ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 293 - SCS-C02 discussion

Report
Export

An Amazon EC2 Auto Scaling group launches Amazon Linux EC2 instances and installs the Amazon CloudWatch agent to publish logs to Amazon CloudWatch Logs. The EC2 instances launch with an IAM role that has an IAM policy attached. The policy provides access to publish custom metrics to CloudWatch. The EC2 instances run in a private subnet inside a VPC. The VPC provides ^ccess to the internet for private subnets through a NAT gateway.

A security engineer notices that no logs are being published to CloudWatch Logs for the EC2 instances that the Auto Scaling group launches. The security engineer validates that the CloudWatch Logs agent is running and is configured properly on the EC2 instances. In addition, the security engineer validates that network communications are working properly to AWS services.

What can the security engineer do to ensure that the logs are published to CloudWatch Logs?

A.
Configure the IAM policy in use by the IAM role to have access to the required cloudwatch: API actions thatwill publish logs.
Answers
A.
Configure the IAM policy in use by the IAM role to have access to the required cloudwatch: API actions thatwill publish logs.
B.
Adjust the Amazon EC2 Auto Scaling service-linked role to have permissions to write to CloudWatch Logs.
Answers
B.
Adjust the Amazon EC2 Auto Scaling service-linked role to have permissions to write to CloudWatch Logs.
C.
Configure the IAM policy in use by the IAM role to have access to the required AWS logs: API actions that willpublish logs.
Answers
C.
Configure the IAM policy in use by the IAM role to have access to the required AWS logs: API actions that willpublish logs.
D.
Add an interface VPC endpoint to provide a route to CloudWatch Logs.
Answers
D.
Add an interface VPC endpoint to provide a route to CloudWatch Logs.
Suggested answer: C

Explanation:

Adjusting the IAM policy attached to the IAM role used by EC2 instances to include the necessary AWS Logs API actions for publishing logs to CloudWatch Logs addresses the issue. This ensures that the EC2 instances have the required permissions to interact with CloudWatch Logs, facilitating the successful publication of logs from the instances.


asked 16/09/2024
Mario Peralta
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first