SCS-C02 exam dumps

SCS-C02 practice question 43 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 43

Select 2

An organization is using AWS CloudTrail to monitor API activity, AWS Config for resource configurations, and Amazon GuardDuty for threat detection. They suspect unauthorized access attempts based on an anomaly in user behavior patterns. The security team wants to correlate data from these services to identify the root cause of the issue. Which combination of approaches should they use to effectively achieve this?

  1. A

    Use Amazon Athena to query CloudTrail logs, Config snapshots, and GuardDuty findings stored in Amazon S3.

  2. B

    Enable Amazon Macie to automatically classify sensitive data across these services and identify anomalies.

  3. C

    Leverage AWS Security Hub to aggregate and correlate GuardDuty findings with CloudTrail and Config data.

  4. D

    Set up an Amazon EventBridge rule to detect specific CloudTrail events and trigger a Lambda function for analysis.

  5. E

    Integrate CloudWatch Logs Insights for real-time querying of all relevant logs and findings from these services.

Show answer and explanation

Correct answers: A, C

Explanation

To effectively correlate and analyze data across CloudTrail, AWS Config, and GuardDuty, you can use Amazon Athena to query logs stored in S3, as it provides powerful querying capabilities across diverse datasets. Additionally, AWS Security Hub aggregates findings from multiple AWS services, allowing you to correlate and detect anomalies in a centralized manner. Combining these services ensures comprehensive analysis and anomaly detection.

  • A. Correct.

    This is correct. Amazon Athena can query structured data across multiple services, such as CloudTrail, Config, and GuardDuty logs stored in S3, making it an effective tool for correlation.

  • B. Incorrect.

    This is incorrect. Amazon Macie focuses on sensitive data discovery and classification, not on correlating data across multiple services like GuardDuty, Config, and CloudTrail.

  • C. Correct.

    This is correct. AWS Security Hub aggregates findings from multiple AWS services, including GuardDuty, CloudTrail, and Config, providing a unified view for correlation and anomaly detection.

  • D. Incorrect.

    This is incorrect. While EventBridge rules can trigger actions based on specific events, it is not designed to perform comprehensive anomaly detection or data correlation across multiple services.

  • E. Incorrect.

    This is incorrect. CloudWatch Logs Insights is useful for querying real-time logs but does not provide a holistic correlation capability across GuardDuty, CloudTrail, and AWS Config.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam