Alert on 5 bastion failed logins in 5 minutes via CloudWatch metric-filter alarm and SNS message filtering

Design and implement monitoring and alerting to address security events. Troubleshoot security monitoring and alerting.
Answer Correct answer: C — CloudWatch agent, failed-login metric-filter alarm, and SNS message filtering to the assigned admin, with no EventBridge needed.

A company is implementing a customized notification solution to detect repeated unauthorized authentication attempts to bastion hosts. The company’s security engineer needs to implement a solution that will provide notification when 5 failed attempts occur within a 5-minute period. The solution must use native AWS services and must notify only the designated system administrator who is assigned to the specific bastion host. Which solution will meet these requirements?

  1. Use the Amazon CloudWatch agent to collect operating system logs. Use Amazon EventBridge to configure an alarm based on a metric filter for failed login attempts. Send an alert to Amazon Simple Notification Service (Amazon SNS) when the defined threshold for the alarm is exceeded. Use Amazon EC2 instance tags to determine which SNS topics receive notifications.
  2. Use AWS Systems Manager Agent to collect operating system logs. Use the Systems Manager Run Command AWS-ConfigureCloudWatch document to configure an Amazon EventBridge event based on a metric filter for failed login attempts. Send an alert to Amazon Simple Notification Service (Amazon SNS) when the defined threshold for the alarm is exceeded. Use SNS messaging filters to control who receives notifications.
  3. Use the Amazon CloudWatch agent to collect operating system logs. Create a CloudWatch alarm based on a metric filter for failed login attempts. Send an alert to Amazon Simple Notification Servige (Amazon SNS) when the defined threshold for the alarm is exceeded. Use SNS messaging filters to control who receives notifications. Correct Answer
  4. Use AWS Systems Manager Agent to collect operating system logs. Use the Systems Manager Run Command AWS-ConfigureCloudWatch document to configure an Amazon CloudWatch alarm based on a metric filter for failed login attempts. Send an alert to Amazon Simple Notification Service (Amazon SNS) when the defined threshold for the alarm is exceeded. Use EC2 instance tags to determine which SNS topics receive notifications.

Community Votes

C
66%
A
34%

66% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CloudWatch metric filters convert log patterns into CloudWatch metrics that an alarm can threshold (5 in 5 minutes). SNS message filtering routes the notification to the correct subscriber based on message attributes (e.g., the bastion host identifier), satisfying the per-host admin requirement without EventBridge. EventBridge is unnecessary when a CloudWatch alarm already delivers to SNS.

The company needs native notification when a bastion host sees 5 failed authentication attempts within 5 minutes, routed only to the administrator assigned to that host. The CloudWatch agent ships the OS auth logs to CloudWatch Logs; a metric filter counts failed login attempts and a CloudWatch alarm triggers at the threshold, sending to an SNS topic that uses subscription message filtering so only the designated admin (matched by a bastion-host attribute) receives the alert.

Adding EventBridge between the metric filter and the alarm (option A); CloudWatch alarms deliver directly to SNS, so EventBridge is redundant. Or relying on SSM Agent/Run Command (options B/D) to collect logs—the CloudWatch agent is the native log-collection path for this pattern.

Community Discussion (7 comments)

phmeeeee 👍 1 Selected: C
C - Retreiving the logs and send it to CloudWatch -> Create metrics filter -> Send alarm when over threshold -> SNS to designated system administrator. A - We are no need EventBridge to send the event based on cloudwatch metrics filter. B&D - is allow you to manage the EC2 instance like patch or automation and not for collect the log or log pasring.
chang4li 👍 1 Selected: D
"must notify only the designated system administrator who is assigned to the specific bastion host."
Pmktechno 👍 1 Selected: A
Amazon CloudWatch agent can collect operating system logs, including login attempts. Amazon EventBridge can be used to create rules that trigger alarms based on specific patterns in the logs, such as failed login attempts. Amazon SNS can send notifications when the alarm threshold is exceeded. Using EC2 instance tags allows you to direct notifications to the appropriate SNS topics, ensuring that only the designated system administrator for the specific bastion host receives the alerts. This solution leverages native AWS services effectively and minimizes operational overhead by automating the detection and notification process.
IPLogic 👍 1 Selected: C
CloudWatch Agent and Logs: The Amazon CloudWatch agent is configured to collect operating system logs, making it an ideal choice for monitoring failed login attempts. CloudWatch Alarm and Metric Filter: Creating a CloudWatch alarm based on a metric filter for failed login attempts ensures that you can set up precise conditions, such as 5 failed attempts within a 5-minute period. SNS and Messaging Filters: Amazon SNS is used to send alerts when the threshold is exceeded. SNS messaging filters can be used to control who receives notifications, ensuring that only the designated system administrator for the specific bastion host is notified. Option A includes using EventBridge to configure the alarm, which is an additional layer that isn't necessary for this specific requirement.
723993f 👍 1 Selected: A
the difference between A and C is that A uses event bridge and tags that can be referenced to route the request to a different sns topic each time, while C uses a single sns and no eventbridge A is the answer because correct routing is an important aspect in the requirements
k23319 👍 1 Selected: C
No need for Eventbridge, use cloudwatch alarms
koo_kai 👍 1 Selected: C
Use metrics filter

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The CloudWatch agent forwards the bastion's OS logs to CloudWatch Logs. A metric filter tallies failed login attempts and a CloudWatch alarm fires when 5 occur in 5 minutes, notifying an SNS topic. SNS message filtering scopes delivery to the subscriber associated with that specific bastion host, meeting the designated-admin requirement natively and simply.

Why the Other Options Are Wrong

A inserts EventBridge between the metric filter and the alarm; CloudWatch alarms already notify SNS directly, so EventBridge adds no value. B and D use the SSM Agent and Run Command document to configure logging, which is a heavier path than the CloudWatch agent for log collection, and the decisive per-host routing is better done with SNS filtering than instance tags. C is the streamlined native solution.

Community Comment Notes

Community favored C (57 votes). Commenters noted no EventBridge is needed—metric filter plus CloudWatch alarm to SNS suffices, and SNS message filtering controls recipient. A minority picked A for tag-based routing, but C's SNS filtering is simpler and meets the per-host requirement.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide