exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 65 discussion

A company is using Amazon Route 53 Resolver for its hybrid DNS infrastructure. The company has set up Route 53 Resolver forwarding rules for authoritative domains that are hosted on on-premises DNS servers.

A new security mandate requires the company to implement a solution to log and query DNS traffic that goes to the on-premises DNS servers. The logs must show details of the source IP address of the instance from which the query originated. The logs also must show the DNS name that was requested in Route 53 Resolver.

Which solution will meet these requirements?

  • A. Use VPC Traffic Mirroring. Configure all relevant elastic network interfaces as the traffic source, include amazon-dns in the mirror filter, and set Amazon CloudWatch Logs as the mirror target. Use CloudWatch Insights on the mirror session logs to run queries on the source IP address and DNS name.
  • B. Configure VPC flow logs on all relevant VPCs. Send the logs to an Amazon S3 bucket. Use Amazon Athena to run SQL queries on the source IP address and DNS name.
  • C. Configure Route 53 Resolver query logging on all relevant VPCs. Send the logs to Amazon CloudWatch Logs. Use CloudWatch Insights to run queries on the source IP address and DNS name.
  • D. Modify the Route 53 Resolver rules on the authoritative domains that forward to the on-premises DNS servers. Send the logs to an Amazon S3 bucket. Use Amazon Athena to run SQL queries on the source IP address and DNS name.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Malluchan
1 month ago
Selected Answer: C
C is the answer, Resolver query logs include values such as the following: The AWS Region where the VPC was created The ID of the VPC that the query originated from The IP address of the instance that the query originated from The instance ID of the resource that the query originated from The date and time that the query was first made The DNS name requested (such as prod.example.com) The DNS record type (such as A or AAAA) The DNS response code, such as NoError or ServFail The DNS response data, such as the IP address that is returned in response to the DNS query
upvoted 1 times
...
Daniel76
1 year, 4 months ago
Selected Answer: C
C is the only answer as you need to config resolver query logging on all vpc, and cloudwatch log insight indeed allow you to query the source IP address. https://aws.amazon.com/blogs/aws/log-your-vpc-dns-queries-with-route-53-resolver-query-logs/
upvoted 2 times
...
brpjp
1 year, 4 months ago
Correct answer is D. https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resolver.html. Please read this statement : Resolver rules enable you to create one forwarding rule for each domain name and specify the name of the domain for which you want to forward DNS queries from your VPC to an on-premises DNS resolver and from your on-premises to your VPC. Rules are applied directly to your VPC and can be shared across multiple accounts. so correct answer, based on above statement is D and not C, as it does not specify the requirements to send outbound connections to on-premise.
upvoted 1 times
FlyingHawk
2 months, 3 weeks ago
Route 53 Resolver rules do not generate logs by themselves. There is no built-in feature to modify rules to send logs to S3. The correct method is to enable Route 53 Resolver query logging, not modify forwarding rules.
upvoted 1 times
...
helloworldabc
7 months, 2 weeks ago
just C
upvoted 1 times
...
...
ahrentom
1 year, 5 months ago
Selected Answer: C
For me it´s anwser C https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resolver-query-logs.html
upvoted 3 times
...
[Removed]
1 year, 5 months ago
Selected Answer: C
Seems like it's C https://medium.com/@sisodiyapradeep/dns-query-logging-aggregation-control-tower-environment-well-architected-telemetry-workload-266dcdbf7195
upvoted 2 times
...
oioi
1 year, 5 months ago
Selected Answer: C
correct.
upvoted 1 times
...
marlonchin
1 year, 5 months ago
https://repost.aws/knowledge-center/route53-view-endpoint-traffic
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago