SCS-C03 Detection Practice Question
A company wants to detect when an IAM user executes a command from a suspicious IP address. Which tool can analyze historical CloudTrail data to establish a baseline of normal behavior and trigger alerts upon deviations?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty.
Amazon GuardDuty provides automated anomaly detection based on CloudTrail, VPC Flow Logs, and DNS logs. It uses machine learning to profile typical user behavior and detects deviations such as logins from unusual locations or IP addresses associated with known malicious actors. This is crucial for environments where manual rule creation is impossible due to the sheer volume of users, as it identifies threats without requiring static IP allow-lists.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CloudWatch Contributor Insights.
Why it's wrong here
Contributor Insights is excellent for identifying top talkers or performance bottlenecks in logs, but it is not a security anomaly detection engine. It does not have the pre-trained machine learning models necessary to identify malicious behavior or suspicious IP addresses automatically. It requires manual query construction to provide any meaningful security insights.
- ✓
Amazon GuardDuty.
Why this is correct
GuardDuty is the purpose-built threat detection service in AWS. It continuously analyzes data sources to detect anomalies like unusual IP activity or API calls from unauthorized locations. Its machine learning models are continuously updated with threat intelligence, making it highly effective at detecting modern credential abuse patterns that bypass traditional firewalls.
- ✗
AWS CloudTrail Insights.
Why it's wrong here
CloudTrail Insights detects anomalies in API call volumes, not the context of the user or the IP address origin. It is designed to flag unusual spikes or drops in API activity, not specifically for detecting malicious login attempts or anomalous geolocation patterns originating from specific external IP addresses.
- ✗
AWS Config.
Why it's wrong here
AWS Config is designed for resource state auditing and compliance. It monitors configuration changes, not user behavior or authentication patterns. It cannot determine if an IP address is 'suspicious' or if a user's login behavior has deviated from their baseline, as it does not perform behavioral analysis or threat intelligence correlation.
About these practice questions
This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.