nerdexam
Amazon

SCS-C02 · Question #405

An Incident Response team is investigating an AWS access key leak that resulted in Amazon EC2 instances being launched. The company did not discover the incident until many months later. The Director

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #405. The question stem and answer options stay visible for context.

Submitted by thandi_sa· Mar 6, 2026Threat Detection and Incident Response

Question

An Incident Response team is investigating an AWS access key leak that resulted in Amazon EC2 instances being launched. The company did not discover the incident until many months later. The Director of Information Security wants to implement new controls that will alert when similar incidents happen in the future. Which controls should the company implement to achieve this? {Select TWO.)

Options

  • AEnable VPC Flow Logs in all VPCs Create a scheduled AWS Lambda function that downloads
  • BUse AWS CloudTrail to make a trail, and apply it to all Regions Specify an Amazon S3 bucket to
  • CAdd the following bucket policy to the company's AWS CloudTrail bucket to prevent log tampering
  • DCreate a Security Auditor role with permissions to access Amazon CloudWatch Logs m all
  • EVerify that Amazon GuardDuty is enabled in all Regions, and create an Amazon CloudWatch

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Threat Detection#Security Monitoring#AWS GuardDuty#VPC Flow Logs
Full SCS-C02 Practice