Courseiva
Incident and Event Response →mediumMultiple Choice

DOP-C02 Incident and Event Response Practice Question

An application running on Amazon EC2 instances in an Auto Scaling group is experiencing intermittent connectivity issues. The DevOps team suspects a security group configuration problem. Which approach should the team use to analyze security group traffic and identify denied requests?

⚠ Common exam trap

The trap is confusing 'audit who changed the rules' (CloudTrail/Config) with 'see which packets were denied' (Flow Logs) — the question asks for traffic analysis, not configuration history.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable VPC Flow Logs and query Amazon Athena

VPC Flow Logs capture IP traffic metadata (source, destination, port, protocol, action) for ENIs, subnets, or VPCs, and publishing them to CloudWatch Logs or S3 lets you query with Amazon Athena to identify REJECT entries caused by security group or NACL rules. This is the standard AWS approach for diagnosing denied traffic at the network layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Config to review security group rules

    Why it's wrong here

    AWS Config evaluates and records security group configuration against managed rules, such as flagging overly permissive ingress CIDRs, but it never sees actual IP traffic traversing the VPC. Its findings are configuration-level compliance snapshots, not flow-level records of accepted or denied connections. Therefore, it cannot reveal which specific sources were rejected or why a connection failed.

  • ✗

    Check AWS CloudTrail for security group modification events

    Why it's wrong here

    AWS CloudTrail captures control-plane API activity, including calls like AuthorizeSecurityGroupIngress or RevokeSecurityGroupIngress, so it can prove a rule was added or removed and by whom. However, denied connection attempts occur on the data plane and are not API calls, so CloudTrail produces no log entry for each blocked packet or connection. It cannot supply source IPs, ports, or the volume of REJECT actions needed to diagnose denied traffic.

  • ✗

    Enable AWS Security Hub and review the security findings

    Why it's wrong here

    AWS Security Hub aggregates findings from services such as GuardDuty, Macie, and Inspector, and it can highlight misconfigurations or threats. But its findings are curated, event-driven, and often based on sampled or detected activity, not an exhaustive record of every network connection attempted through a security group. It may mention suspicious traffic, but it does not provide a queryable log of all denied connections with source/destination metadata for forensic analysis.

  • ✓

    Enable VPC Flow Logs and query Amazon Athena

    Why this is correct

    VPC Flow Logs capture IP traffic metadata for ENIs in the VPC, recording fields like source address, destination address, port, protocol, and the action — ACCEPT or REJECT — for each connection. By publishing flow logs to Amazon S3 and using Amazon Athena with its SerDe, you can run SQL queries to filter on action = 'REJECT' and aggregate the denied connection attempts by source IP, port, or time. This directly reveals which connections are being blocked, making it the correct way to investigate denied traffic.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.