ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security analyst must be alerted whenever more than 20 failed SSH login attempts are recorded against any Amazon Linux EC2 instance within a five-minute window. The instances already stream their /var/log/secure files to a central CloudWatch Logs group. Which action will generate the metric that can be used to trigger a CloudWatch alarm while keeping costs minimal?
Enable detailed monitoring on the EC2 instances and configure a CloudWatch alarm on the EC2 StatusCheckFailed metric.
Define a CloudWatch Logs metric filter for the pattern "Failed password" in the log group and publish it as a custom metric.
Create VPC Flow Logs for each subnet and query them with Amazon Athena every five minutes using a scheduled query.
Turn on an AWS Config rule that evaluates security group ingress for port 22 and configure SNS notifications for non-compliant findings.
CloudWatch Logs metric filters can examine incoming log events and increment a CloudWatch custom metric whenever a defined pattern is detected. By matching the string that appears in /var/log/secure for a failed SSH authentication (for example, "Failed password"), the analyst converts log data into a numerical metric. A CloudWatch alarm can then watch this metric and notify when the count exceeds the threshold. Detailed monitoring, AWS Config rules, and VPC Flow Logs either do not create the required metric or add unnecessary cost and complexity for this specific use case.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is 'Failed password' chosen as the pattern for the CloudWatch Logs metric filter?
Open an interactive chat with Bash
What is a CloudWatch Logs metric filter and how does it work?
Open an interactive chat with Bash
How is a custom metric used to trigger a CloudWatch alarm?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .