SCS-C02 exam dumps

SCS-C02 practice question 69 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 69

Select 2

An organization is experiencing unexpected API calls being made to their AWS environment, which are coming from an unknown external IP address. You are tasked to investigate and determine the root cause. Which of the following steps would you take to perform a root cause analysis? (Select TWO)

  1. A

    Analyze AWS CloudTrail logs to identify the source of the API calls and associated credentials.

  2. B

    Terminate the EC2 instance that is suspected of being compromised.

  3. C

    Use AWS Config to review changes made to IAM policies and roles.

  4. D

    Enable VPC Flow Logs to capture detailed information about the traffic from the suspicious IP address.

  5. E

    Generate an IAM Access Advisor report to identify overly permissive access rights.

Show answer and explanation

Correct answers: A, C

Explanation

To perform root cause analysis for unexpected API calls, it is crucial to investigate the source of the API requests and any changes made to IAM resources. CloudTrail logs provide visibility into API activity, while AWS Config enables you to track changes to IAM policies and roles, which could reveal unauthorized modifications. These steps are critical for identifying and addressing the root cause of the issue.

  • A. Correct.

    CloudTrail logs provide detailed information about API calls, including the source, time, and user/role making the request. This is essential for identifying the root cause of the issue.

  • B. Incorrect.

    While terminating a potentially compromised instance might mitigate the immediate threat, it does not help in identifying the root cause of the unknown API calls.

  • C. Correct.

    AWS Config tracks changes to resources, including IAM policies and roles. Reviewing these changes can help identify if any roles or policies were modified maliciously, aiding in root cause analysis.

  • D. Incorrect.

    VPC Flow Logs are useful for monitoring network traffic but do not provide information about API calls or IAM actions, which is crucial for this scenario.

  • E. Incorrect.

    IAM Access Advisor helps in identifying unused permissions but is not directly relevant for determining the source of suspicious API calls.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam