exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 106 discussion

A security engineer wants to forward custom application-security logs from an Amazon EC2 instance to Amazon CloudWatch. The security engineer installs the CloudWatch agent on the EC2 instance and adds the path of the logs to the CloudWatch configuration file.

However, CloudWatch does not receive the logs. The security engineer verifies that the awslogs service is running on the EC2 instance.

What should the security engineer do next to resolve the issue?

  • A. Add AWS CloudTrail to the trust policy of the EC2 in stance. Send the custom logs to CloudTrail instead of CloudWatch.
  • B. Add Amazon S3 to the trust policy of the EC2 instance. Configure the application to write the custom logs to an S3 bucket that CloudWatch can use to ingest the logs.
  • C. Add Amazon Inspector to the trust policy of the EC2 instance. Use Amazon Inspector instead of the CloudWatch agent to collect the custom logs.
  • D. Attach the CloudWatchAgentServerPolicy AWS managed policy to the EC2 instance role.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jamshif01
10 months, 2 weeks ago
D All other answers are irrelevant
upvoted 2 times
...
rahav
11 months, 2 weeks ago
Selected Answer: D
D for sure
upvoted 2 times
...
yorkicurke
11 months, 2 weeks ago
Selected Answer: D
Uses of CloudWatchAgentServerPolicy ; It allows the CloudWatch agent to publish metrics and logs to CloudWatch on behalf of the IAM role or user the policy is attached to. It provides permissions for the agent to access and manage its own configuration files stored in S3. The policy grants permissions across multiple AWS services like CloudWatch, S3, KMS etc. to allow end-to-end functionality of the monitoring agent.
upvoted 3 times
...
ykhan321
11 months, 2 weeks ago
Selected Answer: D
Only EC2 & Cloudwatch are in questions here.
upvoted 1 times
...
Oralinux
12 months ago
Answer: D
upvoted 1 times
...
Aamee
1 year ago
Selected Answer: D
No doubt about D.
upvoted 3 times
...
[Removed]
1 year ago
Selected Answer: D
D is correcto
upvoted 3 times
...
oioi
1 year ago
Selected Answer: D
correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...