SCS-C02 exam dumps

SCS-C02 practice question 86 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 86

Select 4

You are a security engineer tasked with monitoring and responding to potential unauthorized access in your AWS environment. The organization has multiple AWS accounts and wants centralized visibility into security events across all accounts. You need to design a monitoring and alerting solution that ensures compliance with your security policies. Which of the following steps should you take to achieve this?

  1. A

    Enable AWS CloudTrail in each account and configure it to send logs to an Amazon S3 bucket in a designated monitoring account.

  2. B

    Set up Amazon GuardDuty in each account and enable cross-account access to a centralized account for unified threat detection.

  3. C

    Use Amazon CloudWatch Logs Insights to create custom queries for detailed analysis of security logs in each account.

  4. D

    Configure AWS Security Hub in the monitoring account and link it with member accounts to aggregate findings.

  5. E

    Manually review all CloudTrail logs in each account on a weekly basis to identify potential security issues.

  6. F

    Enable CloudTrail Insights to automatically detect unusual activity and create CloudWatch Alarms for critical events.

Show answer and explanation

Correct answers: A, B, D, F

Explanation

To design and implement effective monitoring and alerting for security events in a multi-account AWS environment, it's essential to centralize log collection (using CloudTrail), enable automated threat detection (via GuardDuty and CloudTrail Insights), and aggregate findings (via Security Hub). Manual log reviews and ad-hoc querying are not scalable or reliable for continuous monitoring. By implementing these best practices, you ensure centralized visibility, automated threat detection, and compliance with security policies.

  • A. Correct.

    Correct: Enabling AWS CloudTrail in each account and centralizing the logs in an S3 bucket in a monitoring account ensures auditability and centralized access to logs for monitoring and analysis.

  • B. Correct.

    Correct: Amazon GuardDuty provides threat detection and can be configured for cross-account access, allowing centralized visibility into potential security threats.

  • C. Incorrect.

    Incorrect: While CloudWatch Logs Insights can be used for querying logs, this is not a scalable solution for continuous monitoring across multiple accounts.

  • D. Correct.

    Correct: AWS Security Hub allows you to aggregate and prioritize security findings across accounts, providing centralized visibility.

  • E. Incorrect.

    Incorrect: Manually reviewing logs is time-consuming and error-prone, and it does not align with best practices for automated monitoring.

  • F. Correct.

    Correct: Enabling CloudTrail Insights helps detect unusual activity automatically, and coupling it with CloudWatch Alarms ensures immediate alerts for critical events.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam