traffic. This allows the security engineer to perform deep packet analysis while remaining completely transparent to the attacker, as the mirrored traffic is a copy and does not affect the original flow. Unlike other options, Traffic Mirroring provides full packet capture (including headers and payloads) for forensic analysis, which is essential for investigating a compromise.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which only provide metadata) with full packet capture, or assume that security groups or Network Firewall can log traffic passively, when in fact they are active security controls that could interfere with the attacker's activities.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture only metadata (source/destination IP, ports, protocol, packet/byte counts) and not the actual packet payloads, so they cannot provide the deep packet analysis needed for investigating a compromise. Option B is wrong because security groups are stateful firewalls that filter traffic at the instance level and do not have a logging capability to CloudWatch Logs; they only allow or deny traffic based on rules, and any logging would require additional agent-based solutions. Option D is wrong because AWS Network Firewall is a managed firewall service that inspects and potentially modifies traffic inline, which could alert the attacker by dropping or altering packets, and it does not provide passive packet capture for analysis.

185
Multi-Selectmedium

A security team suspects that an attacker has compromised an EC2 instance and is using it to launch outbound DDoS attacks. The team needs to quickly isolate the instance while preserving forensic data. Which combination of actions should the team take? (Choose TWO.)

Select 2 answers
A.Apply a restrictive security group that blocks all outbound traffic.
B.Modify the network ACL for the subnet to deny all outbound traffic.
C.Create a snapshot of the EBS volumes attached to the EC2 instance.
D.Detach the instance from the Auto Scaling group.
E.Terminate the EC2 instance immediately.
AnswersA, C

Applying a restrictive security group that blocks all outbound traffic is the right containment step because security groups act as a stateful instance-level firewall. This prevents the compromised EC2 instance from establishing new outbound connections to a command-and-control server or performing data exfiltration, while leaving the instance running so forensic artifacts like memory and processes can be collected. Inbound rules can still permit limited SSH access from approved forensic workstations, allowing incident responders to investigate without fully disconnecting the instance.

Why this answer

Applying a restrictive security group that blocks all outbound traffic immediately stops the EC2 instance from sending any network packets, including DDoS traffic, without terminating the instance. This preserves the running state and allows forensic data collection from the instance's memory and disk. Security groups act as a stateful virtual firewall at the instance level, so blocking outbound traffic effectively isolates the instance from the network.

Exam trap

The trap here is that candidates often confuse network ACLs with security groups, thinking a subnet-level NACL change is equivalent to instance-level isolation, but NACLs affect all instances in the subnet and are stateless, making them unsuitable for targeted incident response.

186
MCQeasy

A security engineer is analyzing the VPC Flow Logs entry in the exhibit. The log shows traffic from an internal IP to an external IP. Which potential security concern should the engineer investigate?

A.The instance is participating in a DDoS attack against the external IP.
B.An EC2 instance is attempting to connect to an external host on port 3389 (RDP).
C.An external host is scanning the internal network on port 443.
D.The security group allows inbound RDP from 0.0.0.0/0.
AnswerB

Outbound RDP from an internal EC2 instance to an external host on port 3389 is inherently suspicious because RDP is a remote administration protocol and is not a normal outbound service. This direction of traffic can indicate a compromised instance serving as a pivot, data exfiltration, or an attacker maintaining persistent control. The flow log shows source 10.0.1.5 (private) to destination 203.0.113.50 on port 3389, so the correct interpretation is that the instance is attempting an outbound RDP connection.

Why this answer

The VPC Flow Logs entry shows outbound traffic from an internal IP to an external IP on destination port 3389, which is the default port for Remote Desktop Protocol (RDP). RDP outbound from an EC2 instance to an external host is a security concern because it could indicate an attacker using the instance as a pivot point to connect to an external command-and-control server or to exfiltrate data via an RDP tunnel. The log direction (src internal, dst external) and port 3389 specifically point to an outbound RDP attempt, not inbound scanning or DDoS.

Exam trap

The trap here is that candidates focus on the port number (3389) and assume it is about inbound RDP from the internet, but the flow direction (src internal, dst external) indicates outbound traffic, which is a different security concern related to egress filtering and potential command-and-control activity.

How to eliminate wrong answers

Option A is wrong because a single outbound RDP connection to an external IP does not indicate participation in a DDoS attack; DDoS attacks typically involve high-volume traffic (e.g., SYN floods, UDP floods) to many targets, not a single TCP connection on port 3389. Option C is wrong because the log shows traffic from an internal IP to an external IP (src internal, dst external), not an external host scanning the internal network; scanning would have the external IP as the source. Option D is wrong because the VPC Flow Logs entry does not contain any information about security group rules; it only shows the traffic flow, and the concern is the outbound RDP attempt, not inbound rules.

187
MCQhard

During a security incident, a security engineer needs to capture network traffic from an EC2 instance for forensic analysis. The instance is part of an Auto Scaling group and may be terminated. What is the MOST efficient way to capture the traffic without affecting the instance's performance?

A.Use VPC Traffic Mirroring to mirror the instance's network traffic.
B.Enable VPC Flow Logs for the subnet.
C.SSH into the instance and run tcpdump to capture packets.
D.Attach a Network Load Balancer in front of the instance.
AnswerA

VPC Traffic Mirroring copies the full packet payload from the instance's elastic network interface to a target such as a Network Load Balancer or another ENI, operating at the hypervisor level without installing agents or consuming the instance's CPU and memory. Because the capture is passive and out-of-band, it preserves the forensic integrity of the evidence and enables thorough inspection of both inbound and outbound traffic.

Why this answer

VPC Traffic Mirroring captures all network traffic at the hypervisor level without installing agents or consuming instance CPU/memory, making it ideal for forensic analysis of an EC2 instance that may be terminated. It works by copying packets from the source ENI to a target (e.g., a Network Load Balancer or another ENI) for inspection, ensuring zero performance impact on the production instance. This approach preserves traffic even if the instance is later terminated, as the mirror session is tied to the ENI, not the instance lifecycle.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (metadata only) with full packet capture, or assume that running tcpdump on the instance is acceptable despite the performance impact and risk of data loss upon termination.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture only metadata (IP addresses, ports, protocols, packet counts) and not the actual packet payloads, making them insufficient for deep forensic analysis. Option C is wrong because running tcpdump on the instance consumes CPU and memory resources, degrading performance during a security incident, and the captured data would be lost if the instance is terminated. Option D is wrong because attaching a Network Load Balancer in front of the instance does not capture traffic; it only distributes incoming traffic and does not provide a copy of the packets for analysis.

188
MCQhard

During an incident investigation, a security analyst finds that an IAM user 'JohnDoe' has been using an access key that was last rotated over 2 years ago. The analyst needs to determine if this key has been compromised. Which approach provides the MOST definitive evidence?

A.Check the S3 access logs to see if the key was used to download sensitive data
B.Use AWS CloudTrail LookupEvents to find API calls made by the key, focusing on unusual IP addresses or times
C.Review the IAM password policy to see if the key was created before the current policy
D.Use AWS Config to see if the key's permissions have changed
AnswerB

CloudTrail LookupEvents is the correct tool because it queries the CloudTrail event history for actual API calls made by an access key, including action name, source IP address, user agent, and timestamp. You can specify the AccessKeyId in the lookup filter to see every call attributed to that key, then correlate those calls with unusual IP addresses or times to spot anomalous behavior. This gives the security analyst direct evidence of what the compromised key did across AWS services, which is exactly the goal of the investigation.

Why this answer

AWS CloudTrail LookupEvents allows you to filter API calls by user identity (such as the access key ID) and examine attributes like source IP address, user agent, and timestamp. Unusual IP addresses or times of day are strong indicators of compromise, as they suggest the key is being used from locations or at hours inconsistent with the legitimate user's behavior. This provides the most definitive evidence because it directly correlates the key's usage with anomalous patterns, rather than relying on indirect indicators like data downloads or permission changes.

Exam trap

The trap here is that candidates assume S3 access logs (Option A) are the definitive source for detecting compromise, but they miss that CloudTrail provides a complete audit trail of all API calls, including those that don't involve S3 data access, making it the superior choice for identifying anomalous behavior.

How to eliminate wrong answers

Option A is wrong because S3 access logs only show object-level operations (e.g., GetObject, PutObject) and do not capture all API calls made by the key; a compromised key might be used for reconnaissance or other actions that don't involve downloading sensitive data, so absence of such logs does not rule out compromise. Option C is wrong because the IAM password policy governs user passwords, not access keys; access key rotation is managed independently via the IAM console or API, and the password policy has no bearing on whether a key is compromised. Option D is wrong because AWS Config tracks resource configuration changes over time, but a compromised key can be used without any permission changes—attackers often use existing permissions to exfiltrate data or perform actions, so unchanged permissions do not indicate the key is safe.

189
Multi-Selecthard

A security engineer is investigating a GuardDuty finding of type 'Backdoor:EC2/C&CActivity.B!DNS'. Which TWO actions should the engineer take as part of the initial response? (Choose two.)

Select 2 answers
A.Enable Amazon GuardDuty in the account if not already enabled.
B.Isolate the EC2 instance by modifying its security group to deny all traffic.
C.Immediately terminate the EC2 instance to stop the activity.
D.Take a snapshot of the instance's EBS volume for forensic analysis.
E.Disable termination protection on the instance to allow future termination.
AnswersB, D

Replacing the instance's security group with one that has no inbound or outbound rules immediately severs network paths used for command-and-control, data exfiltration, and lateral movement while the operating system keeps running. Security groups act as a stateful virtual firewall, so removing all allow rules drops existing connections and blocks new ones without terminating the instance. This containment preserves volatile memory and disk state for subsequent forensic collection, making it the correct first response.

Why this answer

Isolating the EC2 instance by modifying its security group to deny all traffic is a critical containment step in incident response. This immediately stops the C2 (command and control) communication detected by GuardDuty's 'Backdoor:EC2/C&CActivity.B!DNS' finding, preventing further data exfiltration or lateral movement while preserving the instance for forensic analysis.

Exam trap

The trap here is that candidates may confuse incident response containment with eradication, choosing immediate termination (Option C) instead of isolation and forensic preservation (Option B and D).

190
MCQmedium

A security engineer is investigating a potential data breach. AWS CloudTrail logs show that an IAM user 'svc-backup' created an S3 bucket in the us-east-1 region and then uploaded a large number of objects. The engineer suspects that the user's credentials were compromised. What is the MOST efficient way to quickly identify the source IP address and user agent of the API calls made by this user?

A.Query AWS CloudTrail logs in Amazon Athena for the user's API calls.
B.Analyze VPC Flow Logs for traffic to the S3 bucket.
C.Enable Amazon GuardDuty and review the generated findings.
D.Use AWS Config to review the configuration history of the S3 bucket.
AnswerA

AWS CloudTrail records every S3 management and data event, including the IAM user or role, sourceIPAddress, userAgent, event name, and request parameters, and it delivers these logs as gzipped JSON to an S3 bucket. Amazon Athena can run SQL queries directly against that CloudTrail log set, allowing you to quickly filter for a specific user's API calls over a time range and correlate source IPs, user agents, and event names to determine the scope of the breach. This is the standard, authoritative method for investigating API-level activity after an incident.

Why this answer

CloudTrail logs capture detailed records of all API calls, including the source IP address and user agent for each request. By querying these logs with Amazon Athena, the security engineer can efficiently filter for the specific IAM user 'svc-backup' and extract the source IP and user agent from the relevant event records, enabling rapid identification of the compromised credentials' origin.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (which show network-level traffic) with CloudTrail logs (which show API-level activity), failing to recognize that only CloudTrail captures the IAM user identity and user agent required for this investigation.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not include user agent strings or IAM user identity; they cannot link traffic to a specific IAM user's API calls. Option C is wrong because Amazon GuardDuty generates security findings based on threat detection, but it does not provide a direct, queryable history of source IPs and user agents for past API calls; it would require additional investigation and does not offer the most efficient way to retrieve this specific historical data. Option D is wrong because AWS Config records configuration changes to resources (e.g., bucket creation, policy updates) but does not capture API call metadata such as source IP address or user agent; it is designed for compliance and configuration tracking, not for investigating API call origins.

191
MCQeasy

A security engineer is configuring an AWS environment to detect and respond to potential security threats. Which AWS service can be used to automate the remediation of unwanted access to Amazon S3 buckets by invoking AWS Lambda functions?

A.AWS Config
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS WAF
AnswerB

Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs using machine learning and integrated threat intelligence. It specifically detects suspicious S3 access patterns, such as unusual geographical locations, high-volume downloads, or bucket enumeration, and raises findings that can be sent to Amazon EventBridge. This enables automated remediation, for example a Lambda function that revokes IAM policies or applies a bucket policy, making it the correct choice for detecting and automating response to access threats.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads. It can integrate with AWS Lambda functions via CloudWatch Events to automate remediation actions, such as blocking unwanted access to S3 buckets by updating bucket policies or removing public access. This makes GuardDuty the correct choice for detecting and automatically responding to security threats against S3 resources.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to auto-remediate noncompliant resources (using AWS Config rules and Lambda) with GuardDuty's threat-specific detection and response, but AWS Config does not detect security threats like unauthorized access—it only enforces configuration rules.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it does not natively detect security threats or invoke Lambda functions for threat remediation; it can trigger Lambda for configuration drift, not for threat response. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure, not for detecting or remediating unwanted access to S3 buckets. Option D is wrong because AWS WAF is a web application firewall that protects web applications from common exploits like SQL injection and cross-site scripting, and it does not monitor or remediate S3 bucket access patterns.

192
MCQmedium

A company uses Amazon S3 to store sensitive data. The security team wants to detect and alert on public read access to S3 buckets. Which combination of AWS services is MOST appropriate?

A.AWS CloudTrail and Amazon CloudWatch Logs with metric filters for `PutBucketPolicy` events.
B.Amazon Macie with automated discovery jobs and Amazon CloudWatch Events to send alerts.
C.Amazon GuardDuty and AWS Lambda.
D.AWS Config with managed rules like `s3-bucket-public-read-prohibited` and Amazon SNS.
AnswerB

Macie automatically discovers sensitive data using managed data identifiers and also evaluates S3 bucket policies and ACLs for public access. It runs automated discovery jobs on a schedule, and you can use CloudWatch Events to trigger alerts for both sensitive data findings and policy findings. This combines content discovery with access control verification, addressing both dimensions of the requirement.

Why this answer

Amazon Macie is purpose-built for discovering and protecting sensitive data in S3, and its automated discovery jobs can detect public read access to buckets. By integrating with Amazon CloudWatch Events, Macie can trigger alerts in real-time when such access is identified, making it the most appropriate choice for this detection and alerting requirement.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation (which is periodic and reactive) with real-time detection and alerting, or they mistakenly believe CloudTrail captures all public access events, when in fact it only logs API calls that change permissions, not the resulting access state.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs `PutBucketPolicy` events, but this only captures policy changes, not the actual public read access state; a bucket could be publicly readable via ACLs or a pre-existing policy without triggering a new `PutBucketPolicy` event, leading to missed detections. Option C is wrong because GuardDuty focuses on threat detection (e.g., unusual API calls, credential compromise) and does not natively scan S3 bucket permissions for public read access; while Lambda could be used to write custom logic, it is not a direct or managed solution for this specific requirement. Option D is wrong because AWS Config managed rule `s3-bucket-public-read-prohibited` is a detective control that evaluates compliance but does not natively generate real-time alerts; while SNS can be configured, the rule only runs on periodic evaluations or configuration changes, not continuously, and it does not detect public read access via ACLs or bucket policies that are already in place.

193
Multi-Selecteasy

Which TWO AWS services can be used to detect unauthorized access to an S3 bucket? (Select TWO.)

Select 2 answers
A.AWS WAF
B.AWS CloudTrail
C.Amazon GuardDuty
D.Amazon Macie
E.AWS Config
AnswersC, D

Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to continuously monitor for malicious activity. It ingests and analyzes AWS CloudTrail event logs, VPC flow logs, and DNS logs to identify suspicious patterns, including unusual S3 access, credential compromise, or unauthorized API usage. GuardDuty generates findings that indicate potential security threats, making it a direct and effective tool for detecting unauthorized access.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze S3 data events (e.g., GetObject, PutObject) logged via CloudTrail management and data events, identifying suspicious patterns such as unusual access from a known malicious IP address or an anonymous user gaining access to an S3 bucket.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (a logging service) with a detection service, forgetting that CloudTrail only records events and does not analyze or alert on unauthorized access without additional services like GuardDuty or Amazon Detective.

194
MCQmedium

A company uses AWS Organizations and has enabled GuardDuty in the management account. The security team wants to view GuardDuty findings for all member accounts from a single delegated administrator account. Which configuration step is required?

A.Enable GuardDuty in each member account and configure cross-account IAM roles to aggregate findings in the management account.
B.Enable GuardDuty only in the management account and share findings via CloudWatch Logs cross-account subscription.
C.Designate a delegated administrator account in Organizations, then enable GuardDuty in that account. GuardDuty will automatically aggregate findings from member accounts.
D.Enable GuardDuty in the management account and use CloudWatch cross-account dashboard to view findings from member accounts.
AnswerC

This is the recommended multi-account design. By designating a delegated administrator through AWS Organizations, the admin account can enable GuardDuty across every member account with a single action and receives a consolidated view of all findings in the GuardDuty console and via the API. The delegated administrator also gains centralized control to manage member accounts, apply trusted IP lists, configure threat list filters, and create suppression rules for the entire organization. This integration is natively built into GuardDuty, so no custom IAM roles or log-forwarding pipelines are required to aggregate findings.

Why this answer

AWS Organizations allows you to designate a delegated administrator account for GuardDuty, which can then manage and view findings from all member accounts without needing to enable GuardDuty individually in each account. Once the delegated administrator is set up, GuardDuty automatically aggregates findings from all member accounts in the organization, providing a single-pane-of-glass view for the security team.

Exam trap

The trap here is that candidates often assume GuardDuty must be enabled manually in each account or that CloudWatch cross-account features can aggregate GuardDuty findings, but the exam tests knowledge of the delegated administrator feature which is the native, automated solution for multi-account aggregation.

How to eliminate wrong answers

Option A is wrong because it describes a manual, cross-account IAM role approach that is unnecessary and less efficient; GuardDuty's delegated administrator feature eliminates the need for per-account enablement and custom aggregation. Option B is wrong because enabling GuardDuty only in the management account does not allow it to monitor member account activity; GuardDuty must be enabled in each account (or via the delegated administrator) to generate findings from those accounts, and CloudWatch Logs cross-account subscription is not the intended mechanism for aggregating GuardDuty findings. Option D is wrong because CloudWatch cross-account dashboards can visualize metrics but do not automatically aggregate GuardDuty findings from member accounts; GuardDuty findings are not natively pushed to CloudWatch as metrics without additional configuration, and the delegated administrator approach is the correct method.

195
MCQmedium

A security engineer needs to detect and alert on suspicious API calls made from a compromised EC2 instance. The instance is associated with an IAM role that has permissions to call various AWS APIs. Which AWS service should the engineer use to monitor API calls and trigger alerts?

A.Amazon GuardDuty
B.AWS CloudTrail combined with Amazon CloudWatch Events
C.AWS Config
D.VPC Flow Logs
AnswerB

AWS CloudTrail records every API call made to AWS services, capturing details such as the identity, time, source IP, and request parameters. By sending these event logs to Amazon CloudWatch Events (or Amazon EventBridge), you can create custom rules to match specific API activity, such as unusual calls or attempts from unexpected regions, and trigger alerts via SNS or AWS Lambda. This combination gives you direct, real-time, and customizable detection and alerting on the API calls themselves, making it the correct choice.

Why this answer

AWS CloudTrail records all API calls made by or on behalf of the EC2 instance's IAM role. By sending these logs to Amazon CloudWatch Events (now Amazon EventBridge), you can create rules that match specific API actions (e.g., 'ec2:TerminateInstances') and trigger alerts via SNS, Lambda, or other targets. This combination provides real-time monitoring and alerting for suspicious API activity from a compromised instance.

Exam trap

The trap here is that candidates confuse GuardDuty's threat detection capabilities with the need for custom alerting on specific API calls, overlooking that CloudTrail combined with CloudWatch Events (EventBridge) is the correct service pair for granular, user-defined monitoring and alerting.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to identify malicious behavior, but it does not natively trigger custom alerts for specific API calls; it generates its own findings. Option C is wrong because AWS Config is a resource inventory and compliance service that evaluates configuration changes against rules, not a real-time API monitoring and alerting service. Option D is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log API calls or IAM role activity, so they cannot detect suspicious API calls.

196
MCQmedium

A security engineer needs to analyze large volumes of VPC Flow Logs stored in Amazon S3 to identify anomalous traffic patterns. Which approach is MOST cost-effective and scalable?

A.Use AWS Glue to catalog and query the logs.
B.Download the logs to an EC2 instance and use grep commands.
C.Use Amazon Athena with partitioned data in S3.
D.Use Amazon QuickSight to directly query the logs.
AnswerC

Amazon Athena is serverless and lets you run standard SQL directly against VPC Flow Logs stored in S3, requiring no ETL or infrastructure to manage. By partitioning the logs in S3—for example by year/month/day or by hour—you drastically reduce the amount of data scanned per query, and Athena charges per byte scanned, so partitioning cuts costs substantially. Athena is built on Presto, supports filtering, grouping, and joins, and is well suited for ad-hoc security investigations over large volumes of network traffic.

Why this answer

Amazon Athena is the most cost-effective and scalable solution for querying large volumes of VPC Flow Logs stored in S3 because it uses a serverless, pay-per-query model with no infrastructure to manage. By partitioning the data (e.g., by date or region), Athena minimizes the amount of data scanned per query, directly reducing costs while enabling complex SQL-based analysis for anomaly detection.

Exam trap

The trap here is that candidates may confuse AWS Glue's cataloging role with a query engine, or assume QuickSight can directly query S3 without an intermediate service, leading them to overlook Athena's serverless, pay-per-query model as the optimal choice for scalable log analysis.

How to eliminate wrong answers

Option A is wrong because AWS Glue is primarily a metadata catalog and ETL service, not optimized for direct ad-hoc querying of large datasets; using Glue for this purpose would incur unnecessary costs for crawlers and ETL jobs without providing the scalable, on-demand querying that Athena offers. Option B is wrong because downloading logs to an EC2 instance and using grep is not scalable for large volumes, introduces egress costs from S3, requires managing EC2 resources, and cannot efficiently handle complex analytical queries across terabytes of data. Option D is wrong because Amazon QuickSight is a business intelligence visualization tool that relies on a query engine like Athena or a database; directly querying S3 with QuickSight is not supported—it would need Athena as an intermediary, making the suggestion technically incorrect and inefficient.

197
Multi-Selectmedium

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all API calls in the organization are logged and retained for at least one year. Which AWS services or features should be used to meet these requirements? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty with threat detection enabled.
B.AWS Config with recording enabled for all resources.
C.Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.
D.VPC Flow Logs for all VPCs.
E.AWS CloudTrail with organization trail.
AnswersC, E

An S3 lifecycle policy can transition delivered log objects from frequently accessed storage classes to S3 Glacier after one year, preserving the logs for long-term audit needs while reducing cost. This is a correct component for the retention half of the requirement, provided that a delivery mechanism such as an organization CloudTrail trail first places the logs into the S3 bucket. It does not record any API activity by itself, so it is complementary to CloudTrail rather than a replacement.

Why this answer

An Amazon S3 lifecycle policy can automatically transition CloudTrail log objects from S3 Standard to S3 Glacier after one year, meeting the retention requirement cost-effectively. Option E is correct because AWS CloudTrail with an organization trail logs all API calls across all accounts in the AWS Organization, ensuring comprehensive logging.

Exam trap

The trap here is that candidates often confuse AWS Config (which records resource configuration changes) with CloudTrail (which records API calls), leading them to select Config as a logging solution for API activity.

198
Multi-Selectmedium

A security engineer is configuring an automated incident response workflow for Amazon GuardDuty findings. Which TWO actions should the engineer take to ensure that the response is triggered for all current and future GuardDuty findings?

Select 2 answers
A.Enable GuardDuty to export findings to CloudWatch Logs and then create a metric filter.
B.Create an Amazon EventBridge rule with an event pattern that matches GuardDuty finding events.
C.Create an Amazon SNS topic and subscribe the Lambda function to it, then configure GuardDuty to publish to SNS.
D.Configure the rule to invoke an AWS Lambda function that executes the incident response playbook.
E.Set up a CloudWatch Logs subscription filter to forward GuardDuty logs to the Lambda function.
AnswersB, D

GuardDuty publishes every finding as an event to the default EventBridge event bus with a source of 'aws.guardduty' and a detail-type of 'GuardDuty Finding'. A rule with an event pattern that filters on either the source or the detail-type gives you a flexible, event-driven trigger point for incident response. This approach is direct, near-real-time, and requires no extra services or log processing to detect a new security finding.

Why this answer

Amazon EventBridge can capture all GuardDuty findings by using an event pattern that matches the 'GuardDuty Finding' event type. This ensures that both current and future findings automatically trigger the rule without requiring manual updates or additional configuration.

Exam trap

The trap here is that candidates often confuse GuardDuty's integration with CloudWatch Logs (which does not exist) or assume GuardDuty can directly publish to SNS, when in fact EventBridge is the required intermediary for automated workflows.

199
MCQhard

A security engineer is investigating a potential compromise of an EC2 instance. The instance was launched from a custom AMI. The engineer needs to determine if the AMI itself contains malicious software. Which approach provides the most thorough analysis without risking the production environment?

A.Launch a test instance from the AMI in an isolated VPC and run Amazon Inspector.
B.Use AWS Systems Manager to run a compliance scan on the running instance.
C.Create an EBS snapshot from the AMI and scan the snapshot with Amazon Detective.
D.Launch a test instance from the AMI in an isolated VPC and analyze its behavior.
AnswerA

Launching an isolated test instance from the AMI prevents any risk to production resources while allowing deep inspection. Amazon Inspector automatically assesses the instance for software vulnerabilities and unintended network exposure, producing a prioritized list of findings. This approach gives a clean, controlled environment for forensics without altering the original evidence.

Why this answer

Launching a test instance from the AMI in an isolated VPC allows you to run Amazon Inspector, which performs automated vulnerability assessments and network reachability checks against the instance. This approach provides a thorough analysis of the AMI's software and configuration without exposing the production environment to any potential malicious activity. Amazon Inspector uses a knowledge base of common vulnerabilities and exposures (CVEs) and CIS benchmarks to identify security issues, making it effective for detecting malicious software embedded in the AMI.

Exam trap

The trap here is that candidates may choose Option D (behavioral analysis) because it seems more hands-on and thorough, but they overlook that Amazon Inspector provides a more systematic, automated, and comprehensive scan for known vulnerabilities and misconfigurations, which is the most efficient way to identify malicious software in an AMI without risking the production environment.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager compliance scans are designed to assess the configuration of a running instance against defined policies (e.g., patch compliance), not to detect malicious software within the AMI itself; the scan runs on the potentially compromised production instance, risking the production environment. Option C is wrong because Amazon Detective analyzes VPC flow logs, CloudTrail logs, and GuardDuty findings to investigate security incidents, but it does not scan EBS snapshots for malware; creating a snapshot from the AMI and scanning it with Detective would not reveal malicious software in the snapshot. Option D is wrong because while launching a test instance in an isolated VPC and analyzing its behavior (e.g., network traffic, process activity) can provide insights, it lacks the automated, comprehensive vulnerability scanning capabilities of Amazon Inspector, making it less thorough for identifying known malicious software or CVEs.

200
MCQmedium

A security engineer is analyzing a potential security incident involving an Amazon RDS for MySQL database. The engineer suspects that a SQL injection attack was successful. Which AWS service can the engineer use to review the actual SQL queries that were executed against the database?

A.VPC Flow Logs
B.Amazon GuardDuty
C.AWS CloudTrail
D.Amazon RDS Audit Logs
AnswerD

Amazon RDS Audit Logs are the correct source because they record the actual SQL statements executed against the database, along with the connecting user, source IP, and timestamp. For RDS MySQL or MariaDB, you enable the audit_log plugin via a DB parameter group and then export the logs to CloudWatch Logs; for PostgreSQL, you use the pgaudit extension. Misconfigured database users or SQL injection attempts will appear in these logs, making them the definitive forensic evidence during a security incident.

Why this answer

Amazon RDS for MySQL supports audit logs that capture detailed records of database activities, including the actual SQL queries executed. By enabling the `audit_log` plugin and configuring the `server_audit_events` parameter, the engineer can review the exact SQL statements that were run, which is essential for identifying a SQL injection attack. This is the only AWS service that provides query-level visibility into RDS database operations.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs control-plane API calls) with database audit logs (which log data-plane SQL queries), leading them to incorrectly select CloudTrail for reviewing executed SQL statements.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log the content of SQL queries or database operations. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes AWS CloudTrail events, VPC Flow Logs, and DNS logs for suspicious activity, but it does not provide direct access to the SQL queries executed against an RDS database. Option C is wrong because AWS CloudTrail records API calls made to the RDS service (e.g., creating a DB instance) but does not log the data-plane SQL queries executed within the database itself.

201
MCQeasy

A company has a requirement to detect and alert on S3 objects that contain personally identifiable information (PII) being shared publicly. Which AWS service should be used?

A.Amazon CloudWatch
B.Amazon GuardDuty
C.Amazon Inspector
D.Amazon Macie
AnswerD

Amazon Macie is purpose-built to discover and protect sensitive data in Amazon S3, using machine learning and pattern matching to identify personally identifiable information (PII), credentials, and other categories. After you enable Macie, it automatically inventories S3 buckets and continuously evaluates objects for sensitive content, generating alerts when it finds them. This directly aligns with the company's requirement to detect and alert on S3 object content.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data such as personally identifiable information (PII) stored in Amazon S3. It can automatically generate alerts when S3 objects containing PII are made publicly accessible, meeting the requirement to detect and alert on such events.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's threat detection capabilities (which focus on API calls and network behavior) with Macie's data classification and content inspection, leading them to select GuardDuty when the requirement specifically involves detecting PII in S3 objects.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring and observability service for metrics, logs, and alarms, not a data classification or PII detection service; it cannot natively inspect S3 object content for PII. Option B is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior using VPC Flow Logs, DNS logs, and CloudTrail events, but it does not perform content inspection of S3 objects for PII. Option C is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not S3 object content or data classification.

202
MCQhard

A security engineer is investigating a compromised IAM user whose access key was leaked. The engineer uses the AWS CLI to review CloudTrail event history but notices that recent management events performed by the compromised access key are missing. The CloudTrail trail is configured to log management events for all Regions and delivers to an S3 bucket. The engineer needs to determine whether the missing events indicate that the attacker is evading detection or that the engineer is querying the wrong data source. Which action should the engineer take FIRST to confirm the source of the discrepancy?

A.Query Amazon GuardDuty findings for the IAM user to see whether GuardDuty recorded the API calls, then correlate the GuardDuty finding timestamps with the CloudTrail event history.
B.Verify that the CloudTrail trail is logging and that the S3 bucket policy, KMS key policy, and CloudTrail service principal permissions allow the trail to deliver logs, then check the S3 bucket for the expected log file prefix and timestamps.
C.Enable AWS CloudTrail Insights on the trail to detect unusual API call rates, then review the Insights events in the S3 bucket for the compromised access key.
D.Use the AWS CloudTrail console or the aws cloudtrail lookup-events command to query the last 90 days of event history, since the event history is retained for 90 days and is separate from the trail's S3 delivery.
AnswerB

The trail delivers logs to S3 only if the bucket policy, KMS key policy, and CloudTrail service principal have the required permissions. If delivery fails, events will not appear in S3 even though the trail is enabled. Checking the bucket for the expected prefix and recent timestamps confirms whether the trail is actually delivering, which directly addresses the discrepancy before assuming attacker evasion.

Why this answer

When CloudTrail events appear missing, the first step is to confirm that the trail is actually delivering logs to its destination. A trail can be enabled yet fail delivery because the S3 bucket policy, KMS key policy, or CloudTrail service principal lacks required permissions, or because the trail was modified. Inspecting the S3 bucket for the expected log file prefix and recent timestamps distinguishes a delivery failure from attacker evasion, and it is faster and more definitive than querying event history or GuardDuty.

Exam trap

The trap here is assuming that missing CloudTrail events automatically indicate attacker evasion, when a common cause is failed log delivery due to S3 bucket policy, KMS key policy, or service principal permission issues.

203
MCQeasy

Refer to the exhibit. A security engineer is analyzing VPC Flow Logs and notices a pattern of outbound traffic from an EC2 instance to an external IP on port 22 (SSH). The engineer wants to identify which instances are initiating SSH connections to the internet. Which field in the flow log record indicates the source of the connection?

A.The first IP address in the log entry (srcaddr)
B.The second IP address (dstaddr)
C.The first port number (srcport)
D.The second port number (dstport)
AnswerA

The srcaddr field in VPC Flow Logs records the source IP address of the traffic. For outbound flows, this is the private IP address of the EC2 instance's network interface that generated the traffic. Because the question asks to identify the instance that sent the suspicious traffic, srcaddr is the correct field to filter on; it uniquely points to the originating instance within the VPC.

Why this answer

In VPC Flow Logs, the `srcaddr` field records the source IP address of the traffic. Since the engineer is looking for which EC2 instances are initiating outbound SSH connections (port 22), the source IP in the flow log entry (srcaddr) directly identifies the instance that started the connection. The direction of the traffic is determined by the source and destination fields, not by the port numbers alone.

Exam trap

The trap here is that candidates confuse the source port (srcport) with the source address (srcaddr), mistakenly thinking the port number identifies the initiating instance, when in fact the source IP address is the correct field to determine which EC2 instance started the connection.

How to eliminate wrong answers

Option B is wrong because `dstaddr` is the destination IP address (the external server), not the source EC2 instance. Option C is wrong because `srcport` is the source port number (a random ephemeral port used by the client), not the IP address of the initiating instance. Option D is wrong because `dstport` is the destination port (22 for SSH), which identifies the service but not the source of the connection.

204
Multi-Selecteasy

A security engineer needs to detect and respond to malware on an EC2 instance. Which TWO AWS services can be used together to achieve this? (Choose TWO.)

Select 2 answers
A.Amazon Inspector
B.AWS Lambda
C.Amazon CloudWatch
D.AWS WAF
E.Amazon GuardDuty with Malware Protection
AnswersB, E

AWS Lambda is correct for the response side of the detect-and-respond workflow. You can configure Lambda as the target of an Amazon GuardDuty finding through EventBridge rules, then execute a custom response playbook—such as isolating the EC2 instance by detaching security groups, stopping the instance, or capturing a forensic snapshot. This serverless execution gives security teams a fast, reproducible, and policy-driven way to contain malware without provisioning a dedicated incident-response server.

Why this answer

AWS Lambda is correct because it can be used as a serverless compute target to automate incident response actions when malware is detected. For example, a Lambda function can be triggered by a GuardDuty finding to isolate the compromised EC2 instance by modifying security group rules or detaching the instance from an Auto Scaling group, enabling rapid, automated remediation without manual intervention.

Exam trap

The trap here is that candidates often confuse Amazon Inspector's vulnerability scanning with malware detection, or assume CloudWatch alone can perform automated incident response, when in fact GuardDuty's Malware Protection is the only AWS-native service that directly detects malware on EC2, and Lambda is required for automated remediation.

205
MCQhard

During an incident, a security engineer needs to isolate a compromised Amazon EC2 instance without losing the ability to capture forensic data from its EBS volumes. What is the best course of action?

A.Terminate the instance immediately and take a snapshot after termination.
B.Take a snapshot of the EBS volumes, then detach the instance from the Auto Scaling group and modify the security group to deny all traffic.
C.Stop the instance, detach the volumes, and attach them to a forensic instance.
D.Change the security group to restrict traffic to only the forensic team's IP addresses.
AnswerB

This is the correct order: first snapshot the EBS volumes to preserve point-in-time disk evidence before any destructive or state-changing action occurs, then detach the instance from the Auto Scaling group so it won't be terminated or replaced by the group, and finally modify the security group by removing all inbound and outbound allow rules to block all network traffic and isolate the host.

Why this answer

Taking a snapshot of the EBS volumes preserves the forensic data before any changes occur, while detaching the instance from the Auto Scaling group prevents automatic replacement, and modifying the security group to deny all traffic isolates the instance without losing the running state or the ability to capture additional volatile data. This approach balances isolation with forensic preservation, ensuring the instance remains available for further analysis if needed.

Exam trap

The trap here is that candidates often confuse 'stopping' an instance with 'isolating' it, not realizing that stopping triggers OS shutdown processes that can destroy volatile evidence, whereas modifying the security group to deny all traffic achieves isolation without altering the instance state.

How to eliminate wrong answers

Option A is wrong because terminating the instance destroys the running state and any volatile data (e.g., memory, process list), and while a snapshot can be taken after termination, the EBS volumes may have been altered or deleted, losing critical forensic evidence. Option C is wrong because stopping the instance clears the instance store (if used) and may trigger OS-level shutdown scripts that could overwrite or delete forensic data; detaching volumes and attaching them to a forensic instance is a valid step but should be done after taking a snapshot to ensure a point-in-time copy, and stopping the instance is unnecessary and risky. Option D is wrong because restricting traffic to only the forensic team's IP addresses does not fully isolate the instance from lateral movement or external threats; the instance remains accessible and could still be compromised or used as a pivot point, and it does not prevent the instance from being terminated or altered by an attacker.

206
Multi-Selectmedium

Which TWO actions should a security engineer take to investigate a potential AWS API credential leak? (Choose two.)

Select 2 answers
A.Use AWS CloudTrail to review API calls made with the compromised keys.
B.Change the IAM user's password.
C.Disable all AWS services in the account.
D.Immediately rotate the compromised access keys.
E.Delete the IAM user and recreate it with the same permissions.
AnswersA, D

AWS CloudTrail is the authoritative audit service that records API calls made in your account, including the exact access key ID that signed each request. By querying CloudTrail events with the compromised access key ID, a security engineer can reconstruct the attacker's actions, identify which AWS resources were accessed or modified, and determine the scope of potential data exposure. This read-only forensic step does not alter the environment and should be performed immediately to capture evidence while the trail is still available.

Why this answer

AWS CloudTrail logs all API calls made within an AWS account, including those using compromised access keys. By reviewing these logs, a security engineer can identify the scope of the breach, such as which resources were accessed, from which IP addresses, and at what times. This is a critical first step in incident response to understand the impact and gather forensic evidence.

Exam trap

The trap here is that candidates often confuse 'rotating the keys' with 'changing the password' (Option B), not realizing that access keys and passwords are independent credentials, and that immediate rotation (Option D) is the correct containment action alongside forensic investigation (Option A).

207
MCQmedium

During a security incident, a security engineer needs to verify whether an EC2 instance's security group allowed inbound SSH from a specific IP address at the time of the incident. Which AWS service or feature should the engineer use to obtain this historical information?

A.Amazon CloudTrail event history.
B.AWS Systems Manager Inventory.
C.VPC Flow Logs.
D.AWS Config configuration history.
AnswerD

AWS Config configuration history is the correct choice because it records the complete configuration of supported AWS resources, including security groups, whenever a change occurs. Each configuration item is timestamped, so you can retrieve the exact set of security group rules at any point in time, including during the incident. This provides a reliable, auditable point-in-time state without needing to reconstruct it from API calls or traffic logs.

Why this answer

AWS Config configuration history records changes to security group rules, including the addition or removal of inbound SSH allow rules. By querying the configuration history for the specific security group, the engineer can determine the exact state of the rules at the time of the incident, including whether a specific IP address was allowed. This is the only service that provides a historical record of security group rule configurations.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show traffic) with security group configuration history, but Flow Logs only show whether traffic was permitted or denied based on the rules at that time, not the rules themselves.

How to eliminate wrong answers

Option A is wrong because CloudTrail event history logs API calls (e.g., AuthorizeSecurityGroupIngress) but does not capture the actual state of the security group rules at a point in time; it only shows when changes were made, not the current or historical configuration. Option B is wrong because AWS Systems Manager Inventory collects software and configuration data from managed instances, not security group rule history. Option C is wrong because VPC Flow Logs capture network traffic metadata (source/destination IP, port, protocol) but do not record security group rule configurations; they show traffic that was allowed or denied, not the rules themselves.

208
MCQhard

A security engineer is designing an incident response plan for a containerized application running on Amazon ECS with Fargate. The engineer needs to ensure that if a container is compromised, the incident response team can capture a memory dump and disk snapshot for forensic analysis. The containers are stateless and use ephemeral storage. Which approach provides the necessary forensic data?

A.Configure the container to stream /dev/mem to CloudWatch Logs.
B.Enable ECS task memory dumps to CloudWatch Logs.
C.Use ECS Exec to access the container and capture a memory dump; snapshot the task's ephemeral storage.
D.Stop the task and create a new task from the same image.
AnswerC

ECS Exec uses the ExecuteCommand API to open an interactive shell in a running container without opening inbound ports, allowing you to run forensic utilities like 'dd' or 'gcore' to capture volatile memory from inside the container's PID namespace. Before the task is stopped, you can also snapshot the task's ephemeral storage by copying files to an external volume or using an EBS-optimized instance to preserve the disk state. This preserves both volatile and persistent evidence, unlike stopping the task first.

Why this answer

ECS Exec allows interactive access to a running container without stopping it, enabling the capture of a memory dump (e.g., via `gcore` or `/proc/kcore`). Additionally, the task's ephemeral storage can be snapshotted while the container is still running, preserving disk state for forensic analysis. This approach aligns with incident response best practices for stateless containers on Fargate, where traditional host-level forensics are unavailable.

Exam trap

The trap here is that candidates assume stopping the task (Option D) is safe because containers are stateless, but they overlook that forensic data (memory and ephemeral disk) is lost upon task termination, making live capture via ECS Exec (Option C) the only viable method.

How to eliminate wrong answers

Option A is wrong because `/dev/mem` is not accessible in Fargate containers (no kernel-level access) and streaming it to CloudWatch Logs would not produce a usable memory dump; CloudWatch Logs is for log data, not binary forensic artifacts. Option B is wrong because ECS does not have a native feature to send task memory dumps to CloudWatch Logs; memory dumps require explicit capture via tools like `gcore` or `dd` from within the container. Option D is wrong because stopping the task destroys the ephemeral storage and the container's memory, losing all forensic evidence; creating a new task from the same image provides no snapshot of the compromised state.

209
Multi-Selecthard

A security engineer is investigating a potential compromise. The engineer has captured a memory dump from an EC2 instance and needs to analyze it for malware. Which TWO actions should the engineer take to preserve the chain of custody? (Choose TWO.)

Select 2 answers
A.Create an EBS snapshot of the instance's root volume.
B.Analyze the memory dump on the same EC2 instance.
C.Record the date, time, and digital signature of the acquisition.
D.Generate a cryptographic hash of the memory dump file.
E.Upload the memory dump to a public S3 bucket for analysis.
AnswersC, D

Recording the date, time, and digital signature of the acquisition is a cornerstone of establishing chain of custody, demonstrating exactly when the dump was taken and by whom. A digital signature binds the acquisition record to the responder and protects against later allegations that the evidence was fabricated or altered during collection. This documentation is distinct from, but complements, the hash verification that protects the integrity of the dump file itself.

Why this answer

Recording the date, time, and digital signature of the acquisition establishes a clear audit trail, which is essential for proving that the evidence has not been tampered with. In forensic investigations, this metadata is part of the standard chain-of-custody documentation that demonstrates who collected the evidence, when, and that it remains unaltered. A digital signature (e.g., using a tool like gpg or a signed hash) provides non-repudiation and integrity verification beyond a simple hash.

Exam trap

The trap here is that candidates confuse preserving the chain of custody with preserving the data itself, leading them to choose Option A (EBS snapshot) as a backup method, when in fact chain of custody is about documentation and integrity verification, not data preservation.

210
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants a centralized view of all security alerts and findings from services like GuardDuty, Security Hub, and Inspector across all accounts. What is the MOST efficient way to achieve this?

A.Use AWS Systems Manager OpsCenter to centrally view all security findings.
B.Use individual service consoles (GuardDuty, Security Hub, Inspector) for each account.
C.Use Amazon CloudWatch Logs to collect logs from each account and create custom dashboards.
D.Use AWS Security Hub with cross-account aggregation in the management account.
AnswerD

AWS Security Hub cross-account aggregation in the management account consolidates findings from GuardDuty, Inspector and Security Hub across every member account into one pane, satisfying the centralized-view requirement. It uses the Organizations management account as the aggregation administrator, avoiding per-account tooling or duplicated dashboards.

Why this answer

AWS Security Hub is designed to aggregate findings from multiple security services (GuardDuty, Inspector, etc.) across accounts. By enabling cross-account aggregation in the management account of AWS Organizations, Security Hub provides a single, centralized dashboard for all security alerts and findings without needing to collect raw logs or build custom dashboards. This is the most efficient and native approach for a multi-account environment.

Exam trap

The trap here is that candidates may think CloudWatch Logs or OpsCenter are suitable for centralized security findings, but they lack the native cross-account aggregation and structured finding format that Security Hub provides, which is the most efficient and purpose-built solution.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager OpsCenter is primarily for operational issues and incident management, not for aggregating security findings from GuardDuty, Security Hub, or Inspector across accounts; it lacks native cross-account security finding aggregation. Option B is wrong because using individual service consoles for each account is inefficient and does not provide a centralized view; it requires manual logins and lacks cross-account aggregation. Option C is wrong because Amazon CloudWatch Logs can collect logs, but building custom dashboards for security findings is complex, requires additional parsing, and does not natively aggregate structured findings from GuardDuty, Security Hub, or Inspector as Security Hub does.

211
MCQhard

A company's security team is designing an incident response plan for AWS resources. They want to ensure that when a security incident is detected in a production account, a pre-defined runbook is executed automatically. The runbook includes steps to isolate the compromised resource and collect forensic evidence. Which combination of services should the team use to implement this automation?

A.Amazon EventBridge and AWS Lambda
B.AWS Config and Amazon EC2 Auto Scaling
C.AWS Step Functions and AWS Lambda
D.AWS Systems Manager Incident Manager and AWS Systems Manager Automation
AnswerD

AWS Systems Manager Incident Manager is purpose-built to manage the full incident lifecycle—it creates an incident record, routes notifications to on-call responders, aggregates related findings, and provides a status page. Systems Manager Automation publishes runbooks (SSM documents) that can perform defined remediation steps, such as isolating an EC2 instance or revoking IAM permissions, either automatically for pre-approved actions or with manual approval. Together they give a security team a closed-loop incident response capability that can reduce mean time to respond and maintain a post-incident audit trail.

Why this answer

AWS Systems Manager Incident Manager provides the incident management lifecycle, including automated response plans that trigger runbooks when an incident is detected. AWS Systems Manager Automation runbooks contain predefined steps (e.g., isolating EC2 instances, capturing memory dumps, and collecting logs) that can be executed automatically. This combination directly meets the requirement for a pre-defined runbook that isolates the compromised resource and collects forensic evidence.

Exam trap

The trap here is that candidates often choose EventBridge and Lambda (Option A) because they are familiar with event-driven automation, but they overlook that Incident Manager provides the required incident lifecycle, response plans, and pre-built runbook templates specifically designed for security incident response.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge and AWS Lambda can trigger actions based on events, but they lack a built-in incident management lifecycle, runbook orchestration, and the ability to execute complex, multi-step forensic workflows without custom code. Option B is wrong because AWS Config evaluates resource compliance and EC2 Auto Scaling manages instance scaling; neither provides incident response automation or runbook execution for security incidents. Option C is wrong because AWS Step Functions orchestrates workflows and Lambda executes code, but this combination does not include incident detection, alerting, or the pre-defined, auditable runbook capabilities that Systems Manager Incident Manager and Automation provide.

212
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to detect and automatically respond to suspicious API calls across all accounts. Which solution is the MOST efficient and scalable?

A.Use AWS Config rules to detect API calls and trigger Lambda functions
B.Deploy Amazon GuardDuty and use its automated response feature
C.Create a CloudTrail trail in each account and aggregate logs via cross-account S3 bucket
D.Enable AWS CloudTrail organization trail and use Amazon EventBridge to invoke automated responses
AnswerD

Enabling an AWS CloudTrail organization trail in the management account automatically delivers log files for all accounts in the AWS Organization to a single S3 bucket, centralizing API activity without per-account setup. Amazon EventBridge can then ingest CloudTrail events and use rules to match specific API calls, triggering automated responses via targets like Lambda functions, Step Functions, or SNS topics. This native integration provides real-time, account-wide monitoring and response, making it the recommended and most scalable pattern.

Why this answer

Enabling an AWS CloudTrail organization trail centrally logs all API calls from every account in the AWS Organization into a single Amazon S3 bucket and CloudWatch Logs log group. Amazon EventBridge can then be used to create event rules that match specific suspicious API calls (e.g., IAM DeleteRolePolicy) and automatically invoke target actions like AWS Lambda functions or AWS Systems Manager Automation, providing a scalable, centralized, and efficient detection and response mechanism without per-account management overhead.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which evaluate configuration drift) with CloudTrail (which records API activity), or assume that GuardDuty's threat detection includes built-in automated response capabilities, when in fact both require EventBridge for custom automation, making the centralized CloudTrail organization trail plus EventBridge the most efficient and scalable solution.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are designed to evaluate resource configurations and compliance, not to detect real-time API calls; they cannot directly capture or react to API events like CloudTrail does. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS logs, VPC Flow Logs, and CloudTrail events for malicious activity, but it does not have a built-in 'automated response feature' for triggering custom remediation actions; any automated response would require integration with EventBridge or Lambda, making this option incomplete and less direct. Option C is wrong because creating a separate CloudTrail trail in each account and aggregating logs via a cross-account S3 bucket introduces significant operational overhead, duplication, and potential for inconsistent configuration, whereas an organization trail provides a single, automatically replicated trail across all accounts with no per-account setup.

213
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team wants to be alerted when an IAM user creates a new access key for another IAM user (an action that could indicate privilege escalation). What is the most effective way to detect this specific API call?

A.Query AWS CloudTrail logs using Amazon Athena on a schedule.
B.Use AWS Config to create a custom rule that checks for changes to IAM users.
C.Create an Amazon CloudWatch Events rule that matches the 'iam:CreateAccessKey' API call and sends a notification to an SNS topic.
D.Enable Amazon GuardDuty and look for the 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' finding.
AnswerC

A CloudWatch Events rule (now Amazon EventBridge) can use an event pattern matching the iam:CreateAccessKey API call emitted by CloudTrail, specifying source as 'aws.iam' and eventName as 'CreateAccessKey'. The rule can invoke an SNS topic within seconds of the API call, allowing immediate email, SMS, or Lambda-based notifications. This is the only option that is event-driven, real-time, and precisely scoped to the security-sensitive action of creating an IAM access key.

Why this answer

Amazon CloudWatch Events (now Amazon EventBridge) can be configured with a rule that matches the specific 'iam:CreateAccessKey' API call as it occurs. When this API call is made, CloudTrail delivers the event in near real-time to CloudWatch Events, which can then trigger an SNS topic to send an alert. This provides immediate, event-driven detection without the latency of scheduled queries or the overhead of custom rules.

Exam trap

The trap here is that candidates confuse AWS Config (which evaluates resource state) with CloudTrail (which records API actions), leading them to choose Option B, but Config cannot detect the API call itself—only the resulting configuration change, which may be too late or ambiguous.

How to eliminate wrong answers

Option A is wrong because querying CloudTrail logs with Amazon Athena on a schedule introduces significant delay (minutes to hours) between the API call and detection, making it unsuitable for real-time alerting. Option B is wrong because AWS Config custom rules evaluate resource configuration changes, not API calls; they can detect that an access key exists but cannot detect the specific 'iam:CreateAccessKey' API action itself. Option D is wrong because GuardDuty's 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' finding detects stolen credentials being used from an EC2 instance, not the creation of access keys for another user.

214
Multi-Selectmedium

A security engineer is configuring automated incident response for Amazon GuardDuty findings. The engineer wants to isolate a compromised EC2 instance by changing its security group and stopping the instance. Which THREE services should the engineer use together to achieve this? (Choose THREE.)

Select 3 answers
A.Amazon EC2
B.AWS Config
C.AWS Systems Manager
D.Amazon EventBridge
E.AWS Lambda
AnswersC, D, E

AWS Systems Manager is the correct choice because its Automation service provides pre-built and custom runbooks that can execute the remediation workflow, such as isolating an EC2 instance using the aws:stopInstance or aws:executeAwsApi actions. These runbooks can be triggered by an EventBridge rule that filters GuardDuty findings, and they support step-by-step error handling, conditional logic, and IAM-based approvals for safe, auditable incident response. This makes SSM the orchestrator that actually performs the automated isolation.

Why this answer

AWS Systems Manager (SSM) is correct because it provides the Automation runbook capability that can be used to stop an EC2 instance and modify its security groups as part of an incident response workflow. SSM Automation can be triggered by an EventBridge rule and can invoke Lambda functions or run commands directly on the instance to isolate it. This allows the security engineer to automate the isolation and stopping of the compromised instance without manual intervention.

Exam trap

The trap here is that candidates may think AWS Config can directly remediate findings (e.g., via AWS Config Rules with auto-remediation), but Config only triggers evaluations and cannot perform actions like stopping instances or modifying security groups without a separate automation service like SSM or Lambda.

215
Multi-Selecteasy

A company wants to detect anomalous behavior in their AWS environment. Which THREE AWS services can be used for threat detection? (Choose THREE.)

Select 3 answers
A.AWS Trusted Advisor
B.AWS Security Hub
C.AWS Config
D.Amazon GuardDuty
E.Amazon Inspector
AnswersB, D, E

AWS Security Hub is correct because it acts as a central aggregation point for security findings from multiple AWS services, including GuardDuty, Inspector, Macie, and Config, as well as partner products. It normalizes findings using the AWS Security Finding Format (ASFF) and applies consolidated security standards like CIS AWS Foundations and the AWS Foundational Security Best Practices. While it can perform correlation and enrichment, Security Hub itself does not analyze raw telemetry for anomalies; its value is in unifying and prioritizing signals across accounts and regions.

Why this answer

Amazon GuardDuty (D) is correct because it is a managed threat detection service that continuously monitors VPC Flow Logs, AWS CloudTrail management and S3 data events, and DNS logs to identify malicious or anomalous activity such as cryptocurrency mining, credential compromise, and reconnaissance. AWS Security Hub (B) is correct because it aggregates and correlates findings from GuardDuty, Inspector, Macie, and other sources, applies security standards checks, and surfaces prioritized threat-detection insights across accounts and Regions. Amazon Inspector (E) is correct because it performs automated vulnerability management by scanning EC2 instances, container images in ECR, and Lambda functions for software vulnerabilities and unintended network exposure, which supports detecting risky or anomalous configurations.

AWS Trusted Advisor (A) is not a threat-detection service; it provides best-practice checks on cost, performance, security, fault tolerance, and service quotas. AWS Config (C) is a configuration recording and compliance-evaluation service that tracks resource changes and rule compliance, but it does not itself detect threats or malicious behavior.

Exam trap

The trap here is that candidates often confuse AWS Trusted Advisor's security checks (like open port alerts) with threat detection, but Trusted Advisor is a best-practice advisor, not a real-time threat detection service—it lacks the ML-based anomaly detection and threat intelligence that GuardDuty and Security Hub provide.

← PreviousPage 3 of 3 · 215 questions total

Ready to test yourself?

Try a timed practice session using only Threat Detection questions.