SCS-C02 exam dumps

SCS-C02 practice question 221 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 221

Select 2

You are a security engineer reviewing your organization's network monitoring strategy within AWS. The goal is to identify potential security threats and anomalies within network traffic. Which combination of services can you use to capture and analyze network traffic and metadata for this purpose?

  1. A

    Traffic Mirroring and Amazon CloudWatch Logs

  2. B

    VPC Flow Logs and Amazon Athena

  3. C

    Traffic Mirroring and AWS Network Firewall

  4. D

    VPC Flow Logs and AWS WAF

  5. E

    AWS Config and Amazon S3

Show answer and explanation

Correct answers: A, B

Explanation

To detect security threats and anomalies in network traffic, you need to capture and analyze either actual network packets or metadata. Traffic Mirroring captures full network packets for analysis, while VPC Flow Logs capture metadata about traffic flows. Tools like Amazon CloudWatch Logs and Amazon Athena enable storage and querying of this data, making the correct pairs Traffic Mirroring with CloudWatch Logs and VPC Flow Logs with Athena.

  • A. Correct.

    Traffic Mirroring allows you to capture actual network packets for analysis, and Amazon CloudWatch Logs can store and process log data, making this a valid combination for capturing and analyzing network activity.

  • B. Correct.

    VPC Flow Logs capture metadata about IP traffic going to and from network interfaces in your VPC, and Amazon Athena can be used to query and analyze this metadata, making this a valid combination.

  • C. Incorrect.

    While Traffic Mirroring can capture network packets, AWS Network Firewall is primarily for monitoring and filtering network traffic in real-time, rather than analyzing captured data retrospectively.

  • D. Incorrect.

    VPC Flow Logs provide metadata about network traffic, but AWS WAF is primarily used to protect web applications from threats. This combination does not focus on comprehensive traffic analysis.

  • E. Incorrect.

    AWS Config is a configuration management tool and does not capture or analyze network traffic. Storing data in Amazon S3 without a relevant telemetry source like VPC Flow Logs or Traffic Mirroring does not address the stated purpose.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam