SCS-C02 Question 22
Single answerAn organization has developed an incident response plan for its AWS environment. During a simulated security breach, it was discovered that no one was explicitly assigned the responsibility of analyzing AWS CloudTrail logs to identify the source of the incident. Which role should be designated to handle this responsibility within the incident response plan?
- A
Security Analyst
- B
Cloud Architect
- C
Incident Commander
- D
AWS Support Engineer
Show answer and explanation
Correct answer: A
Explanation
The Security Analyst is the most appropriate role to handle AWS CloudTrail log analysis during an incident. This task requires expertise in security monitoring and log forensics, which are core responsibilities of a Security Analyst. Assigning this responsibility ensures that potential threats are identified quickly and effectively during incident response.
- A. Correct.
A Security Analyst is typically responsible for analyzing security logs, such as AWS CloudTrail logs, to identify the root cause of an incident. This falls directly within their expertise and responsibilities in an incident response plan.
- B. Incorrect.
A Cloud Architect focuses on designing and implementing the cloud infrastructure. While they may have knowledge of AWS CloudTrail, analyzing its logs during a security incident is not their primary responsibility.
- C. Incorrect.
An Incident Commander coordinates the overall response process, ensuring tasks are assigned and executed effectively. They oversee the incident but do not perform specific technical tasks like log analysis.
- D. Incorrect.
An AWS Support Engineer is an external party that provides support for AWS services. They may assist in troubleshooting but are not part of an internal organization's incident response plan roles.