Amazon SCS-C02 Exam - Topic 1 Question 10 Discussion
A security engineer is configuring a mechanism to send an alert when three or more failed sign-in attempts to the AWS Management Console occur during a 5-minute period. The security engineer creates a trail in AWS CloudTrail to assist in this work.Which solution will meet these requirements?
B) Configure CloudTrail to send events to Amazon CloudWatch Logs. Create a metric filter for the relevant log group. Create a filter pattern with eventName matching ConsoleLogin and errorMessage matching ''Failed authentication''. Create a CloudWatch alarm with a threshold of 3 and a period of 5 minutes.
A) In CloudTrail, turn on Insights events on the trail. Configure an alarm on the insight with eventName matching ConsoleLogin and errorMessage matching ''Failed authentication''. Configure a threshold of 3 and a period of 5 minutes.
C) Create an Amazon Athena table from the CloudTrail events. Run a query for eventName matching ConsoleLogin and for errorMessage matching ''Failed authentication''. Create a notification action from the query to send an Amazon Simple Notification Service (Amazon SNS) notification when the count equals 3 within a period of 5 minutes.
D) In AWS Identity and Access Management Access Analyzer, create a new analyzer. Configure the analyzer to send an Amazon Simple Notification Service (Amazon SNS) notification when a failed sign-in event occurs 3 times for any IAM user within a period of 5 minutes.
Lindsey
6 months agoMalinda
6 months agoFanny
7 months agoAllene
7 months agoTracie
7 months agoLenita
7 months agoOren
7 months agoBrock
8 months agoIluminada
8 months agoPenney
8 months agoJanella
8 months agoNana
8 months agoLouvenia
8 months agoClorinda
8 months agoPaz
8 months agoKanisha
8 months agoDaren
8 months agoGeorgiana
8 months agoJusta
2 years agoAleta
2 years agoMable
2 years agoGeorgene
2 years agoViva
2 years agoElfrieda
2 years agoHeike
2 years agoOcie
2 years agoFabiola
2 years agoLon
2 years ago