SCS-C02 Threat Detection and Incident Response Practice Question
A company has a security requirement to capture all DNS queries made by EC2 instances for threat analysis. Which AWS service can provide this capability with minimal configuration?
⚠ Common exam trap
A common mix-up: candidates confuse VPC Flow Logs (which capture network traffic metadata) with DNS query logging, not realizing that DNS queries are application-layer (Layer 7) and require a DNS-specific logging mechanism like Route 53 Resolver DNS Firewall's query logging feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Route 53 Resolver DNS Firewall
Amazon Route 53 Resolver DNS Firewall can capture and log all DNS queries made by EC2 instances by enabling DNS query logging to Amazon S3 or CloudWatch Logs. This requires minimal configuration because it integrates directly with the VPC's DNS resolver, automatically capturing outbound DNS traffic without needing agents or changes to instance configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs record IP traffic metadata at the VPC network interface level, such as source and destination IP addresses, ports, protocol, and packet/byte counts. Although traffic destined for a DNS resolver on UDP/TCP port 53 appears in the logs, Flow Logs do not decode or log the DNS payload itself, so the queried domain names, query types, and response codes remain invisible. Thus, they cannot capture all DNS queries content, only the existence of DNS-related connections.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that continuously scans EC2 instances, container images, and Lambda functions for software vulnerabilities, unintended network exposure, and deviations from security best practices. It operates by deploying an agent or leveraging AWS Systems Manager to gather telemetry about the system state, and it has no capability to observe, filter, or log DNS traffic. Its purpose is identifying security issues, not recording the content or metadata of DNS queries, so it is entirely irrelevant to capturing all DNS queries.
- ✓
Amazon Route 53 Resolver DNS Firewall
Why this is correct
Amazon Route 53 Resolver DNS Firewall enables you to filter and log DNS queries that are made through Amazon Provided DNS within a VPC. By associating DNS Firewall rule groups with a VPC and enabling Route 53 Resolver query logging, you capture detailed DNS query metadata, including the queried domain name, query type, response code, and the source IP of the requester. This makes it a direct fit for the security requirement to capture all DNS queries, because it both monitors and optionally blocks DNS traffic at the resolver level.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity across AWS services, capturing events such as who made a call, from which source IP, when, and what action was requested via the AWS API. DNS queries are network-layer requests that occur between clients and the DNS resolver; they are not AWS API calls, and CloudTrail has no data source for the content or metadata of those DNS lookups. Even with CloudTrail data events, the scope is limited to supported AWS operations (e.g., S3 object-level activities), never general DNS query traffic, so it cannot fulfill the requirement.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.