nerdexam
Amazon

SCS-C02 · Question #15

A company recently had a security audit in which the auditors identified multiple potential threats. These potential threats can cause usage pattern changes such as DNS access peak, abnormal…

The correct answer is C. Enable Amazon GuardDuty from a centralized account. Use GuardDuty to manage AWS. https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_data-sources.html

Submitted by stefanr· Mar 6, 2026Threat Detection and Incident Response

Question

A company recently had a security audit in which the auditors identified multiple potential threats. These potential threats can cause usage pattern changes such as DNS access peak, abnormal instance traffic, abnormal network interface traffic, and unusual Amazon S3 API calls. The threats can come from different sources and can occur at any time. The company needs to implement a solution to continuously monitor its system and identify all these incoming threats in near-real time. Which solution will meet these requirements?

Options

  • AEnable AWS CloudTrail logs, VPC flow logs, and DNS logs. Use Amazon CloudWatch Logs to
  • BEnable AWS CloudTrail logs, VPC flow logs, and DNS logs. Use Amazon Macie to monitor these
  • CEnable Amazon GuardDuty from a centralized account. Use GuardDuty to manage AWS
  • DEnable Amazon Inspector from a centralized account. Use Amazon Inspector to manage AWS

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    83% (24)
  • D
    3% (1)

Explanation

https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_data-sources.html

Topics

#GuardDuty#threat detection#VPC flow logs#DNS logs

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice