SAP-C02 exam dumps

SAP-C02 practice question 114 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 114

Select 2

Your organization has a multi-account AWS environment managed within AWS Organizations. You need to design a solution where critical security events from all member accounts are forwarded to a centralized monitoring account. These events should trigger Lambda functions in the monitoring account for immediate processing. Which combination of steps is required to implement this solution?

  1. A

    Enable AWS CloudTrail in each member account and configure event delivery to an S3 bucket in the monitoring account.

  2. B

    Create a cross-account IAM role in each member account that allows the monitoring account to access CloudTrail logs.

  3. C

    Use Amazon EventBridge to create a rule in each member account that forwards security events to an Event Bus in the monitoring account.

  4. D

    Set up an EventBridge rule in the monitoring account to trigger Lambda functions based on events received from member accounts.

  5. E

    Enable Amazon GuardDuty in all member accounts and configure findings to be sent to the monitoring account.

Show answer and explanation

Correct answers: C, D

Explanation

To design a solution for multi-account security event notifications, Amazon EventBridge is the correct service to use. EventBridge allows the creation of rules in member accounts to forward specific events to an Event Bus in the monitoring account. In the monitoring account, EventBridge rules can then trigger Lambda functions for immediate processing of these events. This solution is scalable, cost-effective, and aligns with best practices for centralizing and automating security event responses in a multi-account environment.

  • A. Incorrect.

    While enabling CloudTrail in member accounts can capture security events, forwarding these logs to an S3 bucket in the monitoring account does not directly trigger Lambda functions. This approach does not fulfill the requirement for immediate event processing.

  • B. Incorrect.

    Creating a cross-account IAM role allows access to resources, but it does not inherently facilitate the forwarding of security events to the monitoring account or trigger Lambda functions.

  • C. Correct.

    Using Amazon EventBridge to forward security events to an Event Bus in the monitoring account is the correct approach for centralizing events in a multi-account environment.

  • D. Correct.

    Setting up an EventBridge rule in the monitoring account to trigger Lambda functions ensures that the events received from member accounts are processed immediately, fulfilling the solution's requirements.

  • E. Incorrect.

    Enabling GuardDuty can centralize findings, but it is not relevant to the EventBridge-based forwarding and processing of security events as described in this scenario.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam