nerdexam
Amazon

SCS-C03 · Question #5

A security engineer wants to forward custom application-security logs from an Amazon EC2 instance to Amazon CloudWatch. The security engineer installs the CloudWatch agent on the EC2 instance and adds

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #5. The question stem and answer options stay visible for context.

Submitted by jian89· Mar 6, 2026Security Logging and Monitoring

Question

A security engineer wants to forward custom application-security logs from an Amazon EC2 instance to Amazon CloudWatch. The security engineer installs the CloudWatch agent on the EC2 instance and adds the path of the logs to the CloudWatch configuration file. However, CloudWatch does not receive the logs. The security engineer verifies that the awslogs service is running on the EC2 instance. What should the security engineer do next to resolve the issue?

Options

  • AAdd AWS CloudTrail to the trust policy of the EC2 instance. Send the custom logs to CloudTrail
  • BAdd Amazon S3 to the trust policy of the EC2 instance. Configure the application to write the
  • CAdd Amazon Inspector to the trust policy of the EC2 instance. Use Amazon Inspector instead of
  • DAttach the CloudWatchAgentServerPolicy AWS managed policy to the EC2 instance role.

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CloudWatch agent#EC2 instance role#log forwarding#IAM permissions
Full SCS-C03 Practice