A company with many accounts under AWS Organizations must capture all management-event API activity from every account into a central, consistent audit trail. What is the most efficient way to do this?
AWS Certified Security โ Specialty
AWS_SCS_C02Ready to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 100 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 100 questions โ10 questions across 6 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
5 questions in Security Logging and Monitoring
Security Logging and Monitoring
5 questions in topicDesign and implement logging, monitoring, and alerting for security.
Security policy requires an alert whenever the root user signs in or makes API calls. CloudTrail delivers events to CloudWatch Logs. How should the engineer implement the alert?
A security analyst must investigate whether an EC2 instance communicated with a suspicious external IP address, including which ports and whether traffic was accepted or rejected. Which log source provides this?
A compliance team must maintain a continuous record of AWS resource configuration changes and evaluate resources against security rules (for example, 'no security group allows 0.0.0.0/0 on port 22'). Which service provides this?
An auditor requires assurance that CloudTrail log files stored in S3 have not been modified or deleted after delivery. Which combination best provides tamper-evident logs?