SCS-C02 exam dumps

SCS-C02 practice question 176 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 176

Select 3

An organization wants to monitor unusual activity patterns in its AWS environment to detect potential security threats. They are already collecting logs from AWS CloudTrail, Amazon CloudWatch Logs, and AWS Config. Which combination of solutions should they use to identify anomalies, correlate findings, and visualize insights effectively?

  1. A

    Enable CloudTrail Insights to automatically detect unusual write management API activity patterns.

  2. B

    Use Amazon CloudWatch Logs Insights to query logs and build custom dashboards for anomaly detection.

  3. C

    Integrate AWS Security Hub to aggregate, analyze, and correlate security findings from multiple AWS services.

  4. D

    Enable S3 Event Notifications to automatically detect anomalies in log files stored in Amazon S3.

  5. E

    Use AWS Trusted Advisor to identify unusual activity patterns in API logs.

Show answer and explanation

Correct answers: A, B, C

Explanation

To effectively monitor and detect unusual activity patterns in the AWS environment, the organization should use a combination of CloudTrail Insights, CloudWatch Logs Insights, and AWS Security Hub. CloudTrail Insights detects unusual API activity, CloudWatch Logs Insights enables querying and visualization of log data, and Security Hub provides centralized correlation and analysis of security findings. S3 Event Notifications and Trusted Advisor are not suitable for this specific use case.

  • A. Correct.

    CloudTrail Insights is designed to automatically detect unusual activity patterns, such as spikes in API calls, and can help the organization identify potential security threats.

  • B. Correct.

    CloudWatch Logs Insights allows querying and analyzing log data interactively, enabling the organization to create customized dashboards for identifying anomalies.

  • C. Correct.

    AWS Security Hub aggregates findings from different AWS services, such as CloudTrail and GuardDuty, providing centralized insights and correlation of security-related events.

  • D. Incorrect.

    S3 Event Notifications are not designed for detecting anomalies in logs. They are used to trigger actions like Lambda functions when events occur in an S3 bucket.

  • E. Incorrect.

    AWS Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance, but it does not analyze logs or detect activity anomalies.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam