Metric Filters for Security Events Quiz

5 questions Pass: 70% +25 pts

Quiz covering CloudWatch Security Monitoring

Metric Filters for Security Events Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    What is the primary purpose of a CloudWatch Metric Filter in the context of security monitoring?

  2. 2

    You are monitoring CloudTrail logs for unauthorized API calls. Which component is required to receive an email notification when a specific metric filter pattern is matched?

  3. 3

    When defining a metric filter pattern to detect 'UnauthorizedOperation' errors in CloudTrail logs, what is the best practice for capturing only relevant events?

  4. 4

    You have created a metric filter to track 'root' user logins. After testing, you notice the metric is not incrementing even though 'root' logins are occurring. What is the most likely cause?

  5. 5

    You need to monitor for multiple distinct security events (e.g., 'ConsoleLoginFailure' and 'UnauthorizedApiCall') within the same log group. How should you configure your metric filters?