Amazon
SCS-C02 · Question #288
A company's Security Officer is concerned about the risk of AWS account root user logins and has assigned a Security Engineer to implement a notification solution for near-real-time alerts upon…
The correct answer is B. Run AWS CloudTrail logs through Amazon CloudWatch Events to detect account roo4 user. See the full explanation below for the reasoning.
Submitted by klara.se· Mar 6, 2026Security Logging and Monitoring
Question
A company's Security Officer is concerned about the risk of AWS account root user logins and has assigned a Security Engineer to implement a notification solution for near-real-time alerts upon account root user logins. How should the Security Engineer meet these requirements?
Options
- ACreate a cron job that runs a script lo download the AWS IAM security credentials We. parse the
- BRun AWS CloudTrail logs through Amazon CloudWatch Events to detect account roo4 user
- CSave AWS CloudTrail logs to an Amazon S3 bucket in the Security team's account Process the
- DSave VPC Plow Logs to an Amazon S3 bucket in the Security team's account and process the
How the community answered
(21 responses)- A5% (1)
- B76% (16)
- C5% (1)
- D14% (3)
Topics
#CloudTrail#CloudWatch Events#Root user monitoring#Real-time alerting
Community Discussion
No community discussion yet for this question.