Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company is using AWS Config to track resource changes. They want to receive notifications when a security group is modified to allow inbound traffic from 0.0.0.0/0. What is the most efficient way to achieve this?

⚠ Common exam trap

Watch out — candidates often confuse CloudTrail's ability to log API calls (Option D) with the ability to evaluate the resulting resource state; CloudTrail only records the action, not the rule's content, so you would need additional logic to determine if the inbound rule actually allows 0.0.0.0/0.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom AWS Config rule with an AWS Lambda function that checks for public inbound traffic.

AWS Config custom rules allow you to define a Lambda function that evaluates security group configurations against your compliance requirements. By writing a rule that checks for inbound rules with '0.0.0.0/0' on ports like SSH (22) or RDP (3389), you can trigger notifications via Amazon SNS when non-compliant changes occur. This is the most efficient approach as it directly monitors the desired condition without relying on external services or manual log analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use IAM Access Analyzer to detect publicly accessible security groups.

    Why it's wrong here

    IAM Access Analyzer is designed to examine identity-based and resource-based policies for cross-account or public access, such as S3 bucket policies or IAM role trust policies. It does not inspect VPC security group ingress or egress rules, which are managed by the EC2/VPC network layer rather than by IAM policies. Therefore, it cannot identify a security group with an inbound rule for 0.0.0.0/0.

  • ✗

    Enable Amazon GuardDuty and use its findings for security group changes.

    Why it's wrong here

    GuardDuty analyzes telemetry from VPC Flow Logs, DNS query logs, and CloudTrail management events to identify threats like brute-force attacks or crypto mining, but it does not monitor for configuration drift or security group rule changes. Its findings pertain to malicious activity, not to the presence of overly permissive inbound rules. As a result, it will not produce a finding when a security group is changed to allow public SSH access.

  • ✓

    Create a custom AWS Config rule with an AWS Lambda function that checks for public inbound traffic.

    Why this is correct

    A custom AWS Config rule powered by a Lambda function can evaluate security groups on every configuration change. The Lambda function uses the AWS Config API to receive the resource's details, parses the IpPermissions, and checks for any rule with CidrIp 0.0.0.0/0 or ::/0. If public inbound traffic is found, the function returns NON_COMPLIANT, enabling continuous, automated compliance monitoring and remediation. This is exactly the kind of custom, resource-specific logic that Config supports.

  • ✗

    Create a CloudTrail trail and filter on AuthorizeSecurityGroupIngress events.

    Why it's wrong here

    A CloudTrail trail can record AuthorizeSecurityGroupIngress API calls, but that only gives you a raw audit log after the fact. To detect public access, you would need to manually parse each event's request parameters and correlate them with existing rules, and even then you might miss RevokeSecurityGroupIngress or direct VPC changes made via the console. CloudTrail is a reactive auditing tool, whereas AWS Config proactively maintains a continuous compliance state and evaluates the resulting security group configuration, not just the API call.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.