Skip to content
BytePatterns

SCS-C03 · Domain 1: Detection · 16% of the exam

Task 1.2: Design and implement logging solutions

Keeping the evidence: an organization trail in CloudTrail, a dedicated logging account, the CloudWatch agent, VPC and transit gateway flow logs and Route 53 Resolver query logs chosen for the threat, a security data lake in Security Lake, and searching it all with Logs Insights, Athena and OpenSearch.

Study it

  • Organization trails, a logging account and the CloudWatch agent

    Partly covered by: CloudWatch, Alarms & X-Ray

  • Network log sources: VPC and transit gateway flow logs, Route 53 Resolver query logs

    Lesson coming

  • A security data lake: Security Lake, OCSF and subscribers

    Lesson coming

  • Searching logs: CloudWatch Logs Insights, Athena and OpenSearch

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An organization needs a record of API activity from every current and future account. The records must be stored in an S3 bucket in a dedicated log archive account, and administrators in member accounts must not be able to stop or change the logging. What should the security team do?

  1. AUse a StackSet to create a multi-Region trail in each account that delivers to the log archive bucket
  2. BCreate an organization trail from the management account that logs to the log archive bucket
  3. CRely on CloudTrail event history in each account and export it to the log archive account each month
  4. DCreate a multi-Region trail in the management account that delivers to the log archive account's bucket
Show the answer and why
  • AUse a StackSet to create a multi-Region trail in each account that delivers to the log archive bucket

    Incorrect

    A trail created in a member account belongs to that account, so its administrators can stop or delete it.

  • BCreate an organization trail from the management account that logs to the log archive bucket

    Correct

    An organization trail logs events for the management account and all member accounts, is added to accounts that join later, and member accounts cannot remove or modify it.

  • CRely on CloudTrail event history in each account and export it to the log archive account each month

    Incorrect

    Event history holds only 90 days of management events per Region and account. It is not a durable, centrally controlled record.

  • DCreate a multi-Region trail in the management account that delivers to the log archive account's bucket

    Incorrect

    A trail that is not applied to the organization logs only the account it is created in, so member account activity is missing.

The organization trail is the control that member accounts cannot touch. It can also be created by a CloudTrail delegated administrator account, and the bucket policy must allow CloudTrail to write the organization's log files.

Question 2 · choose 1

GuardDuty reported that a resource in a VPC queried a domain linked to malware. The instances use the Amazon-provided DNS server. For future investigations, the team must be able to see which instance asked for which domain name, and keep that record for a year. What should the team configure?

  1. AVPC flow logs with all available fields, delivered to an S3 bucket
  2. BPublic DNS query logging for the company's Route 53 public hosted zones
  3. CA Route 53 Resolver query logging configuration associated with the VPC
  4. DExport of GuardDuty's DNS log data source to an S3 bucket for a year
Show the answer and why
  • AVPC flow logs with all available fields, delivered to an S3 bucket

    Incorrect

    Flow logs do not record traffic that instances send to the Amazon DNS server, and they never contain the names being queried.

  • BPublic DNS query logging for the company's Route 53 public hosted zones

    Incorrect

    Public query logging records queries that resolvers send to Route 53 for the company's own public hosted zones, not lookups that instances make for other domains.

  • CA Route 53 Resolver query logging configuration associated with the VPC

    Correct

    Resolver query logs record queries that originate in the associated VPCs, including the instance ID, source IP and the name queried, and can be sent to S3 for long retention.

  • DExport of GuardDuty's DNS log data source to an S3 bucket for a year

    Incorrect

    GuardDuty reads DNS query logs through its own independent stream, separate from Resolver query logging. It does not hand that stream to you.

The question "which instance looked up this name" is answered only by Resolver query logs. Note that cached answers are not logged again within the TTL.

Question 3 · choose 1

A company wants CloudTrail management events, VPC flow logs, Route 53 Resolver query logs and Security Hub CSPM findings from all accounts and Regions stored in one place that it owns. The data must be in a common open schema so that the company's third-party SIEM can read it without custom parsers. Which solution meets these requirements?

