SCS-C02 exam dumps

SCS-C02 practice question 2 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 2

Select 2

Your organization uses AWS CloudTrail for logging API activity in your AWS environment. A security analyst reports suspicious activity related to IAM roles and requests your assistance in investigating the issue. To detect unauthorized access attempts to IAM roles and identify potential security threats, which combination of actions should you take?

  1. A

    Use Amazon CloudWatch Logs Insights to query CloudTrail logs for AssumeRole API events.

  2. B

    Set up a CloudWatch alarm to monitor for changes to IAM policies and roles.

  3. C

    Enable Amazon GuardDuty to detect unusual activity related to IAM roles.

  4. D

    Use AWS Config to review the historical configuration changes for IAM roles.

  5. E

    Enable AWS Security Hub to automatically block suspicious IAM role activity.

Show answer and explanation

Correct answers: A, C

Explanation

To effectively detect unauthorized access attempts to IAM roles and identify potential security threats, you should focus on analyzing relevant API activity and leveraging threat detection services. Querying AssumeRole events in CloudTrail logs helps identify unauthorized access attempts, while Amazon GuardDuty provides detection for unusual or anomalous activity related to IAM roles. Other options, such as AWS Config and Security Hub, provide valuable insights for compliance and aggregation but are not specifically targeted at detecting unauthorized role access in this scenario.

  • A. Correct.

    Correct. Querying CloudTrail logs using CloudWatch Logs Insights allows you to analyze AssumeRole API events and identify unauthorized or unusual access attempts.

  • B. Incorrect.

    Incorrect. Monitoring changes to IAM policies and roles is useful for compliance and configuration management but does not directly detect unauthorized access attempts to IAM roles.

  • C. Correct.

    Correct. Amazon GuardDuty provides threat detection capabilities and can identify unusual activity related to IAM roles, such as anomalous API calls.

  • D. Incorrect.

    Incorrect. AWS Config helps track configuration changes but does not provide direct detection of unauthorized access attempts or unusual activity.

  • E. Incorrect.

    Incorrect. AWS Security Hub aggregates findings but does not automatically block suspicious activity. Blocking requires additional configuration or tools.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam