New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 15 Topic 2 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 15 Topic 2 Discussion

SCS-C02 Exam Topic 2 Question 15 Discussion:
Question #: 15
Topic #: 2

A security engineer configures VPC Flow Logs and the associated IAM role to log all VPC traffic to a log group in Amazon CloudWatch Logs. After a wait of 10 minutes, no logs are appearing in the log group. The security engineer confirms that traffic is being sent to the VPC.

After additional debugging, the security engineer isolates the problem to the role that is associated with the VPC flow logs.

What could be the reason that the logs are not appearing in CloudWatch Logs?


A.

The logs:GetLogEvents permission is not granted in the role.


B.

The security engineer does not have permission to assume the role.


C.

The principal vpc-flow-logs.amazonaws.com does not have permission to assume the role.


D.

The role does not have permission to tag a CloudWatch Logs stream.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.