AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium
A security engineer is investigating a series of failed login attempts targeting an EC2 instance running a critical application. The attempts are originating from various suspicious IP addresses. The engineer needs to quickly identify the source IP addresses, the time of the attempts, and the specific user accounts targeted, to block further access. Which logging and monitoring solution provides the most direct and actionable information for this investigation?
- AVPC Flow Logs
- BAmazon CloudWatch Metrics for EC2
- CAWS CloudTrail data events for S3
- DApplication logs from the EC2 instance
Show answer & explanationAnswer & explanation
Correct answer: D. Application logs from the EC2 instance
Application logs generated by the critical application running on the EC2 instance would contain the most granular details about login attempts, including source IP addresses, timestamps, and targeted user accounts. VPC Flow Logs show network traffic, but not application-level login details. CloudTrail focuses on AWS API calls, and CloudWatch Metrics provide aggregated data.
Why the other options are wrong
- A. VPC Flow Logs record IP traffic information for network interfaces, which can show source/destination IPs and ports, but not application-specific login attempts or user accounts.
- B. Amazon CloudWatch Metrics for EC2 provide performance metrics like CPU utilization or network in/out, but not details of application-level login attempts.
- C. CloudTrail data events for S3 track S3 object-level actions, which are irrelevant to EC2 instance login attempts.
Application Logs
Logs generated directly by an application (e.g., web server, database, custom software) that record events, errors, and user activities specific to that application's operations.
- Provide granular details about application-level events.
- Essential for troubleshooting application issues and security incidents.
- Location and format vary by application and operating system.
Memory trick: For EC2 logins, check the app's own diary.