DOP-C02 exam dumps

DOP-C02 practice question 392 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 392

Select 4

Your organization is running multiple workloads on AWS and requires a centralized security monitoring and auditing solution that provides actionable insights into account activity, ensures compliance with regulatory requirements, and integrates with AWS services for threat detection. Which set of actions should you take to implement this solution effectively?

  1. A

    Enable AWS CloudTrail and store logs in an encrypted Amazon S3 bucket with lifecycle policies.

  2. B

    Set up Amazon GuardDuty to continuously monitor for malicious activities and anomalies.

  3. C

    Use AWS Config to track changes to resources and evaluate them against compliance rules.

  4. D

    Deploy Amazon Inspector to scan for vulnerabilities in application code.

  5. E

    Integrate AWS CloudWatch with AWS Security Hub for centralized alerting and dashboarding.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

Implementing security monitoring and auditing solutions on AWS requires leveraging multiple AWS services to ensure comprehensive coverage. CloudTrail provides a record of all account activities, GuardDuty detects potential threats, AWS Config monitors compliance, and integrating CloudWatch with Security Hub centralizes alerting and dashboarding. While Amazon Inspector is useful for vulnerability scanning, it is not directly related to centralized monitoring and auditing.

  • A. Correct.

    Enabling AWS CloudTrail is essential for auditing and maintaining a record of all API activities in your AWS accounts. Storing the logs in an encrypted S3 bucket ensures security and compliance, while lifecycle policies help manage storage costs effectively.

  • B. Correct.

    Amazon GuardDuty is a managed threat detection service that uses machine learning to identify potential security threats, making it a critical component of a security monitoring solution.

  • C. Correct.

    AWS Config allows you to track changes to resource configurations and validate compliance against defined rules, ensuring that the environment adheres to security and regulatory requirements.

  • D. Incorrect.

    Amazon Inspector is a vulnerability assessment tool that scans EC2 instances and container images. While useful for vulnerability management, it is not directly related to centralized security monitoring and auditing.

  • E. Correct.

    Integrating CloudWatch with Security Hub consolidates findings from multiple AWS services, providing a unified view of security alerts and enabling actionable insights.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam