SCS-C02 exam dumps

SCS-C02 practice question 174 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 174

Select 3

Your organization has enabled AWS CloudTrail and is using AWS CloudWatch Logs to monitor API activity. Recently, your team has observed unusual API usage patterns, potentially indicating a security issue. Which AWS service or feature combination can help you quickly identify and analyze these unusual patterns?

  1. A

    Use AWS CloudTrail Insights to detect unusual API activity and analyze trends.

  2. B

    Use AWS CloudWatch Logs Insights to query and analyze the CloudTrail logs for anomalies.

  3. C

    Enable AWS Config rules to monitor compliance and detect unusual API activity.

  4. D

    Use AWS Security Hub insights to aggregate and prioritize security findings related to unusual activity.

  5. E

    Enable AWS Trusted Advisor to monitor and detect security anomalies in CloudTrail logs.

Show answer and explanation

Correct answers: A, B, D

Explanation

To identify and analyze unusual API activity, AWS CloudTrail Insights, CloudWatch Logs Insights, and Security Hub insights are the most relevant features. CloudTrail Insights detects unusual API behavior automatically, CloudWatch Logs Insights allows you to query and analyze logs for further investigation, and Security Hub aggregates findings to help prioritize security issues. AWS Config and Trusted Advisor are not suitable for detecting or analyzing API activity anomalies.

  • A. Correct.

    AWS CloudTrail Insights is specifically designed to detect unusual API activity and provide insights into trends, making it a key tool for identifying anomalies.

  • B. Correct.

    AWS CloudWatch Logs Insights allows for querying and analyzing logs, including CloudTrail logs, to identify anomalies and investigate suspicious activity.

  • C. Incorrect.

    AWS Config is primarily used to monitor resource compliance and configuration changes, but it does not directly detect unusual API activity in logs.

  • D. Correct.

    AWS Security Hub provides insights by aggregating and prioritizing security findings from multiple sources, including CloudTrail, making it useful for identifying and prioritizing unusual activity.

  • E. Incorrect.

    AWS Trusted Advisor is focused on best practices and cost optimization, and it does not provide the capability to monitor or detect anomalies in CloudTrail logs.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam