ECCouncil EC-Council Certified Cloud Security Engineer (CCSE) 312-40 Question # 2 Topic 1 Discussion

ECCouncil EC-Council Certified Cloud Security Engineer (CCSE) 312-40 Question # 2 Topic 1 Discussion

312-40 Exam Topic 1 Question 2 Discussion:
Question #: 2
Topic #: 1

An organization uses AWS for its operations. It is observed that the organization's EC2 instance is

communicating with a suspicious port. Forensic investigators need to understand the patterns of the current security breach. Which log source on the AWS platform can provide investigators with data of evidentiary value during their investigation?


A.

Amazon CloudTrail


B.

Amazon CloudWatch


C.

Amazon VPC flow logs


D.

S3 Server Access Logs


Get Premium 312-40 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.