What's changed: Deepened SCS-C02 Chapter 2 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)
2.4In-scope services for security logging and monitoring
A roundup of in-scope SCS-C03 services for security logging and monitoring.
2.4.1In-scope services for security logging and monitoring
For security logging and monitoring, beyond CloudTrail/CloudWatch/Config, know: AWS CloudTrail Lake (immutably retain CloudTrail events long-term and analyze with SQL), Amazon Managed Grafana (visualize metrics/logs), AWS User Notifications (centralize/deliver AWS notifications from many sources), Network Access Analyzer (statically analyze network reachability intent), and Amazon EMR (distributed analysis of large logs).
2.4.2Section summary
- Retain/analyze: CloudTrail Lake / EMR / Network Access Analyzer
- Visualize/notify: Managed Grafana / User Notifications
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which retains CloudTrail events immutably long-term and lets you query them with SQL for audit/investigation?
Q2. Which statically analyzes configuration (security groups, routes) to find unintended network reachability?

