nerdexam
Amazon

SCS-C02 · Question #372

Your company has a set of EC2 Instances defined in AWS. These Ec2 Instances have strict security groups attached to them. You need to ensure that changes to the Security groups are noted and acted…

The correct answer is D. Use Cloudwatch events to be triggered for any changes to the Security Groups. Configure the. The below diagram from an AWS blog shows how security groups can be monitored Option A is invalid because you need to use Cloudwatch Events to check for chan Option B is invalid because you need to use Cloudwatch Events to check for chang Option C is invalid because AWS…

Submitted by marco_it· Mar 6, 2026Security Logging and Monitoring

Question

Your company has a set of EC2 Instances defined in AWS. These Ec2 Instances have strict security groups attached to them. You need to ensure that changes to the Security groups are noted and acted on accordingly. How can you achieve this?

Exhibit

SCS-C02 question #372 exhibit

Options

  • AUse Cloudwatch logs to monitor the activity on the Security Groups. Use filters to search for the
  • BUse Cloudwatch metrics to monitor the activity on the Security Groups. Use filters to search for
  • CUse AWS inspector to monitor the activity on the Security Groups. Use filters to search for the
  • DUse Cloudwatch events to be triggered for any changes to the Security Groups. Configure the

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    9% (3)
  • D
    85% (28)

Explanation

The below diagram from an AWS blog shows how security groups can be monitored Option A is invalid because you need to use Cloudwatch Events to check for chan Option B is invalid because you need to use Cloudwatch Events to check for chang Option C is invalid because AWS inspector is not used to monitor the activity on Security Groups

Topics

#CloudWatch Events#security group monitoring#change detection#alerting

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice