CoStudy

HomeCertificationsAWS Certified Security SCS-C03 › Security Logging and Monitoring

Security Logging and Monitoring — AWS Certified Security SCS-C03 practice questions

24 multiple-choice questions and 13 flashcards on Security Logging and Monitoring, about 13% of the AWS Certified Security SCS-C03 bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Security Logging and Monitoring is one of 6 chapters in CoStudy's AWS Certified Security — Specialty (SCS-C03) bank, and it holds 24 of the bank's 178 multiple-choice questions — roughly 13% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Security Logging and Monitoring practice questions

3 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

A multi-account org needs a single tamper-evident log of S3 object-level activity across every account. The MINIMAL correct CloudTrail design is:

  1. IAM policy with NotAction wildcard
  2. Cross-account role assumed with sts:AssumeRole
  3. Amazon Inspector for network scanning
  4. GuardDuty for data classification

Answer: B — Cross-account role assumed with sts:AssumeRole

Org trail centralizes across all accounts. Data events (opt-in, billed) are required for S3 object-level (GetObject/PutObject). Log file validation provides cryptographic integrity. Object Lock + dedicated log archive account provide WORM and blast-radius isolation. A is fragmented and not tamper-resistant. C misses S3 object events. D is unrelated (Insights = anomaly detection).

AWS Security Hub provides:

  1. Detective without GuardDuty enabled
  2. Aggregates findings from GuardDuty, Inspector
  3. Public subnet with IGW route
  4. Envelope encryption via customer library

Answer: B — Aggregates findings from GuardDuty, Inspector

Security Hub: single pane of glass for security findings across AWS services and partner integrations. ASFF (AWS Security Finding Format). Continuous compliance checks. Cross-account aggregation. Critical SCS-C02 service.

AWS Config aggregator's PRIMARY use is to:

  1. Detective without GuardDuty enabled
  2. VPC endpoint policy restricting bucket access
  3. AWS Glue crawler without KMS-encrypted output
  4. Self-signed certificate stored in ACM

Answer: B — VPC endpoint policy restricting bucket access

Aggregator = multi-account/multi-Region view. The others are wrong.

Security Logging and Monitoring flashcards

4 cards from the 13 in this chapter.

Security Hub?

Aggregates findings from GuardDuty, Inspector, Macie, IAM Access Analyzer. Compliance dashboards.

CloudTrail Lake?

Managed query service for CloudTrail data. SQL queries.

CloudTrail organizational trail?

Single trail across all org accounts. Centralized auditing.

AWS CloudTrail?

Logs API calls. Audit trail. Required for security investigations.

Practise the full chapter

These are a sample. The full Security Logging and Monitoring chapter runs 37 items with per-chapter progress tracking, on the web and in the iOS app.

Open AWS Certified Security SCS-C03 in CoStudy →

Other AWS Certified Security SCS-C03 chapters

All AWS Certified Security SCS-C03 practice questions →