A security team wants continuous, intelligent threat detection across accounts by analyzing CloudTrail, VPC Flow Logs, and DNS logs, with no agents to deploy. Which service should they enable?
AWS Certified Security โ Specialty
AWS_SCS_C02Ready to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 100 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 100 questions โ10 questions across 6 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
All 10 questions
Threat Detection and Incident Response
4 questions in topicDetect, analyze, and respond to security threats and incidents on AWS.
After GuardDuty raises a finding about suspicious activity from an IAM role, an analyst must investigate the root cause by correlating activity across accounts and time using a visual graph. Which service is designed for this security investigation?
An EC2 instance is suspected of being compromised. Following incident-response best practices, what should the security engineer do to contain it while preserving evidence?
A team wants specific GuardDuty findings to automatically trigger a remediation workflow (for example, isolating an instance) with no manual steps. Which approach achieves this?
Security Logging and Monitoring
5 questions in topicDesign and implement logging, monitoring, and alerting for security.
A company with many accounts under AWS Organizations must capture all management-event API activity from every account into a central, consistent audit trail. What is the most efficient way to do this?
Security policy requires an alert whenever the root user signs in or makes API calls. CloudTrail delivers events to CloudWatch Logs. How should the engineer implement the alert?
A security analyst must investigate whether an EC2 instance communicated with a suspicious external IP address, including which ports and whether traffic was accepted or rejected. Which log source provides this?
A compliance team must maintain a continuous record of AWS resource configuration changes and evaluate resources against security rules (for example, 'no security group allows 0.0.0.0/0 on port 22'). Which service provides this?
An auditor requires assurance that CloudTrail log files stored in S3 have not been modified or deleted after delivery. Which combination best provides tamper-evident logs?
Infrastructure Security
1 question in topicSecure edge, network, and compute infrastructure.
A public web application must be protected against common exploits such as SQL injection and cross-site scripting at the application layer. Which service should the engineer deploy?