nerdexam
Amazon

SCS-C02 · Question #211

A company has secured the AWS account root user for its AWS account by following AWS best practices. The company also has enabled AWS CloudTrail, which is sending its logs to Amazon S3. A security eng

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #211. The question stem and answer options stay visible for context.

Submitted by mike_84· Mar 6, 2026Security Logging and Monitoring

Question

A company has secured the AWS account root user for its AWS account by following AWS best practices. The company also has enabled AWS CloudTrail, which is sending its logs to Amazon S3. A security engineer wants to receive notification in near-real time if a user uses the AWS account root user credentials to sign in to the AWS Management Console. Which solutions will provide this notification? (Choose two.)

Options

  • AUse AWS Trusted Advisor and its security evaluations for the root account. Configure an Amazon
  • BUse AWS IAM Access Analyzer. Create an Amazon CloudWatch Logs metric filter to evaluate log
  • CConfigure AWS CloudTrail to send its logs to Amazon CloudWatch Logs. Configure a metric filter
  • DConfigure AWS CloudTrail to send log notifications to an Amazon Simple Notification Service
  • EConfigure an Amazon EventBridge event rule that runs when Amazon CloudWatch API calls are

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#root account monitoring#CloudTrail#CloudWatch metric filter#EventBridge
Full SCS-C02 Practice