SCS-C02 Threat Detection and Incident Response Practice Question
A company has a requirement to detect and respond to threats in near real-time by analyzing VPC Flow Logs. The logs are generated in a VPC and sent to CloudWatch Logs. What is the MOST efficient way to analyze these logs for suspicious patterns and trigger automated responses?
⚠ Common exam trap
Test-takers frequently choose batch-oriented solutions like Athena or S3 event notifications, overlooking the explicit 'near real-time' requirement in the question, which demands a streaming analytics approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Amazon Kinesis Data Analytics for real-time analysis and AWS Lambda for automated response
Amazon Kinesis Data Analytics can process streaming VPC Flow Logs from CloudWatch Logs in near real-time using SQL or Apache Flink, enabling immediate detection of suspicious patterns. AWS Lambda can then be triggered to automate incident response actions, such as updating security groups or isolating instances, making this the most efficient solution for near real-time threat detection and response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stream logs to Amazon Elasticsearch Service and use Kibana alerts
Why it's wrong here
Streaming logs to Amazon Elasticsearch Service (Amazon OpenSearch Service) and relying on Kibana alerts is not suitable for true real-time threat detection because ingestion is batch-oriented—for example, using Kinesis Firehose introduces a buffering window (default 1-5 minutes) and OpenSearch has an indexing refresh interval that delays document visibility. Additionally, Kibana alerting runs scheduled queries on already-indexed data, adding further latency. This means detection time is minutes behind the actual threat, which fails to meet a real-time response requirement.
- ✗
Use S3 event notifications to trigger Lambda functions on new log files
Why it's wrong here
Using S3 event notifications to trigger Lambda functions on new log files assumes logs are already delivered to S3, but most logging services (CloudTrail, VPC Flow Logs, ELB logs) deliver files only after a frequency interval—typically 5 minutes to several hours—so the activity is not captured as it happens. Even when an event fires, the full file must be written first, and Lambda invocation adds cold-start overhead (sometimes 1-3 seconds), making the total end-to-end detection latency far too high for real-time threat response. This approach is best suited for asynchronous, post-processing tasks, not immediate detection.
- ✗
Export logs to S3 and use Amazon Athena queries with scheduled rules
Why it's wrong here
Exporting logs to S3 and using Athena with scheduled rules is fundamentally a batch analysis model—Athena queries execute across objects in S3 and incur overhead for object discovery, file reading, and data scan; each query typically takes seconds to minutes, especially on large log datasets. Scheduled rules (e.g., via EventBridge Scheduler) run on a fixed cron-like interval, meaning threats can go undetected until the next schedule, and there is no event-driven trigger to initiate immediate action. Since Athena is pull-based and not streaming, it cannot detect anomalies as they occur, making it unsuitable for sub-minute detection and response.
- ✓
Use Amazon Kinesis Data Analytics for real-time analysis and AWS Lambda for automated response
Why this is correct
Amazon Kinesis Data Analytics continuously processes streaming logs using SQL or Apache Flink, allowing pattern matching, anomaly detection, and aggregation over sliding windows in near-real-time—latency can be under a few seconds. It can output its results to a Lambda function (via a Kinesis Data Analytics destination or an intermediate Kinesis Data Stream) which then executes an automated response (e.g., updating security groups, invoking AWS WAF, or sending alerts). This stream-processing architecture directly meets the 'detect and respond' requirement with minimal delay, unlike batch-based alternatives.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.