  1. ATurn on Security Hub CSPM cross-Region aggregation and give the SIEM access to the home Region
  2. BStream each log group to the SIEM through CloudWatch Logs subscription filters and Amazon Data Firehose
  3. CTurn on Amazon Detective for the organization and give the SIEM access to the behavior graph
  4. DTurn on Amazon Security Lake for the organization and add the SIEM as a subscriber
Show the answer and why
  • ATurn on Security Hub CSPM cross-Region aggregation and give the SIEM access to the home Region

    Incorrect

    Cross-Region aggregation replicates findings, insights and control data. It does not collect flow logs or DNS logs.

  • BStream each log group to the SIEM through CloudWatch Logs subscription filters and Amazon Data Firehose

    Incorrect

    This moves each source in its own native format, so the SIEM still needs a parser per source, and it adds pipelines to run.

  • CTurn on Amazon Detective for the organization and give the SIEM access to the behavior graph

    Incorrect

    Detective builds a behavior graph for investigations. It is not a data lake that other tools read in a common schema.

  • DTurn on Amazon Security Lake for the organization and add the SIEM as a subscriber

    Correct

    Security Lake collects these sources across accounts and Regions into S3 buckets in your account, converts them to OCSF in Parquet, and gives subscribers data or query access.

"Many sources, one open schema, owned by us, read by other tools" is the description of Security Lake: OCSF normalization plus subscribers.

Question 4 · choose 2

Security analysts must run ad hoc queries over two sources without building new pipelines: two years of CloudTrail log files in the log archive S3 bucket, and the last 30 days of application logs in CloudWatch Logs. Which services should they use? (Choose TWO.)

  1. ACloudTrail event history in the log archive account
  2. BSecurity Hub CSPM custom insights grouped by resource and account
  3. CAmazon Athena with a table defined over the trail's S3 location
  4. DAmazon Detective finding groups for the related entities
  5. ECloudWatch Logs Insights on the application log groups
Show the answer and why
  • ACloudTrail event history in the log archive account

    Incorrect

    Event history covers only the past 90 days of management events for one account and Region.

  • BSecurity Hub CSPM custom insights grouped by resource and account

    Incorrect

    An insight is a grouping of security findings. It does not query application logs or raw CloudTrail files.

  • CAmazon Athena with a table defined over the trail's S3 location

    Correct

    Athena queries CloudTrail log files where they are stored in S3, and partition projection keeps queries over long periods efficient.

  • DAmazon Detective finding groups for the related entities

    Incorrect

    Finding groups relate findings and entities for an investigation. They are not an ad hoc query tool for arbitrary logs.

  • ECloudWatch Logs Insights on the application log groups

    Correct

    Logs Insights interactively searches and analyzes log data that is already in CloudWatch Logs.

Query data where it already lives: Athena for log files in S3, Logs Insights for log groups.

Question 5 · choose 1

A team notices that application log groups in CloudWatch Logs keep data forever, and storage costs grow. Policy says to keep these logs for one year. What should the team do?

  1. ADelete the log streams by hand every month
  2. BEncrypt the log groups with a KMS key that expires
  3. CSet a one-year retention on each log group
  4. DTurn on S3 Lifecycle rules for the log groups
Show the answer and why
  • ADelete the log streams by hand every month

    Incorrect

    Manual deletion is error-prone and not a policy.

  • BEncrypt the log groups with a KMS key that expires

    Incorrect

    KMS keys do not expire on their own, and encryption does not remove data.

  • CSet a one-year retention on each log group

    Correct

    By default, log data is kept indefinitely; a retention setting on the log group deletes older events.

  • DTurn on S3 Lifecycle rules for the log groups

    Incorrect

    Log groups are not S3 buckets; S3 Lifecycle does not apply to them.

Set retention when log groups are created, for example in the template that creates them.

Question 6 · choose 1

Database auditors need the audit logs of an Amazon RDS for MySQL instance in a central, searchable place. The team has no access to the database host's file system. What should the team do?

