Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company has a multi-account AWS environment using AWS Organizations. The security team has enabled AWS CloudTrail with an organization trail that delivers logs to a centralized S3 bucket in the management account. They have also enabled Amazon GuardDuty in all accounts. Recently, they noticed that some EC2 instances in a member account are exhibiting unusual network behavior, such as outbound traffic to known malicious IP addresses. The security engineer needs to quickly determine the source of the traffic and identify which EC2 instances are affected. The engineer has access to the management account and the member account. Which course of action should the engineer take to most efficiently investigate this incident?

⚠ Common exam trap

SCS-C02 often tests whether candidates confuse vulnerability scanning (Inspector), configuration tracking (Config), and manual log querying (Athena) with the purpose-built threat investigation service (Detective) that automatically correlates GuardDuty findings with network and API activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon Detective to investigate the GuardDuty findings and analyze VPC Flow Logs to identify the affected instances.

Amazon Detective is purpose-built to investigate and analyze GuardDuty findings, automatically ingesting VPC Flow Logs, CloudTrail, and GuardDuty data to build a behavior graph that pinpoints affected EC2 instances and traffic sources. It correlates the malicious-IP finding with the specific instance and network path in a few clicks, which is exactly the 'quickly determine source and affected instances' requirement. This is the most efficient investigative path because Detective already has the data pre-processed and linked to the finding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Config to review the configuration changes of the EC2 instances and identify any anomalies.

    Why it's wrong here

    AWS Config is a resource compliance and configuration history service, not a traffic inspection tool. Although it can record changes to EC2 instance attributes or security group rules, it cannot ingest or analyze VPC Flow Logs, packet captures, or network traffic patterns. Detecting anomalies in configuration changes is not the same as investigating GuardDuty findings, which require correlating network activity and identifying affected instances through traffic-level data.

  • ✓

    Use Amazon Detective to investigate the GuardDuty findings and analyze VPC Flow Logs to identify the affected instances.

    Why this is correct

    Amazon Detective is purpose-built for security investigations and natively integrates with GuardDuty findings. It automatically aggregates and correlates data from VPC Flow Logs, CloudTrail, and other sources, presenting a visual graph of resources, IP addresses, and behaviors. By launching an investigation from a GuardDuty finding, you can quickly scope the affected EC2 instances and analyze the associated flow log data without manual querying. This gives the most efficient and complete investigation pathway.

  • ✗

    Use Amazon Inspector to scan the EC2 instances for vulnerabilities and correlate with network traffic.

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that scans EC2 instances for software vulnerabilities, unintended network exposure, and deviations from security best practices. It does not ingest or analyze VPC Flow Logs, nor does it correlate network traffic with active GuardDuty findings. While a vulnerability scan may reveal weaknesses that could have been exploited, it cannot identify the specific source IPs or affected instances from an ongoing attack, which is the core requirement here.

  • ✗

    Query the VPC Flow Logs stored in the centralized S3 bucket using Amazon Athena to find the source IP and affected instances.

    Why it's wrong here

    Querying VPC Flow Logs with Amazon Athena is technically possible and can indeed reveal source IPs and affected instances by filtering the logs. However, this approach requires manually building and tuning SQL queries, understanding the flow log schema, and knowing which S3 objects to scan. It also lacks the automatic correlation with GuardDuty findings that Amazon Detective provides, making it slower and more error-prone. Detective offers a pre-built, integrated visualization of the same data, making it a more efficient and accurate choice.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.