SCS-C02 exam dumps

SCS-C02 practice question 156 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 156

Select 3

Your organization recently implemented AWS services for their infrastructure. As a security engineer, you are tasked with ensuring proper logging of network activity, API-level actions, and DNS queries for compliance and forensic purposes. Which AWS services should you configure to meet these requirements?

  1. A

    Enable AWS CloudTrail for capturing API-level activity across all AWS resources.

  2. B

    Enable VPC Flow Logs to capture network traffic metadata within a VPC.

  3. C

    Enable AWS Config to monitor and log changes to resource configurations.

  4. D

    Enable Amazon Route 53 DNS Query Logs to capture DNS resolution activity.

  5. E

    Enable AWS Shield Advanced to log DDoS mitigation activities.

Show answer and explanation

Correct answers: A, B, D

Explanation

To ensure proper logging for compliance and forensic purposes, you need to configure AWS CloudTrail for API-level actions, VPC Flow Logs for network activity, and Amazon Route 53 DNS Query Logs for DNS resolution activity. AWS Config and AWS Shield Advanced are not relevant for this specific logging requirement.

  • A. Correct.

    AWS CloudTrail provides a detailed log of API calls made in your AWS account, which is essential for tracking API-level actions.

  • B. Correct.

    VPC Flow Logs capture metadata about network traffic within a VPC, which is critical for understanding network activity and troubleshooting.

  • C. Incorrect.

    AWS Config tracks configuration changes to AWS resources but does not provide logging for network activity or DNS queries.

  • D. Correct.

    Amazon Route 53 DNS Query Logs allow you to capture details about DNS queries, helping you monitor DNS resolution activity.

  • E. Incorrect.

    AWS Shield Advanced provides DDoS protection but is not a logging service for network, API, or DNS activity.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam