SCS-C02 Security Logging and Monitoring Practice Question
A company has a multi-account AWS Organization with 50 accounts. The security team wants to monitor for unauthorized IAM role assumption across all accounts. They have enabled AWS CloudTrail in all accounts and are delivering logs to a central S3 bucket in the security account. They also have Amazon GuardDuty enabled in all accounts. The security team wants a centralized dashboard to visualize cross-account role assumption events. They have limited budget and want to use existing services. What should they do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Amazon Athena to query CloudTrail logs in S3 and visualize with Amazon QuickSight.
Amazon Athena can query CloudTrail logs stored in S3 using standard SQL, and Amazon QuickSight can create visualizations from Athena query results. This leverages existing services without additional cost for Amazon QuickSight (pay-per-session pricing) and minimal cost for Athena (based on data scanned). Option B is incorrect because AWS Config aggregator provides a view of resource configuration across accounts, not API call analysis. Option C is incorrect because CloudWatch Logs Insights cannot directly query logs stored in S3; it requires logs to be in CloudWatch Logs. Option D is incorrect because Amazon Elasticsearch Service incurs additional costs and complexity, which the company wants to avoid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Amazon Athena to query CloudTrail logs in S3 and visualize with Amazon QuickSight.
Why this is correct
Amazon Athena can query CloudTrail logs directly in Amazon S3 using standard SQL, without requiring any ingestion or ETL step. When all accounts in the organization deliver CloudTrail logs to a centralized S3 bucket, Athena can run cross-account queries over the entire set of log files. Amazon QuickSight connects to Athena to build interactive dashboards from those results, and the serverless pay-per-query pricing makes this a cost-effective analysis solution.
- ✗
Use AWS Config aggregator to view cross-account IAM role creation.
Why it's wrong here
AWS Config records resource configuration changes and compliance states, not the IAM role assumption events or API actions that are captured in CloudTrail. An aggregator can consolidate Config findings from all 50 accounts, but it would only show the resulting state of a role, not who assumed it, when, or from which account. Since the audit requires activity logging, Config does not provide the necessary event-level detail.
- ✗
Use Amazon CloudWatch Logs Insights to query logs from the central S3 bucket.
Why it's wrong here
CloudWatch Logs Insights only runs queries against log groups in CloudWatch Logs, not against objects in an S3 bucket. While CloudTrail can optionally deliver logs to CloudWatch Logs, simply pointing Logs Insights at the central S3 bucket is not supported. Without a CloudTrail trail configured to stream to CloudWatch Logs, the logs never reach CloudWatch and cannot be queried this way.
- ✗
Use Amazon Elasticsearch Service to index CloudTrail logs from S3 and visualize with Kibana.
Why it's wrong here
Amazon Elasticsearch Service (now OpenSearch Service) can ingest CloudTrail logs from S3, but doing so requires building and maintaining a pipeline (e.g., Lambda or Logstash) and running a cluster 24/7, which generates significant recurring cost. The question likely favors a serverless, low-cost solution; OpenSearch Service also requires you to manage index mappings and snapshots. Athena avoids that operational burden and cost because it queries the S3 logs in place without indexing.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.