ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security team ingests AWS CloudTrail and VPC Flow Logs into an on-premises SIEM. Analysts complain that successful Describe* and List* API calls clog dashboards, masking higher-risk activity and inflating ingestion costs. Without eliminating visibility into unauthorized or write operations, which log-tuning change provides the MOST effective reduction of noise at the source?
Modify the existing CloudTrail trail to log only management events with a WriteOnly read/write type and to include events that return an Error response.
Change the CloudWatch Logs retention policy for the CloudTrail log group to one day so excess data is purged quickly.
Configure VPC Flow Logs to capture only 10% of accepted traffic and all rejected traffic before forwarding to the SIEM.
Disable the CloudWatch Logs subscription filter that forwards CloudTrail to the SIEM while continuing to archive the raw logs in Amazon S3.
Configuring CloudTrail to capture only WriteOnly management events-while still recording events that result in an Error status-removes the bulk of successful read-only calls such as Describe* and List*. The setting keeps all write activity (create, modify, delete) and any failed or unauthorized read attempts, so threat detection coverage is retained. Adjusting VPC Flow Logs sampling is not possible, shortening retention does not reduce data sent to the SIEM, and disabling the subscription filter would drop all CloudTrail visibility rather than selectively reduce low-value traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are AWS CloudTrail management events?
Open an interactive chat with Bash
What is the role of a SIEM in log ingestion and analysis?
Open an interactive chat with Bash
Why should Error responses be logged in CloudTrail?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .