Amazon
SCS-C02 · Question #243
A company is implementing a customized notification solution to detect repeated unauthorized authentication attempts to bastion hosts. The company's security engineer needs to implement a solution…
The correct answer is C. Use the Amazon CloudWatch agent to collect operating system logs Create a CloudWatch alarm. See the full explanation below for the reasoning.
Submitted by haruto_sh· Mar 6, 2026Security Logging and Monitoring
Question
A company is implementing a customized notification solution to detect repeated unauthorized authentication attempts to bastion hosts. The company's security engineer needs to implement a solution that will provide notification when 5 failed attempts occur within a 5-minute period. The solution must use native AWS services and must notify only the designated system administrator who is assigned to the specific bastion host. Which solution will meet these requirements?
Options
- AUse the Amazon CloudWatch agent to collect operating system logs. Use Amazon EventBridge to
- BUse AWS Systems Manager Agent to collect operating system logs. Use the Systems Manager
- CUse the Amazon CloudWatch agent to collect operating system logs Create a CloudWatch alarm
- DUse AWS Systems Manager Agent to collect operating system logs. Use the Systems Manager
How the community answered
(34 responses)- A12% (4)
- B6% (2)
- C79% (27)
- D3% (1)
Topics
#CloudWatch Logs#CloudWatch Alarms#Security Monitoring#Bastion Host Security
Community Discussion
No community discussion yet for this question.