ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your security team converts CloudTrail logs into a CloudWatch custom metric that counts denied S3 API calls every 24 hours. They have 90 days of historical data that accurately reflects normal usage and want to receive an alert only when the daily count deviates more than three standard deviations from that baseline. Which CloudWatch capability lets them accomplish this with the least additional development effort?
Configure a standard CloudWatch alarm that fires when the metric exceeds a fixed threshold derived from the 90-day average.
Turn on Amazon GuardDuty S3 Protection so that it generates findings whenever unusual S3 access attempts occur.
Enable CloudWatch Anomaly Detection for the metric and create an alarm that triggers when data points are outside a three-sigma band.
Attach a CloudWatch Logs metric filter and subscribe it to an SNS topic that publishes every time the metric is updated.
CloudWatch Anomaly Detection automatically builds a statistical model from the metric's historical values, calculates an expected range, and allows an alarm to fire when the datapoint falls outside a band expressed in standard deviations. A static threshold alarm (distractor) ignores normal variance and generates false positives. A metric filter plus SNS still requires the team to hard-code a threshold. GuardDuty S3 Protection detects known threat patterns, not statistical outliers in a custom metric.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CloudWatch Anomaly Detection and how does it work?
Open an interactive chat with Bash
What are the advantages of using a three-sigma band for anomaly detection?
Open an interactive chat with Bash
How does CloudWatch Anomaly Detection differ from static threshold alarms?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .