SCS-C02 exam dumps

SCS-C02 practice question 272 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 272

Select 3

Your organization has detected unusual activity originating from a specific IP range in your VPC. To investigate, you need to analyze network traffic logs and identify whether the traffic originated from internal resources or external sources. Which AWS log sources would provide the most relevant data for your investigation?

  1. A

    VPC Flow Logs

  2. B

    AWS WAF Logs

  3. C

    Route 53 Query Logs

  4. D

    CloudTrail Logs

  5. E

    Amazon S3 Access Logs

Show answer and explanation

Correct answers: A, B, C

Explanation

To investigate unusual network activity, you need log sources that provide detailed information about traffic behavior, such as VPC Flow Logs (for traffic patterns), AWS WAF Logs (for web traffic anomalies), and Route 53 Query Logs (for DNS-related activity). CloudTrail and Amazon S3 Access Logs are not directly relevant to this scenario as they focus on API activity and S3 bucket access, respectively.

  • A. Correct.

    VPC Flow Logs are the most relevant for analyzing network traffic at the VPC level, including source and destination IP addresses, protocols, and ports. This is essential for identifying internal and external traffic.

  • B. Correct.

    AWS WAF Logs are useful for identifying unusual or malicious web traffic at the application layer, such as SQL injection or IP blocking, which might be part of the unusual activity.

  • C. Correct.

    Route 53 Query Logs provide insights into DNS queries and can help identify whether the suspected IP range is associated with specific domain lookups, which might indicate external traffic.

  • D. Incorrect.

    CloudTrail Logs primarily track API activity within your AWS environment, but they do not capture detailed VPC network traffic, making them less relevant for this investigation.

  • E. Incorrect.

    Amazon S3 Access Logs capture requests made to S3 buckets, which is unrelated to analyzing unusual network activity in a VPC.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam