nerdexam
Amazon

SCS-C02 · Question #279

A security engineer is auditing a production system and discovers several additional IAM roles that are not required and were not previously documented during the last audit 90 days ago. The engineer

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #279. The question stem and answer options stay visible for context.

Submitted by obi.ng· Mar 6, 2026Threat Detection and Incident Response

Question

A security engineer is auditing a production system and discovers several additional IAM roles that are not required and were not previously documented during the last audit 90 days ago. The engineer is trying to find out who created these IAM roles and when they were created. The solution must have the lowest operational overhead. Which solution will meet this requirement?

Options

  • AImport AWS CloudTrail logs from Amazon S3 into an Amazon Elasticsearch Service cluster, and
  • BCreate a table in Amazon Athena for AWS CloudTrail events.
  • CUse AWS Config to look up the configuration timeline for the additional IAM roles and view the
  • DDownload the credentials report from the IAM console to view the details for each IAM entity,

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM#CloudTrail#Log Analysis#Security Audit
Full SCS-C02 Practice