SCS-C02 exam dumps

SCS-C02 practice question 163 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 163

Select 3

Your organization wants to analyze application logs generated by multiple AWS resources in near real-time to detect security anomalies. The solution must ensure that the logs are encrypted during transit and at rest, support advanced search capabilities, and enable automated responses to specific threats. Which combination of services and configurations should you use to meet these requirements?

  1. A

    Use Amazon CloudWatch Logs to collect logs and configure a subscription filter to send logs to Amazon Kinesis Data Firehose for delivery to Amazon S3 with server-side encryption enabled.

  2. B

    Enable AWS CloudTrail to capture API activity logs and configure integration with Amazon GuardDuty for anomaly detection.

  3. C

    Deploy Amazon Elasticsearch Service (Amazon OpenSearch Service) with fine-grained access control enabled for advanced log search and analysis.

  4. D

    Use Amazon S3 to store all logs and set up lifecycle policies to archive old logs to Amazon Glacier for cost optimization.

  5. E

    Configure AWS Lambda to process logs from Amazon S3 and trigger automated responses when specific patterns are detected.

Show answer and explanation

Correct answers: A, C, E

Explanation

To design a log analysis solution that supports near real-time detection of security anomalies, logs must be collected, securely stored, and analyzed for patterns. Amazon CloudWatch Logs and Amazon Kinesis Data Firehose handle collection and secure delivery. Amazon OpenSearch Service enables advanced search and analysis of log data, while AWS Lambda allows automated responses to detected threats. Together, these services fulfill the requirements for security anomaly detection, encryption, and automation.

  • A. Correct.

    Correct: Amazon CloudWatch Logs can collect logs from various AWS resources, and Amazon Kinesis Data Firehose can deliver these logs to Amazon S3 with encryption enabled, ensuring secure log storage.

  • B. Incorrect.

    Incorrect: While AWS CloudTrail and GuardDuty are useful for detecting security anomalies, they don't provide a complete log analysis solution with advanced search or automated response capabilities.

  • C. Correct.

    Correct: Amazon Elasticsearch Service (now Amazon OpenSearch Service) provides advanced search and analytics capabilities for log data, and fine-grained access control ensures secure access to log data.

  • D. Incorrect.

    Incorrect: Storing logs in Amazon S3 with lifecycle policies is a cost-effective solution for long-term log retention, but it doesn't support real-time analysis or automated responses.

  • E. Correct.

    Correct: AWS Lambda can process logs and trigger automated responses, making it a vital component of a near real-time log analysis solution.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam