Answer: A
Option A is CORRECT. Log data can be collected from EC2 instances by installing & configuring a CloudWatch Log Agent on the EC2 server. These logs can then be delivered to CloudWatch log group streams, where they can be analyzed using Metric Filters. Actions like notifying an admin on the invalid login attempt can then be done by defining CloudWatch alarms on the associated Log metrics.
Option B is incorrect. CloudTrail tracks API requests made by users. Its logs will be more useful when operations on resources are performed like creating an EC2 instance or terminating an EC2 instance. Those logs can be integrated with CloudWatch for detecting abnormal operations on different AWS resources. The user login scenario is captured as logs on the EC2 instance & sent to CloudWatch by the Log Agent. When a user tries to SSH to an EC2 instance, the activity is not recorded in AWS CloudTrail as it is not an AWS API call.
Option C is incorrect. Although it is possible to run a log utility to report failed login attempts by the user, it defeats the advantages that a centralized Monitoring & Logging system offers. Also, by doing so, real-time monitoring will not happen due to the absence of streaming data resulting in delayed incident detection & resolution.
Option D is incorrect since the best way to track log data is to push it to a Log stream destination where it can be quickly monitored resulting in faster incident resolution.
Diagram:
References:
https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/WhatIsCloudWatchLogs.html
https://aws.amazon.com/cloudwatch/
https://aws.amazon.com/cloudtrail/
https://www.tests.com/aws-monitoring-and-auditing/