SCS-C02 exam dumps

SCS-C02 practice question 14 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 14

Select 3

Your organization uses AWS services to host its web application, and you are responsible for designing an incident response plan. As part of the preparation phase, your team has decided to automate certain steps to respond to security incidents, such as unauthorized changes to IAM permissions. Which combination of AWS services and features should you use to detect and respond to such incidents automatically?

  1. A

    Amazon CloudWatch Alarms to trigger an automated Lambda function to revert unauthorized IAM changes

  2. B

    AWS Config with a custom rule to detect IAM policy changes and trigger an SNS notification

  3. C

    AWS CloudTrail to log all API activity and integrate with Amazon GuardDuty to detect suspicious activity

  4. D

    AWS Systems Manager Automation to manually run an incident response workflow for IAM changes

  5. E

    Amazon S3 Event Notifications to monitor IAM changes and trigger automated actions

Show answer and explanation

Correct answers: A, B, C

Explanation

AWS best practices for incident response emphasize automation in detecting and responding to security incidents. Amazon CloudWatch, AWS Config, and AWS CloudTrail (integrated with GuardDuty) collectively enable real-time detection and automated response to IAM permission changes. These tools work together to ensure incidents are identified and mitigated with minimal manual intervention, aligning with AWS's incident response preparation phase.

  • A. Correct.

    Correct: Amazon CloudWatch Alarms can monitor specific metrics or conditions (such as unauthorized IAM changes) and trigger automated actions, such as invoking a Lambda function to revert changes.

  • B. Correct.

    Correct: AWS Config can be set up with custom rules to detect IAM policy changes. When a rule is violated, it can trigger an SNS notification or other automated workflows.

  • C. Correct.

    Correct: AWS CloudTrail logs all API activity, and when integrated with Amazon GuardDuty, it can detect suspicious activity such as unauthorized IAM changes, enabling automated incident detection and response.

  • D. Incorrect.

    Incorrect: AWS Systems Manager Automation is a useful tool for predefined workflows, but it is designed primarily for manual or semi-automated responses rather than real-time automated incident detection.

  • E. Incorrect.

    Incorrect: Amazon S3 Event Notifications are specific to S3 bucket events, such as object creation or deletion. It is not applicable for monitoring IAM changes.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam