SCS-C02 exam dumps

SCS-C02 practice question 42 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 42

Select 3

An organization uses AWS services such as Amazon S3, AWS Lambda, and Amazon CloudFront. They suspect unusual activity related to unauthorized access attempts to their S3 buckets. To investigate, they want to correlate access patterns across these services and identify anomalies. Which combination of steps should they take to achieve this?

  1. A

    Enable AWS CloudTrail logging across all relevant AWS services and centralize logs in an S3 bucket.

  2. B

    Use Amazon Athena to query CloudTrail logs for unusual API call patterns, such as repeated 'Denied' errors or access requests from unfamiliar IP addresses.

  3. C

    Configure AWS Config to monitor compliance rules and automatically block unauthorized access attempts to S3 buckets.

  4. D

    Enable Amazon GuardDuty to analyze access patterns across AWS accounts and detect anomalies.

  5. E

    Use Amazon Macie to scan for sensitive data in S3 buckets and identify anomalies in data access patterns.

Show answer and explanation

Correct answers: A, B, D

Explanation

To identify and investigate unauthorized access attempts, the organization needs to enable centralized logging (AWS CloudTrail), analyze access patterns for anomalies (Amazon Athena and GuardDuty), and correlate data across services. AWS Config and Amazon Macie, while valuable for compliance and data protection, do not directly address the need for anomaly detection and correlation across services.

  • A. Correct.

    Enabling AWS CloudTrail logging provides detailed event data across AWS services, which is essential for identifying and correlating access patterns.

  • B. Correct.

    Amazon Athena allows querying and analyzing CloudTrail logs, enabling the detection of unusual patterns such as unauthorized access attempts.

  • C. Incorrect.

    While AWS Config is useful for compliance monitoring, it does not directly help in correlating data across services or detecting access anomalies.

  • D. Correct.

    Amazon GuardDuty is designed to analyze activity across AWS accounts and detect anomalies, including unauthorized access attempts.

  • E. Incorrect.

    Amazon Macie focuses on discovering and protecting sensitive data, but it is not primarily used for correlating data across multiple services.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam