DOP-C02 exam dumps

DOP-C02 practice question 393 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 393

Select 3

Your company has a multi-account AWS environment managed via AWS Organizations. You are tasked with implementing a centralized security monitoring solution to detect anomalous activities, such as unauthorized access attempts or API calls from unusual locations, across all accounts. The solution must also ensure compliance with your organization's audit requirements. Which combination of steps should you take to implement this solution?

  1. A

    Enable AWS CloudTrail in each account and configure it to send logs to a centralized S3 bucket in the management account.

  2. B

    Configure Amazon GuardDuty in each account to analyze CloudTrail logs and detect suspicious activities.

  3. C

    Enable AWS Config in each account and aggregate its findings into a central AWS Config aggregator in the management account.

  4. D

    Set up AWS Security Hub in the management account and enable trusted security standards like CIS Benchmarks across all accounts.

  5. E

    Use Amazon Macie to classify sensitive data across all accounts and integrate it with AWS CloudTrail logs.

Show answer and explanation

Correct answers: A, B, D

Explanation

To implement a centralized security monitoring and auditing solution, it is essential to enable AWS CloudTrail for logging and centralize the logs for analysis, use Amazon GuardDuty for threat detection, and leverage AWS Security Hub for a unified security posture and compliance monitoring. AWS Config and Amazon Macie have their uses, but they do not directly fulfill the requirements of detecting account-level anomalous activities or centralizing security monitoring.

  • A. Correct.

    Enabling AWS CloudTrail in all accounts and centralizing the logs into an S3 bucket in the management account provides a comprehensive audit trail of API calls and other account activity, which is a foundational step for security monitoring and compliance.

  • B. Correct.

    Amazon GuardDuty is a managed threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify potential security threats like unauthorized access attempts and unusual API activity.

  • C. Incorrect.

    While AWS Config helps track resource configurations and compliance, it is not directly designed for detecting anomalous activities like unauthorized access or unusual API calls.

  • D. Correct.

    AWS Security Hub provides a centralized view of security findings from multiple AWS services, including GuardDuty, and ensures compliance with security standards like CIS Benchmarks, making it essential for security monitoring and auditing.

  • E. Incorrect.

    Amazon Macie is a data classification and protection service focused on identifying sensitive data, but it is not used for detecting account-level anomalous activities or auditing compliance.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam