Skip to content
BytePatterns

SCS-C03 · Domain 1: Detection · 16% of the exam

Task 1.1: Design and implement monitoring and alerting solutions for an AWS account or organization

Knowing when something is wrong: deciding what a workload needs watched, collecting findings from GuardDuty, Macie, Security Hub and Security Lake in one place, turning them into metrics, alarms and dashboards, and running regular checks automatically with AWS Config conformance packs and Systems Manager.

Study it

  • What to watch: monitoring requirements, health checks and CloudWatch alarms

    Partly covered by: CloudWatch, Alarms & X-Ray, Observability Basics

  • Findings in one place: GuardDuty, Macie, Security Hub, Security Hub CSPM and delegated administrators

    Lesson coming

  • Assessments on a schedule: AWS Config conformance packs and Systems Manager

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company uses AWS Organizations with 140 member accounts and adds new accounts every month. The security team wants Amazon GuardDuty running in every existing and future account in the two Regions the company uses, with all findings visible from a security tooling account, and with as little ongoing work as possible. What should the team do?

  1. AMake the security tooling account the delegated GuardDuty administrator and set auto-enable to all accounts (ALL) in each Region
  2. BMake the security tooling account the delegated GuardDuty administrator and set auto-enable to new accounts only (NEW) in each Region
  3. CDeploy a CloudFormation StackSet that creates a GuardDuty detector in every account and in both Regions
  4. DEnable GuardDuty in the security tooling account in both Regions and invite every member account to join it
Show the answer and why
  • AMake the security tooling account the delegated GuardDuty administrator and set auto-enable to all accounts (ALL) in each Region

    Correct

    A delegated administrator sees the findings of its member accounts, and the ALL setting enables GuardDuty for existing accounts and for accounts that join later. Auto-enable preferences are set per Region.

  • BMake the security tooling account the delegated GuardDuty administrator and set auto-enable to new accounts only (NEW) in each Region

    Incorrect

    NEW enables GuardDuty only for accounts that join the organization after the setting is saved, so the 140 existing accounts stay uncovered.

  • CDeploy a CloudFormation StackSet that creates a GuardDuty detector in every account and in both Regions

    Incorrect

    Each account would run its own standalone detector. Findings are visible centrally only to an administrator account that has the other accounts as members, which a StackSet does not set up.

  • DEnable GuardDuty in the security tooling account in both Regions and invite every member account to join it

    Incorrect

    Invitations are the legacy method for accounts outside the organization. Each new account would need its own invitation, and GuardDuty recommends AWS Organizations instead.

Central management plus automatic coverage is the delegated administrator with auto-enable set to ALL. Choose NEW only when existing accounts are already handled some other way.

Question 2 · choose 1

A delegated GuardDuty administrator account has an Amazon EventBridge rule that sends GuardDuty findings to the incident team's queue. New findings arrive within minutes. When an existing finding recurs, for example repeated port probes against the same instance, the update can take up to six hours to reach the queue. The team wants updates about recurring findings within 15 minutes for every member account. What should the team do?

  1. AIn each member account, set the frequency for updated findings to 15 minutes
  2. BIn the delegated administrator account, set the updated-findings frequency to 15 minutes
  3. CChange the EventBridge rule's event pattern so that it matches findings of every severity
  4. DExport findings to an S3 bucket and process each new object with S3 Event Notifications and Lambda
Show the answer and why
  • AIn each member account, set the frequency for updated findings to 15 minutes

    Incorrect

    Only an administrator account can change this frequency, and the value it sets applies to its member accounts. A member account cannot change it for itself.

  • BIn the delegated administrator account, set the updated-findings frequency to 15 minutes

    Correct

    GuardDuty groups later occurrences of a finding and sends them on a schedule that defaults to 6 hours. The administrator can set 15 minutes, 1 hour or 6 hours, and the setting applies to all members.

  • CChange the EventBridge rule's event pattern so that it matches findings of every severity

    Incorrect

    The pattern filters events that GuardDuty has already sent. It does not make GuardDuty send updates for recurring findings any sooner.

  • DExport findings to an S3 bucket and process each new object with S3 Event Notifications and Lambda

    Incorrect

    The same frequency setting governs updated findings exported to S3, so the S3 path would still deliver recurring findings every 6 hours.

New findings go to EventBridge in near real time; later occurrences of the same finding follow the updated-findings frequency, which only the administrator account can lower.

Question 3 · choose 1

A company has about 3,000 S3 buckets across its organization. The security team wants a continuous, low-cost view of which buckets are likely to contain sensitive data, so that it can decide where a deeper review is needed. Inspecting every object in every bucket is not required. Which approach meets these requirements?

  1. ASchedule an Amazon Macie sensitive data discovery job that analyzes all objects in all buckets every day
  2. BReview the bucket inventory and policy findings that Amazon Macie produces for the buckets
  3. CTurn on Amazon Macie automated sensitive data discovery for the organization
  4. DTurn on GuardDuty S3 Protection in every account
Show the answer and why
  • ASchedule an Amazon Macie sensitive data discovery job that analyzes all objects in all buckets every day

    Incorrect

    Jobs give deeper, targeted analysis of the objects in their scope. Running one over every bucket is the exhaustive review the team said it does not need.

  • BReview the bucket inventory and policy findings that Amazon Macie produces for the buckets

    Incorrect

    Bucket inventory and policy findings describe security and access control, such as public or shared buckets. They do not say whether the objects contain sensitive data.

  • CTurn on Amazon Macie automated sensitive data discovery for the organization

    Correct

    Automated discovery continually evaluates the bucket inventory and samples representative objects, giving broad visibility into where sensitive data might reside without analyzing every object.

  • DTurn on GuardDuty S3 Protection in every account

    Incorrect

    S3 Protection monitors CloudTrail data events for S3 to detect threats such as exfiltration. It does not inspect object contents.

Macie offers two ways to find sensitive data: automated discovery for a broad, sampled view across the estate, and jobs for deep, targeted analysis of chosen buckets. Start broad, then point jobs at what the broad view surfaces.

Question 4 · choose 2

A security team must run the same set of AWS Config rules in every account of its organization, including accounts created later. Member account administrators must not be able to change or delete those rules. The team works from the delegated administrator account for AWS Config. Which actions should the team take? (Choose TWO.)

  1. ADeploy the rules as an organization conformance pack from the delegated administrator account
  2. BMake sure every account, including new ones, has an AWS Config configuration recorder running
  3. CCreate an AWS Config aggregator in the delegated administrator account for all accounts
  4. DDeploy the conformance pack to each account with a CloudFormation StackSet that uses self-managed permissions
  5. EAttach an SCP that denies config:PutConfigRule to all member accounts
Show the answer and why
  • ADeploy the rules as an organization conformance pack from the delegated administrator account

    Correct

    An organization conformance pack is deployed to every member account, including accounts that join later, and member accounts cannot modify its rules and remediation actions.

  • BMake sure every account, including new ones, has an AWS Config configuration recorder running

    Correct

    Organization rules and conformance packs need a recorder in the account. If none exists, deployment to a new account is retried only for 7 hours.

  • CCreate an AWS Config aggregator in the delegated administrator account for all accounts

    Incorrect

    An aggregator gives a read-only view of configuration and compliance data. It cannot deploy rules to the source accounts.

  • DDeploy the conformance pack to each account with a CloudFormation StackSet that uses self-managed permissions

    Incorrect

    Self-managed StackSets do not deploy automatically to accounts added later, and the resulting packs are ordinary resources that the account can change.

  • EAttach an SCP that denies config:PutConfigRule to all member accounts

    Incorrect

    An SCP only limits actions; it deploys no rules. Rules from an organization conformance pack are already protected from member accounts.

The organization conformance pack does the deploying and the protecting, but it can evaluate only where AWS Config is recording. Pair it with a recorder in every account, for example through the account baseline.

Question 5 · choose 1

The security team wants a notification soon after IAM Access Analyzer reports a new finding that a resource is shared outside the account. What should the team set up?

  1. AA weekly review of the Access Analyzer console by the team
  2. BAn EventBridge rule for Access Analyzer finding events
  3. CAn IAM credential report generated every day
  4. DA CloudWatch metric filter on the analyzer's log group
Show the answer and why
  • AA weekly review of the Access Analyzer console by the team

    Incorrect

    A weekly review is not a notification and adds delay.

  • BAn EventBridge rule for Access Analyzer finding events

    Correct

    IAM Access Analyzer sends an event to EventBridge for each finding, and a rule can route it to a notification target.

  • CAn IAM credential report generated every day

    Incorrect

    The credential report covers users' credentials, not resource sharing findings.

  • DA CloudWatch metric filter on the analyzer's log group

    Incorrect

    Access Analyzer findings are delivered as events, not written to a log group for metric filters.

Most AWS security services publish findings to EventBridge, which is the common hub for alerting and automation.

Question 6 · choose 1

Security Hub CSPM runs in four Regions. Analysts want to see and manage findings, insights and control status from all four Regions in one place. What should the team configure?

  1. AA Security Hub CSPM insight in each of the four Regions
  2. BAn S3 bucket where each Region exports findings daily
  3. CCross-Region aggregation with one home Region
  4. DA separate administrator account for each Region
Show the answer and why
  • AA Security Hub CSPM insight in each of the four Regions

    Incorrect

    Insights group findings within one Region; they do not bring other Regions' data together.

  • BAn S3 bucket where each Region exports findings daily

    Incorrect

    Exported files are not managed in Security Hub CSPM and add custom work.

  • CCross-Region aggregation with one home Region

    Correct

    Aggregation brings findings, insights, control status and scores from linked Regions into a single home Region.

  • DA separate administrator account for each Region

    Incorrect

    More administrators split the view further instead of combining it.

The home Region was formerly called the aggregation Region; some API operations still use the older term.

Question 7 · choose 1

Auditors require GuardDuty findings to be kept for three years. What should the security team do?

  1. AIncrease the GuardDuty finding retention setting to three years
  2. BExport findings to an S3 bucket encrypted with a KMS key
  3. CArchive the findings in GuardDuty so they are never deleted
  4. DTurn on GuardDuty Runtime Monitoring for longer history
Show the answer and why
  • AIncrease the GuardDuty finding retention setting to three years

    Incorrect

    GuardDuty keeps findings for 90 days; there is no longer retention setting.

  • BExport findings to an S3 bucket encrypted with a KMS key

    Correct

    GuardDuty can export findings to an S3 bucket, using a KMS key to encrypt them, where they can be kept as long as needed.

  • CArchive the findings in GuardDuty so they are never deleted

    Incorrect

    Archiving changes a finding's status; it does not extend retention.

  • DTurn on GuardDuty Runtime Monitoring for longer history

    Incorrect

    Runtime Monitoring adds a data source; it does not change how long findings are kept.

Long-term retention of security findings belongs in your own storage, with lifecycle rules and access controls you manage.

Question 8 · choose 1

The team wants to be alerted when the rate of API calls or API errors in an account suddenly departs from its normal pattern, such as a burst of resource deletions. Which feature is built for this?

  1. ACloudTrail Insights turned on for the trail
  2. BLog file integrity validation on the trail
  3. CAWS Config change notifications to SNS
  4. DVPC Flow Logs for all subnets in the account
Show the answer and why
  • ACloudTrail Insights turned on for the trail

    Correct

    Insights learns a baseline of API call and error rates and creates Insights events when current rates deviate from it.

  • BLog file integrity validation on the trail

    Incorrect

    Integrity validation proves log files were not changed; it does not analyze activity.

  • CAWS Config change notifications to SNS

    Incorrect

    Config reports resource configuration changes, not API call rates.

  • DVPC Flow Logs for all subnets in the account

    Incorrect

    Flow logs describe network traffic, not API activity.

Insights events can feed EventBridge rules like any other CloudTrail event.

Question 9 · choose 1

An Amazon EventBridge rule opens a ticket for every Amazon Inspector finding event, and the queue is flooded with low and medium findings. The team wants tickets only for CRITICAL findings. Every finding must stay active and shown by default in the Inspector console for the weekly vulnerability report. What should the team change?

  1. ACreate an Inspector suppression rule for findings below CRITICAL
  2. BAdd a detail.severity filter for CRITICAL to the rule's event pattern
  3. CTag the instances with low findings with the InspectorEc2Exclusion key
  4. DMatch Inspector2 Scan events instead of Inspector2 Finding events
Show the answer and why
  • ACreate an Inspector suppression rule for findings below CRITICAL

    Incorrect

    A suppression rule hides matching findings from the default console view, which breaks the reporting requirement.

  • BAdd a detail.severity filter for CRITICAL to the rule's event pattern

    Correct

    Inspector finding events carry the finding's severity, so the event pattern can match CRITICAL only while Inspector keeps every finding.

  • CTag the instances with low findings with the InspectorEc2Exclusion key

    Incorrect

    Excluded instances are not scanned and get no findings at all, including any future critical ones.

  • DMatch Inspector2 Scan events instead of Inspector2 Finding events

    Incorrect

    Scan events report that an initial scan finished, with counts per severity; they do not describe individual findings.

Decide where the filter belongs. Narrowing what reaches a target is the job of the event pattern; suppression rules and exclusion tags change what Inspector shows or scans.

Practise domain 1 →Practise all domains →