SCS-C03 Exam Question 46

A company has a single AWS account and uses an Amazon EC2 instance to test application code. The company recently discovered that the instance was compromised and was serving malware. Analysis showed that the instance was compromised 35 days ago. A security engineer must implement a continuous monitoring solution that automatically notifies the security team by email for high severity findings as soon as possible.
Which combination of steps should the security engineer take to meet these requirements? (Select THREE.)
  • SCS-C03 Exam Question 47

    A company is operating an open-source software platform that is internet facing. The legacy software platform no longer receives security updates. The software platform operates using Amazon Route 53 weighted load balancing to send traffic to two Amazon EC2 instances that connect to an Amazon RDS cluster. A recent report suggests this software platform is vulnerable to SQL injection attacks, with samples of attacks provided. The company ' s security engineer must secure this system against SQL injection attacks within 24 hours. The security engineer's solution must involve the least amount of effort and maintain normal operations during implementation.
    What should the security engineer do to meet these requirements?
  • SCS-C03 Exam Question 48

    A security engineer is responding to an incident that is affecting an AWS account. The ID of the account is
    123456789012. The attack created workloads that are distributed across multiple AWS Regions.
    The security engineer contains the attack and removes all compute and storage resources from all affected Regions. However, the attacker also created an AWS KMS key. The key policy on the KMS key explicitly allows IAM principal kms:* permissions.
    The key was scheduled to be deleted the previous day. However, the key is still enabled and usable. The key has an ARN of arn:aws:kms:us-east-2:123456789012:key/mrk-0bb0212cd9864fdea0dcamzo26efb5670.
    The security engineer must delete the key as quickly as possible.
    Which solution will meet this requirement?
  • SCS-C03 Exam Question 49

    A startup company is using a single AWS account that has resources in a single AWS Region. A security engineer configures an AWS CloudTrail trail in the same Region to deliver log files to an Amazon S3 bucket by using the AWS CLI. Because of expansion, the company adds resources in multiple Regions. The security engineer notices that the logs from the new Regions are not reaching the S3 bucket.
    What should the security engineer do to fix this issue with the LEAST amount of operational overhead?
  • SCS-C03 Exam Question 50

    A company uploads data files as objects into an Amazon S3 bucket. A vendor downloads the objects to perform data processing.
    A security engineer must implement a solution that prevents objects from residing in the S3 bucket for longer than 72 hours.