SCS-C02 exam dumps

SCS-C02 practice question 95 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 95

Select 2

Your organization is running a critical application on AWS, and you need to ensure that any unauthorized changes to security groups are immediately detected and flagged. Additionally, you require a solution that can trigger a notification to your security team whenever such changes occur. Which combination of AWS services can meet this requirement?

  1. A

    Amazon CloudWatch with a custom metric filter and SNS for notifications

  2. B

    AWS Config with a rule to monitor security group changes and an SNS topic for notifications

  3. C

    Amazon EventBridge with a rule to detect security group changes and an SNS topic for notifications

  4. D

    AWS CloudTrail with real-time logging enabled and an S3 bucket for log storage

  5. E

    AWS Trusted Advisor to monitor and notify about security group changes

Show answer and explanation

Correct answers: B, C

Explanation

To meet the requirement of detecting and notifying about unauthorized changes to security groups, AWS Config and EventBridge are the best solutions. AWS Config tracks and evaluates configuration changes in AWS resources, while EventBridge allows you to create rules that detect specific events, such as API calls related to security group changes. Both services can trigger notifications via Amazon SNS to alert the security team. CloudWatch, CloudTrail, and Trusted Advisor do not provide the necessary real-time monitoring and notification capabilities for this scenario.

  • A. Incorrect.

    Amazon CloudWatch can monitor metrics and trigger alarms, but it cannot directly identify unauthorized changes to security groups. It requires additional services like AWS Config to track configuration changes.

  • B. Correct.

    AWS Config is designed to track and evaluate configuration changes in AWS resources, including security groups. By creating a custom rule and linking it to an SNS topic, you can achieve the desired functionality.

  • C. Correct.

    Amazon EventBridge can be configured with rules to detect specific API calls, such as changes to security groups, and trigger actions like sending notifications through SNS.

  • D. Incorrect.

    AWS CloudTrail provides the audit logs necessary to trace changes, but it does not provide real-time detection or notifications out of the box. It is more focused on log storage and analysis.

  • E. Incorrect.

    AWS Trusted Advisor provides recommendations to optimize AWS usage and security but does not provide real-time monitoring or notification capabilities for security group changes.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam