Skip to content
BytePatterns

DOP-C02 · Domain 6: Security and Compliance · 17% of the exam

Task 6.3: Implement security monitoring and auditing solutions.

Seeing and proving what happened: CloudTrail, AWS Config, VPC Flow Logs and drift detection for audit, GuardDuty, Inspector and IAM Access Analyzer for threats and weaknesses, and alerts on unexpected activity.

Study it

  • Audit and detection: CloudTrail, AWS Config, flow logs, GuardDuty, Inspector and IAM Access Analyzer

    Partly covered by: CloudWatch, Alarms & X-Ray

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A security team wants to be alerted when the rate of write API calls in a production account suddenly departs from its usual pattern, for example a burst of DeleteSnapshot or TerminateInstances calls from a compromised role. Normal call volumes vary a lot by hour and by day, so the team does not want to define or maintain thresholds per API. The account already has a trail that logs management events. What should the DevOps engineer do?

  1. ACreate CloudWatch Logs metric filters for each destructive API name and static alarms on the resulting metrics
  2. BCreate an EventBridge rule that sends every DeleteSnapshot and TerminateInstances call to the security team's SNS topic
  3. CTurn on GuardDuty Malware Protection for EC2 so that it scans instances when unusual API activity happens
  4. DTurn on CloudTrail Insights for API call rate and route its Insights events through EventBridge
Show the answer and why
  • ACreate CloudWatch Logs metric filters for each destructive API name and static alarms on the resulting metrics

    Incorrect

    This needs a filter and a hand-set threshold for every API, which the team wants to avoid, and fixed thresholds ignore the varying volume.

  • BCreate an EventBridge rule that sends every DeleteSnapshot and TerminateInstances call to the security team's SNS topic

    Incorrect

    This alerts on every normal call as well, not on unusual rates, so the team would be flooded.

  • CTurn on GuardDuty Malware Protection for EC2 so that it scans instances when unusual API activity happens

    Incorrect

    Malware Protection scans EBS volumes for malware. It does not baseline API call rates.

  • DTurn on CloudTrail Insights for API call rate and route its Insights events through EventBridge

    Correct

    Insights builds a baseline of write management API call rates and logs an Insights event when the current rate deviates from it, and Insights events reach EventBridge.

CloudTrail Insights learns the normal API call rate and error rate of an account and flags deviations, so no per-API thresholds are needed. The API call rate measure needs the trail to log write management events.

Question 2 · choose 1

About 900 x86_64 Amazon EC2 instances running Amazon Linux 2023 and Ubuntu 24.04, spread over 60 accounts, are managed by Systems Manager, and their instance profiles already carry the policies that Amazon Inspector needs. Amazon Inspector EC2 scanning is active, with the security account as its delegated administrator. Auditors now want weekly evidence that the operating system settings of every instance tagged Environment=prod, such as SSH daemon options, password rules and file permissions, meet CIS Benchmark Level 1, reviewed in the security account. The team does not want to install or maintain any other scanning tool. What should the DevOps engineer do?

  1. ACreate an Amazon Inspector CIS scan configuration in the security account for all accounts, on the Environment=prod tag, Level 1, weekly
  2. BEnable the CIS AWS Foundations Benchmark standard in AWS Security Hub CSPM for every account through central configuration
  3. CDeploy an organization conformance pack based on the sample template for the CIS AWS Foundations Benchmark Level 1
  4. DUse the existing Amazon Inspector EC2 scanning findings, filtered by the Environment=prod tag, as the evidence
Show the answer and why
  • ACreate an Amazon Inspector CIS scan configuration in the security account for all accounts, on the Environment=prod tag, Level 1, weekly

    Correct

    CIS scans benchmark the operating systems of managed instances that match the configuration's tags, can recur weekly, and a delegated administrator can target member accounts and view their results.

  • BEnable the CIS AWS Foundations Benchmark standard in AWS Security Hub CSPM for every account through central configuration

    Incorrect

    The standard's controls check AWS account and resource settings, such as IAM, CloudTrail and security groups, not the settings inside each instance's operating system.

  • CDeploy an organization conformance pack based on the sample template for the CIS AWS Foundations Benchmark Level 1

    Incorrect

    Each AWS Config rule in the pack evaluates a specific AWS resource, so it cannot read SSH, password or file settings inside the instances.

  • DUse the existing Amazon Inspector EC2 scanning findings, filtered by the Environment=prod tag, as the evidence

    Incorrect

    EC2 scanning reports package vulnerabilities and network reachability issues, not whether operating system settings follow CIS recommendations.

"CIS" names two different things here. The CIS AWS Foundations Benchmark covers how the AWS accounts are configured, and Security Hub CSPM and AWS Config check it. The CIS Benchmarks for operating systems cover settings inside each server, and Amazon Inspector CIS scans check those on managed EC2 instances, on demand or on a daily, weekly or monthly schedule, with targets chosen by tag.

Question 3 · choose 3

Auditors require that API activity in every account of an organization, in all enabled Regions, is recorded; that administrators of member accounts cannot stop or change this recording; that anyone can later prove whether a delivered log file was changed or deleted; and that log files cannot be deleted or overwritten by anyone, including the root user, for one year. Which actions should the DevOps engineer take? (Choose THREE.)

  1. ACreate a multi-Region organization trail from the management account or a CloudTrail delegated administrator account
  2. BTurn on log file integrity validation for the trail
  3. CSend the events to a new CloudTrail Lake event data store instead of an S3 bucket
  4. DStore the logs in an S3 bucket with Object Lock in compliance mode and a default retention period of one year
  5. ESend the trail to CloudWatch Logs and create metric filters that alarm when someone calls DeleteTrail or StopLogging
Show the answer and why
  • ACreate a multi-Region organization trail from the management account or a CloudTrail delegated administrator account

    Correct

    An organization trail logs events for the management account and all member accounts, and users in member accounts cannot turn its logging off or change it.

  • BTurn on log file integrity validation for the trail

    Correct

    CloudTrail then delivers signed digest files with SHA-256 hashes, so it can be shown whether a log file was modified, deleted or unchanged.

  • CSend the events to a new CloudTrail Lake event data store instead of an S3 bucket

    Incorrect

    CloudTrail Lake is no longer open to new customers, and it would not replace the immutable S3 storage the auditors ask for.

  • DStore the logs in an S3 bucket with Object Lock in compliance mode and a default retention period of one year

    Correct

    In compliance mode, a protected object version cannot be overwritten or deleted by any user, including the root user, until its retention ends.

  • ESend the trail to CloudWatch Logs and create metric filters that alarm when someone calls DeleteTrail or StopLogging

    Incorrect

    Alarms report changes after the fact. They neither prevent changes nor make log files immutable or verifiable.

The organization trail covers every account and is locked against member account changes, log file validation makes tampering detectable, and S3 Object Lock in compliance mode makes the files immutable for the retention period.

Question 4 · choose 1

A security team wants to know when an Amazon EC2 instance in any of its accounts communicates with IP addresses or domains known to be malicious, such as command-and-control servers or cryptocurrency mining pools. The team does not want to build log pipelines, maintain threat intelligence lists or write detection queries. What should the DevOps engineer do?

  1. ATurn on VPC Flow Logs for every VPC, deliver them to S3, and run daily Athena queries against a downloaded list of malicious IP addresses
  2. BAdd AWS Network Firewall to every VPC with a stateful rule group that the team updates with known bad domains each week
  3. CTurn on Amazon GuardDuty, which analyzes VPC flow logs, DNS logs and CloudTrail events with threat intelligence feeds
  4. DEnable Amazon Inspector for EC2 so that it reports instances that contact malicious addresses
Show the answer and why
  • ATurn on VPC Flow Logs for every VPC, deliver them to S3, and run daily Athena queries against a downloaded list of malicious IP addresses

    Incorrect

    This builds the log pipeline, the threat list upkeep and the detection queries the team does not want to own.

  • BAdd AWS Network Firewall to every VPC with a stateful rule group that the team updates with known bad domains each week

    Incorrect

    In this design the team updates the domain list every week, the upkeep it wants to avoid, and a firewall must be deployed and routed in every VPC.

  • CTurn on Amazon GuardDuty, which analyzes VPC flow logs, DNS logs and CloudTrail events with threat intelligence feeds

    Correct

    GuardDuty uses threat intelligence such as lists of malicious IP addresses and domains, and it reads its foundational data sources without anyone enabling them separately.

  • DEnable Amazon Inspector for EC2 so that it reports instances that contact malicious addresses

    Incorrect

    Amazon Inspector finds software vulnerabilities and unintended network exposure. It does not watch the traffic instances send.

GuardDuty is the managed threat detection service: it consumes VPC flow logs, DNS logs and CloudTrail events through its own streams and matches activity against threat intelligence, producing findings without log management.

Question 5 · choose 1

Security groups and IAM roles in a production account are deployed with AWS CloudFormation. Engineers sometimes change these resources directly in the console during incidents and forget to update the templates. The security team wants these out-of-band changes detected on an ongoing basis and recorded as compliance results, without writing code. What should the DevOps engineer do?

  1. ASet a stack policy on each stack that denies updates to the security groups and IAM roles
  2. BUse the AWS Config managed rule cloudformation-stack-drift-detection-check for the stacks
  3. CWrite a Lambda function that runs DetectStackDrift on every stack each hour and emails the results
  4. DTurn on termination protection for each stack so that changes outside CloudFormation are rejected
Show the answer and why
  • ASet a stack policy on each stack that denies updates to the security groups and IAM roles

    Incorrect

    A stack policy applies only during stack updates. Changes made directly in the console bypass it.

  • BUse the AWS Config managed rule cloudformation-stack-drift-detection-check for the stacks

    Correct

    The rule runs drift detection on stacks and marks a stack noncompliant when its drift status is DRIFTED, on configuration changes and periodically.

  • CWrite a Lambda function that runs DetectStackDrift on every stack each hour and emails the results

    Incorrect

    This produces drift results with code the team must write and run, and it records no compliance status.

  • DTurn on termination protection for each stack so that changes outside CloudFormation are rejected

    Incorrect

    Termination protection only blocks deleting the stack. It has no effect on edits made to resources in the console.

Drift detection compares the live resources with the template. The AWS Config managed rule turns it into ongoing compliance evaluation; for many stacks, tags can split the scope across several rule instances.

Question 6 · choose 1

Security Hub CSPM findings for resources tagged as business-critical arrive at their default severity and get lost among others. Security wants such findings raised to CRITICAL as they are ingested, and known low-risk findings from a sandbox account suppressed, without custom code. What should the DevOps engineer configure?

  1. AAn EventBridge rule and a Lambda function that update each finding after it is created
  2. BDisable the controls that produce findings for critical resources
  3. CSecurity Hub CSPM automation rules that raise severity and suppress findings
  4. DA weekly export of findings to S3 and a spreadsheet that re-ranks them
Show the answer and why
  • AAn EventBridge rule and a Lambda function that update each finding after it is created

    Incorrect

    This is custom code for what automation rules do natively.

  • BDisable the controls that produce findings for critical resources

    Incorrect

    Disabling controls hides the findings that matter most.

  • CSecurity Hub CSPM automation rules that raise severity and suppress findings

    Correct

    Automation rules update findings as they are ingested, for example by changing severity or suppressing them.

  • DA weekly export of findings to S3 and a spreadsheet that re-ranks them

    Incorrect

    This is manual and does not change the findings in Security Hub.

Automation rules apply actions such as suppressing findings, changing severity and adding notes to findings that match defined criteria.

Question 7 · choose 1

GuardDuty raises frequent findings for traffic from the company's own external vulnerability scanner, whose IP addresses are fixed and approved. Security wants GuardDuty to stop generating findings from these trusted sources while still detecting everything else. What should the DevOps engineer configure?

  1. ADisable GuardDuty in the affected accounts while the scanner runs each week
  2. BA trusted entity list or IP list in GuardDuty with the scanner's addresses
  3. CA GuardDuty threat list that contains the scanner's IP addresses
  4. DA security group rule that blocks the scanner's addresses
Show the answer and why
  • ADisable GuardDuty in the affected accounts while the scanner runs each week

    Incorrect

    This stops all detection during the scan.

  • BA trusted entity list or IP list in GuardDuty with the scanner's addresses

    Correct

    Lists let GuardDuty stop generating findings from trusted sources.

  • CA GuardDuty threat list that contains the scanner's IP addresses

    Incorrect

    Threat lists mark sources as malicious, which creates more findings.

  • DA security group rule that blocks the scanner's addresses

    Incorrect

    Blocking the approved scanner stops the scans the company needs.

GuardDuty entity lists (recommended) and legacy IP address lists customize detection: trusted lists stop findings from known sources, and threat lists flag known malicious ones.

Question 8 · choose 1

Some EC2 instances run appliances where the team cannot install or run the SSM Agent, yet security requires package vulnerability findings for every instance in Amazon Inspector. What should the DevOps engineer rely on for these instances?

  1. AAgent-based scanning through the Inspector SSM plugin on the instances
  2. BECR enhanced scanning of the images used to build the appliances
  3. CVPC Flow Logs analysis of the appliances' network traffic
  4. DAgentless scanning, which reads software inventory from EBS snapshots
Show the answer and why
  • AAgent-based scanning through the Inspector SSM plugin on the instances

    Incorrect

    Agent-based scanning needs instances managed by SSM.

  • BECR enhanced scanning of the images used to build the appliances

    Incorrect

    Container image scanning does not scan running EC2 instances.

  • CVPC Flow Logs analysis of the appliances' network traffic

    Incorrect

    Network logs do not reveal installed package vulnerabilities.

  • DAgentless scanning, which reads software inventory from EBS snapshots

    Correct

    Agentless scanning uses EBS snapshots, so instances without the SSM Agent can still be scanned.

Inspector scans EC2 instances with agent-based or agentless methods. Hybrid scanning, the default, uses both, so unmanaged instances are covered by snapshot-based scanning.

Question 9 · choose 1

An auditor asks the company to show that no database subnet in its VPCs can be reached from an internet gateway, and to find any network paths that break this rule, based on the current network configuration. What should the DevOps engineer use?

  1. AVPC Flow Logs reviewed for any traffic that reached the database subnets so far
  2. BNetwork Access Analyzer with a scope from internet gateways to database subnets
  3. CGuardDuty findings for the database instances in each VPC
  4. DA Trusted Advisor report on the security groups in each account
Show the answer and why
  • AVPC Flow Logs reviewed for any traffic that reached the database subnets so far

    Incorrect

    Flow logs show traffic that happened, not every possible path.

  • BNetwork Access Analyzer with a scope from internet gateways to database subnets

    Correct

    Network Access Analyzer identifies network paths that do not meet the access requirements you specify.

  • CGuardDuty findings for the database instances in each VPC

    Incorrect

    GuardDuty reports threats, not configuration paths.

  • DA Trusted Advisor report on the security groups in each account

    Incorrect

    This does not analyze full paths from internet gateways to subnets.

Network Access Analyzer evaluates network configuration against defined access requirements and reports unintended paths, which helps demonstrate compliance.

Question 10 · choose 1

Across 120 accounts, security groups with overly permissive rules keep appearing, and many unused security groups pile up. Security wants these found centrally across the organization, with the option to remediate automatically. What should the DevOps engineer configure?

  1. AAmazon Inspector EC2 scanning for the organization, with a delegated administrator that reviews network reachability findings
  2. BVPC Flow Logs in every account and a monthly manual review
  3. CFirewall Manager content and usage audit security group policies
  4. DAn IAM Access Analyzer analyzer for the whole organization
Show the answer and why
  • AAmazon Inspector EC2 scanning for the organization, with a delegated administrator that reviews network reachability findings

    Incorrect

    Network reachability findings show open paths to EC2 instances, but Inspector neither finds unused security groups nor changes their rules.

  • BVPC Flow Logs in every account and a monthly manual review

    Incorrect

    Flow logs show traffic, not rule content or unused groups.

  • CFirewall Manager content and usage audit security group policies

    Correct

    These policies audit security group rules and usage, and can remediate noncompliant or unused groups.

  • DAn IAM Access Analyzer analyzer for the whole organization

    Incorrect

    Access Analyzer analyzes access policies, not security group rules.

Firewall Manager security group policies apply common groups, audit rules for noncompliance and audit usage to clean up unused or redundant groups across accounts.

Practise domain 6 →Practise all domains →