🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company hosts a Java web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The security team must detect brute-force login attempts by monitoring the application's log file (app.log) in near real time and must keep the logs for 90 days. Which solution provides the required visibility and retention while minimizing ongoing operational effort?

  • Enable VPC Flow Logs for the application subnets, export logs to an S3 bucket with a 90-day lifecycle rule, and turn on Amazon GuardDuty to alert on suspicious activity.

  • Keep app.log on each EC2 instance's EBS volume, run a daily cron job to search for failed logins and email a report, and rotate and delete logs older than 90 days.

  • Install and configure the CloudWatch Logs agent on each instance to stream app.log to a CloudWatch Logs group, create a metric filter for failed logins, and set the log group retention period to 90 days.

  • Enable S3 server access logging on the application's artifact bucket, deliver logs to CloudTrail Lake, and query weekly with Amazon Athena to find repeated login failures.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot