nerdexam
Amazon

SCS-C02 · Question #268

An application running on Amazon EC2 instances generates log files in a folder on a Linux file system. The instances block access to the console and file transfer utilities, such as Secure Copy Protoc

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #268. The question stem and answer options stay visible for context.

Submitted by tyler.j· Mar 6, 2026Security Logging and Monitoring

Question

An application running on Amazon EC2 instances generates log files in a folder on a Linux file system. The instances block access to the console and file transfer utilities, such as Secure Copy Protocol (SCP) and Secure File Transfer Protocol (SFTP). The Application Support team wants to automatically monitor the application log files so the team can set up notifications in the future. A Security Engineer must design a solution that meets the following requirements:

  • Make the log files available through an AWS managed service.
  • Allow for automatic monitoring of the logs.
  • Provide an Interlace for analyzing logs.
  • Minimize effort.

Which approach meets these requirements?

Options

  • AModify the application to use the AWS SDK Write the application logs lo an Amazon S3 bucket
  • BInstall the unified Amazon CloudWatch agent on the instances
  • CInstall AWS Systems Manager Agent on the instances
  • DInstall Amazon Kinesis Agent on the instances

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#EC2 Log Collection#Kinesis Agent#Real-time Log Streaming#Security Monitoring
Full SCS-C02 Practice