nerdexam
AmazonAmazon

SCS-C02 · Question #273

SCS-C02 Question #273: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #273. The question stem and answer options stay visible for context.

Submitted by chen.hong· Mar 6, 2026

Question

A company's web application is hosted on Amazon EC2 instances running behind an Application Load Balancer (ALB) in an Auto Scaling group. An AWS WAF web ACL is associated with the ALB. AWS CloudTrail is enabled, and stores logs in Amazon S3 and Amazon CloudWatch Logs. The operations team has observed some EC2 instances reboot at random. After rebooting, all access logs on the instances have been deleted. During an investigation, the operations team found that each reboot happened just after a PHP error occurred on the new-user-creation.php file. The operations team needs to view log information to determine if the company is being attacked. Which set of actions will identify the suspect attacker's IP address for future occurrences?

Options

  • AConfigure VPC Flow Logs on the subnet where the ALB is located, and stream the data
  • BConfigure the CloudWatch agent on the ALB
  • CConfigure the ALB to export access logs to an Amazon Elasticsearch Service cluster, and use the
  • DConfigure the web ACL to send logs to Amazon Kinesis Data Firehose, which delivers the logs to

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SCS-C02 PracticeBrowse All SCS-C02 Questions