Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 20 Topic 3 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 20 Topic 3 Discussion

SCS-C03 Exam Topic 3 Question 20 Discussion:
Question #: 20
Topic #: 3

A company uses an organization in AWS Organizations to manage its 250 member accounts. The company also uses AWS IAM Identity Center with a SAML external identity provider (IdP). IAM Identity Center has been delegated to a member account. The company ' s security team has access to the delegated account.

The security team has been investigating a malicious internal user who might be accessing sensitive accounts. The security team needs to know when the user logged into the organization during the last 7 days.

Which solution will quickly identify the access attempts?


A.

In the delegated account, use Amazon CloudWatch Logs to search for events that match the user details for all successful attempts.


B.

In each member account, use the IAM Identity Center console to search for events that match the user details for all attempts.


C.

In the external IdP, use Amazon EventBridge to search for events that match the user details for all attempts.


D.

In the organization ' s management account, use AWS CloudTrail to search for events that match the user details for all successful attempts.


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.