ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 295 - SCS-C01 discussion

Report
Export

You are responsible to deploying a critical application onto AWS. Part of the requirements for this application is to ensure that the controls set for this application met PCI compliance. Also there is a need to monitor web application logs to identify any malicious activity. Which of the following services can be used to fulfil this requirement. Choose 2 answers from the options given below Please select:

A.
Amazon Cloudwatch Logs
Answers
A.
Amazon Cloudwatch Logs
B.
Amazon VPC Flow Logs
Answers
B.
Amazon VPC Flow Logs
C.
Amazon AWS Config
Answers
C.
Amazon AWS Config
D.
Amazon Cloudtrail
Answers
D.
Amazon Cloudtrail
Suggested answer: A, D

Explanation:

The AWS Documentation mentions the following about these services

AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With CloudTrail, you can log, continuously monitor, and retain account activity related to actions across your AWS infrastructure. CloudTrail provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command line tools, and other AWS services. This event history simplifies security analysis, resource change tracking, and troubleshooting.

Option B is incorrect because VPC flow logs can only check for flow to instances in a VPC

Option C is incorrect because this can check for configuration changes only For more information on Cloudtrail, please refer to below URL:

https://aws.amazon.com/cloudtrail;You can use Amazon CloudWatch Logs to monitor, store, and access your log files from AmazonElastic Compute Cloud (Amazon EC2) instances, AWS CloudTrail, Amazon Route 53, and othersources. You can then retrieve the associated log data from CloudWatch Logs.

For more information on Cloudwatch logs, please refer to below URL: http://docs.aws.amazon.com/AmazonCloudWatch/latest/loes/WhatisCloudWatchLoES.htmll The correct answers are: Amazon Cloudwatch Logs, Amazon Cloudtrail

asked 16/09/2024
Gennadiy Volkov
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first