Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company has a security requirement to capture all DNS queries made by EC2 instances for threat analysis. Which AWS service can provide this capability with minimal configuration?

⚠ Common exam trap

A common mix-up: candidates confuse VPC Flow Logs (which capture network traffic metadata) with DNS query logging, not realizing that DNS queries are application-layer (Layer 7) and require a DNS-specific logging mechanism like Route 53 Resolver DNS Firewall's query logging feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Route 53 Resolver DNS Firewall

Amazon Route 53 Resolver DNS Firewall can capture and log all DNS queries made by EC2 instances by enabling DNS query logging to Amazon S3 or CloudWatch Logs. This requires minimal configuration because it integrates directly with the VPC's DNS resolver, automatically capturing outbound DNS traffic without needing agents or changes to instance configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs record IP traffic metadata at the VPC network interface level, such as source and destination IP addresses, ports, protocol, and packet/byte counts. Although traffic destined for a DNS resolver on UDP/TCP port 53 appears in the logs, Flow Logs do not decode or log the DNS payload itself, so the queried domain names, query types, and response codes remain invisible. Thus, they cannot capture all DNS queries content, only the existence of DNS-related connections.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that continuously scans EC2 instances, container images, and Lambda functions for software vulnerabilities, unintended network exposure, and deviations from security best practices. It operates by deploying an agent or leveraging AWS Systems Manager to gather telemetry about the system state, and it has no capability to observe, filter, or log DNS traffic. Its purpose is identifying security issues, not recording the content or metadata of DNS queries, so it is entirely irrelevant to capturing all DNS queries.

  • ✓

    Amazon Route 53 Resolver DNS Firewall

    Why this is correct

    Amazon Route 53 Resolver DNS Firewall enables you to filter and log DNS queries that are made through Amazon Provided DNS within a VPC. By associating DNS Firewall rule groups with a VPC and enabling Route 53 Resolver query logging, you capture detailed DNS query metadata, including the queried domain name, query type, response code, and the source IP of the requester. This makes it a direct fit for the security requirement to capture all DNS queries, because it both monitors and optionally blocks DNS traffic at the resolver level.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity across AWS services, capturing events such as who made a call, from which source IP, when, and what action was requested via the AWS API. DNS queries are network-layer requests that occur between clients and the DNS resolver; they are not AWS API calls, and CloudTrail has no data source for the content or metadata of those DNS lookups. Even with CloudTrail data events, the scope is limited to supported AWS operations (e.g., S3 object-level activities), never general DNS query traffic, so it cannot fulfill the requirement.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.