nerdexam
Amazon

SCS-C02 · Question #70

A security team has received an alert from Amazon GuardDuty that AWS CloudTrail logging has been disabled. The security team's account has AWS Config, Amazon Inspector, Amazon Detective, and AWS…

The correct answer is C. Use Detective to find the details of the CloudTrailLoggingDisabled event from GuardDuty. Findings detected by GuardDuty GuardDuty uses your log data to uncover suspected instances of malicious or high-risk activity. Detective provides resources that help you investigate these findings. For each finding, Detective provides the associated finding details. Detective…

Submitted by kevin_r· Mar 6, 2026Threat Detection and Incident Response

Question

A security team has received an alert from Amazon GuardDuty that AWS CloudTrail logging has been disabled. The security team's account has AWS Config, Amazon Inspector, Amazon Detective, and AWS Security Hub enabled. The security team wants to identify who disabled CloudTrail and what actions were performed while CloudTrail was disabled. What should the security team do to obtain this information?

Options

  • AUse AWS Config to search for the CLOUD_TRAIL_ENABLED event. Use the configuration
  • BUse Amazon Inspector to find the details of the CloudTrailLoggingDisabled event from
  • CUse Detective to find the details of the CloudTrailLoggingDisabled event from GuardDuty,
  • DUse GuardDuty to find which user generated the CloudTrailLoggingDisabled event. Use Security

How the community answered

(50 responses)
  • A
    16% (8)
  • B
    6% (3)
  • C
    74% (37)
  • D
    4% (2)

Explanation

Findings detected by GuardDuty GuardDuty uses your log data to uncover suspected instances of malicious or high-risk activity. Detective provides resources that help you investigate these findings. For each finding, Detective provides the associated finding details. Detective also shows the entities, such as IP addresses and AWS accounts, that are connected to the finding. You can then explore the activity for the involved entities to determine whether the detected activity from the finding is a genuine cause for concern. https://docs.aws.amazon.com/detective/latest/userguide/investigation-phases-starts.html

Topics

#Amazon GuardDuty#Amazon Detective#CloudTrail logging disabled#incident investigation

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice