DOP-C02 exam dumps

DOP-C02 practice question 394 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 394

Select 3

Your organization has a requirement to monitor and audit all API calls made to AWS resources for security and compliance purposes. You also need to detect unusual activity, such as unauthorized access attempts, and send alerts in near real-time. Which combination of services should you implement to meet these requirements?

  1. A

    Enable AWS CloudTrail to capture API activity logs

  2. B

    Use Amazon GuardDuty to detect unusual and unauthorized activity

  3. C

    Configure Amazon Macie to monitor API access patterns for sensitive data

  4. D

    Set up Amazon CloudWatch Alarms to monitor specific metrics and send alerts

  5. E

    Enable AWS Config to track configuration changes to AWS resources

Show answer and explanation

Correct answers: A, B, D

Explanation

To implement a comprehensive security monitoring and auditing solution, you need to enable AWS CloudTrail to capture API activity logs, use Amazon GuardDuty to detect unusual activity such as unauthorized access, and set up Amazon CloudWatch Alarms to generate alerts for specific security events. While other services like Amazon Macie and AWS Config serve important security and compliance functions, they do not directly fulfill the requirements outlined in this scenario.

  • A. Correct.

    Enabling AWS CloudTrail is essential for capturing API activity logs, which provide a detailed audit trail for monitoring and compliance.

  • B. Correct.

    Amazon GuardDuty is a threat detection service that can identify unusual and unauthorized activity, such as compromised credentials or anomalous API usage.

  • C. Incorrect.

    Amazon Macie is used to detect and protect sensitive data like personally identifiable information (PII) but is not directly used for monitoring API access patterns or detecting unauthorized activity.

  • D. Correct.

    Amazon CloudWatch Alarms can be configured to monitor specific metrics, such as unauthorized API calls or changes in usage patterns, and trigger alerts in near real-time.

  • E. Incorrect.

    AWS Config is primarily used to track configuration changes to resources and ensure compliance with security policies, but it does not directly monitor API activity or detect unauthorized access.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam