nerdexam
AmazonAmazon

SCS-C02 · Question #96

SCS-C02 Question #96: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #96. The question stem and answer options stay visible for context.

Submitted by tunde_lagos· Mar 6, 2026

Question

A company has a group of Amazon EC2 instances in a single private subnet of a VPC with no internet gateway attached. A security engineer has installed the Amazon CloudWatch agent on all instances in that subnet to capture logs from a specific application. To ensure that the logs flow securely, the company's networking team has created VPC endpoints for CloudWatch monitoring and CloudWatch logs. The networking team has attached the endpoints to the VPC. The application is generating logs However, when the security engineer queries CloudWatch, the logs do not appear. Which combination of steps should the security engineer take to troubleshoot this issue? (Choose three.)

Options

  • AEnsure that the EC2 instance profile that is attached to the EC2 instances has permissions to
  • BCreate a metric filter on the logs so that they can be viewed in the AWS Management Console.
  • CCheck the CloudWatch agent configuration file on each EC2 instance to make sure that the
  • DCheck the VPC endpoint policies of both VPC endpoints to ensure that the EC2 instances have
  • ECreate a NAT gateway in the subnet so that the EC2 instances can communicate with
  • FEnsure that the security groups allow all the EC2 instances to communicate with each other to

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SCS-C02 PracticeBrowse All SCS-C02 Questions