SCS-C02 exam dumps

SCS-C02 practice question 8 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 8

Select 4

Your company runs a multi-account AWS environment using AWS Organizations. You are tasked with designing an incident response plan for detecting and responding to potential security breaches. Which of the following actions should be included in your incident response plan to ensure effective detection and coordination across accounts?

  1. A

    Enable GuardDuty in the management account and configure it to aggregate findings from all member accounts.

  2. B

    Set up CloudTrail in every account and send logs to a centralized S3 bucket with appropriate permissions.

  3. C

    Use AWS Config to ensure CloudTrail is enabled and configured correctly in all accounts.

  4. D

    Implement a Security Hub administrator account to view and manage findings across all accounts.

  5. E

    Rely on manual log analysis during incidents to reduce costs associated with automated monitoring services.

Show answer and explanation

Correct answers: A, B, C, D

Explanation

An effective incident response plan in a multi-account AWS environment should prioritize centralized monitoring, log aggregation, and compliance enforcement. GuardDuty, CloudTrail, AWS Config, and Security Hub each play critical roles in ensuring comprehensive detection, logging, and response capabilities. Manual log analysis is not practical in modern cloud environments as it is slow and error-prone.

  • A. Correct.

    Correct. Enabling GuardDuty in the management account and aggregating findings from member accounts ensures centralized threat detection and monitoring, which is vital for incident response.

  • B. Correct.

    Correct. Centralizing CloudTrail logs in an S3 bucket allows for unified visibility and access to logs, which is essential for forensic analysis during incident responses.

  • C. Correct.

    Correct. AWS Config helps in ensuring that CloudTrail is consistently enabled and correctly configured across accounts, reducing the risk of misconfiguration that could hinder incident response.

  • D. Correct.

    Correct. Security Hub provides a centralized view of security findings across multiple accounts, enabling efficient coordination and response during incidents.

  • E. Incorrect.

    Incorrect. Relying on manual log analysis is not a best practice as it delays response times and is prone to human error. Automated monitoring services enhance detection and response capabilities.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam