SCS-C02 exam dumps

SCS-C02 practice question 82 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 82

Select 2

Your organization has deployed a web application using Amazon EC2 instances behind an Application Load Balancer (ALB). As part of your security compliance requirements, you need to monitor for unauthorized access patterns and ensure that log data is retained for auditing purposes. Which combination of steps should you take to meet these requirements?

  1. A

    Enable access logging on the Application Load Balancer and configure the logs to be sent to an Amazon S3 bucket with proper permissions.

  2. B

    Enable AWS CloudTrail logging for the ALB and configure it to send logs to an Amazon CloudWatch Logs group.

  3. C

    Enable Amazon VPC Flow Logs and configure them to capture traffic within the VPC where the ALB and EC2 instances are hosted.

  4. D

    Set up AWS Config to track changes to the ALB's configuration and ensure compliance with security policies.

  5. E

    Use Amazon GuardDuty to continuously monitor for unauthorized access patterns and anomalous behavior.

Show answer and explanation

Correct answers: A, E

Explanation

To monitor unauthorized access patterns effectively and retain logs for auditing, you need to enable access logging on the ALB, which captures detailed HTTP request data. Additionally, Amazon GuardDuty provides continuous threat detection and monitoring for unauthorized access attempts or anomalous behavior. Combining these services ensures both compliance and robust security monitoring.

  • A. Correct.

    Correct: Enabling access logging on the ALB ensures that HTTP requests are logged and stored in Amazon S3, allowing you to analyze access patterns and retain logs for auditing.

  • B. Incorrect.

    Incorrect: AWS CloudTrail provides logging for API activity, not for monitoring HTTP requests made to the ALB. ALB access logging is the correct mechanism for this use case.

  • C. Incorrect.

    Incorrect: VPC Flow Logs capture network traffic within a VPC but do not provide detailed HTTP request data for the ALB. This option is not suitable for monitoring unauthorized access to the web application.

  • D. Incorrect.

    Incorrect: AWS Config is a configuration management tool that tracks changes to AWS resources but does not provide logging or monitoring for HTTP requests or unauthorized access patterns.

  • E. Correct.

    Correct: Amazon GuardDuty is a threat detection service that can identify unauthorized access patterns and anomalous traffic, enhancing your monitoring capabilities.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam