ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 120 - SCS-C01 discussion

Report
Export

The Security team believes that a former employee may have gained unauthorized access to AWS resources sometime in the past 3 months by using an identified access key. What approach would enable the Security team to find out what the former employee may have done within AWS?

A.
Use the AWS CloudTrail console to search for user activity.
Answers
A.
Use the AWS CloudTrail console to search for user activity.
B.
Use the Amazon CloudWatch Logs console to filter CloudTrail data by user.
Answers
B.
Use the Amazon CloudWatch Logs console to filter CloudTrail data by user.
C.
Use AWS Config to see what actions were taken by the user.
Answers
C.
Use AWS Config to see what actions were taken by the user.
D.
Use Amazon Athena to query CloudTrail logs stored in Amazon S3.
Answers
D.
Use Amazon Athena to query CloudTrail logs stored in Amazon S3.
Suggested answer: A

Explanation:

You can use CloudTrail to search event history for the last 90 days. You can use CloudWatch queries to search API history beyond the last 90 days. You can use Athena to query CloudTrail logs over the last 90 days. https:// aws.amazon.com/premiumsupport/knowledge-center/view-iam-history/

asked 16/09/2024
MAYKON AZEVEDO
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first