  1. ACopy the log files from the host over SSH every night
  2. BPublish the database logs to Amazon CloudWatch Logs
  3. CTurn on CloudTrail data events for the RDS instance
  4. DTurn on VPC Flow Logs for the database subnet
Show the answer and why
  • ACopy the log files from the host over SSH every night

    Incorrect

    Amazon RDS does not provide host access to the database log files.

  • BPublish the database logs to Amazon CloudWatch Logs

    Correct

    Amazon RDS can export database logs to CloudWatch Logs for analysis and durable storage.

  • CTurn on CloudTrail data events for the RDS instance

    Incorrect

    CloudTrail records API calls to the RDS service, not the database's own audit log.

  • DTurn on VPC Flow Logs for the database subnet

    Incorrect

    Flow logs show network flows, not database audit events.

Pick which log types to publish, for example the audit log, in the instance's settings.

Question 7 · choose 1

Auditors want a history of how resource configurations in an account have changed, stored in S3, plus periodic snapshots of all recorded resources. Which AWS Config component delivers this?

  1. AA conformance pack with the operational best practices
  2. BAn aggregator in the same account and Region
  3. CThe delivery channel with snapshots turned on
  4. DA remediation action attached to each AWS Config rule
Show the answer and why
  • AA conformance pack with the operational best practices

    Incorrect

    Conformance packs evaluate compliance; they do not deliver history files.

  • BAn aggregator in the same account and Region

    Incorrect

    Aggregators combine data from accounts and Regions for viewing; they do not deliver files to S3.

  • CThe delivery channel with snapshots turned on

    Correct

    The delivery channel sends configuration history and snapshots to S3 and notifications to SNS.

  • DA remediation action attached to each AWS Config rule

    Incorrect

    Remediation fixes resources; it does not deliver history.

The configuration recorder captures changes; the delivery channel decides where they go.

Question 8 · choose 1

A company has one AWS account and wants CloudTrail to log activity in every enabled Region, including Regions it does not use today, into a single S3 bucket. What should it create?

  1. AOne trail in each Region the company uses
  2. BOne multi-Region trail for the whole account
  3. CA trail that has only data events turned on
  4. DThe CloudTrail event history of each Region
Show the answer and why
  • AOne trail in each Region the company uses

    Incorrect

    Activity in other Regions would go unlogged.

  • BOne multi-Region trail for the whole account

    Correct

    A multi-Region trail logs events from all Regions enabled in the account and delivers them to the same bucket.

  • CA trail that has only data events turned on

    Incorrect

    Data events add object-level activity; they do not widen Regional coverage.

  • DThe CloudTrail event history of each Region

    Incorrect

    Event history is per Region and kept for 90 days; it is not delivered to a bucket.

Pair the multi-Region trail with an SCP that keeps it from being stopped or deleted.

Question 9 · choose 1

Administrators reach instances only through Session Manager, and session logging to S3 is on. Auditors notice that some sessions have no recorded commands. Those engineers connected with SSH through Session Manager. What explains the gap?

  1. AThe S3 bucket for the logs lacks default encryption
  2. BCloudTrail data events are not turned on for Systems Manager
  3. CData sent over SSH or port forwarding is not logged
  4. DThe instances use IMDSv1 instead of IMDSv2
Show the answer and why
  • AThe S3 bucket for the logs lacks default encryption

    Incorrect

    Encryption settings do not decide which sessions are logged.

  • BCloudTrail data events are not turned on for Systems Manager

    Incorrect

    CloudTrail records API calls, not the commands typed in a session.

  • CData sent over SSH or port forwarding is not logged

    Correct

    For SSH, data is encrypted end to end and Session Manager is only a tunnel, so it cannot log the session data.

  • DThe instances use IMDSv1 instead of IMDSv2

    Incorrect

    The metadata service version has no effect on session logging.

If full command logging is required, allow only standard shell sessions and block SSH and port forwarding through the session documents.

Practise domain 1 →Practise all domains →