Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SCS-C03 Exam - Topic 3 Question 4 Discussion

Actual exam question for Amazon's SCS-C03 exam
Question #: 4
Topic #: 3
[All SCS-C03 Questions]

A company's security team wants to receive near-real-time email notifications about AWS abuse reports related to DoS attacks. An Amazon SNS topic already exists and is subscribed to by the security team.

What should the security engineer do next?

Show Suggested Answer Hide Answer
Suggested Answer: B

AWS abuse notifications are delivered as AWS Health events. According to the AWS Certified Security -- Specialty Study Guide, Amazon EventBridge integrates natively with AWS Health and can be used to detect specific event types such as AWS_ABUSE_DOS_REPORT in near real time.

By creating an EventBridge rule that filters for the abuse report event type and publishes directly to Amazon SNS, the solution remains fully managed, low latency, and cost effective.

Polling APIs introduces delay and complexity. CloudTrail does not log abuse notifications. EventBridge with AWS Health is the recommended mechanism for reacting to AWS service events.

Referenced AWS Specialty Documents:

AWS Certified Security -- Specialty Official Study Guide

AWS Health and EventBridge Integration

AWS Abuse Notification Handling


Contribute your Thoughts:

0/2000 characters
Sol
4 days ago
Gotta love those AWS acronyms. Keeps us on our toes, eh?
upvoted 0 times
...
Mirta
10 days ago
D) is the classic "let's make it complicated" solution. I'll stick with B).
upvoted 0 times
...
Alyssa
15 days ago
Haha, "AWS_ABUSE_DOS_REPORT" - sounds like a party I don't want to be invited to!
upvoted 0 times
...
Tamra
20 days ago
Hmm, I'm not sure about that. Polling Trusted Advisor seems like a more direct approach.
upvoted 0 times
...
Kendra
25 days ago
B) is the way to go. Straight to the point!
upvoted 0 times
...
Shelton
1 month ago
I recall we discussed EventBridge in relation to AWS Health events, so option B might be the best choice here.
upvoted 0 times
...
Latrice
1 month ago
I feel like using CloudTrail logs could be a valid approach, but I’m not confident if it would be as immediate as the other options.
upvoted 0 times
...
Derick
2 months ago
I'm not entirely sure, but I remember something about polling APIs in our study sessions. Is that what options A and C are doing?
upvoted 0 times
...
Leeann
2 months ago
I think option B sounds familiar since we practiced setting up EventBridge rules for specific AWS events.
upvoted 0 times
...
Ahmed
2 months ago
B seems like the best choice to me. Automating the notification process through EventBridge and SNS is going to be the most robust and low-maintenance solution. The other options just add unnecessary complexity in my opinion.
upvoted 0 times
...
Sheridan
2 months ago
I'm a little confused by all the different AWS services involved. I'd need to double-check the details on how each of these options works, but I think I'm leaning towards B or D. Gotta make sure I fully understand the requirements first.
upvoted 0 times
...
Brunilda
3 months ago
Option B is definitely the way to go here. It's the most efficient and reliable way to get those abuse notifications in near-real-time without having to build and maintain any additional custom code.
upvoted 0 times
...
Catalina
3 months ago
Hmm, I'm a bit unsure about this one. I'm trying to decide between B and D. Polling the Support API or using CloudTrail and CloudWatch might give me more control, but the EventBridge option does sound simpler.
upvoted 0 times
...
Kelvin
3 months ago
I think I'd go with option B. Creating an EventBridge rule to match the AWS Health events seems like the most straightforward way to get the notifications directly to the SNS topic.
upvoted 0 times
...

Save Cancel