SCS-C02 Security Logging and Monitoring Practice Question
A company needs to monitor for unauthorized changes to security group rules. Which TWO AWS services can be used together to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
Options B and E are correct. AWS Config can track changes to security group rules, and Amazon CloudWatch Events can trigger a notification when a Config rule detects a change. Option A (GuardDuty) is for threat detection. Option C (Inspector) is for vulnerability scanning. Option D (CloudTrail) logs API calls but is not the best for direct rule-level monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that uses machine learning and integrated threat intelligence to identify suspicious activity such as cryptocurrency mining, compromised credentials, or unusual network traffic. It does not maintain a configuration history or evaluate security group rules against a desired baseline, so it cannot tell you whether a specific rule change was unauthorized. While GuardDuty might alert on traffic patterns resulting from a poor rule, it is not designed to monitor the rules themselves.
- ✓
AWS Config
Why this is correct
AWS Config is purpose-built for recording configuration item changes and evaluating them against desired policies. When a security group rule is added, removed, or modified, Config generates a configuration item and can trigger an AWS Config rule (e.g., a managed rule or a custom Lambda rule) that determines whether the new state is compliant with the organization's requirements. It provides a timeline of every change, so you can identify exactly what was unauthorized and when it happened, and it can automatically remediate noncompliant rules via Systems Manager Automation. This is why AWS Config is the core service for this monitoring need.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is an automated vulnerability management service that continually scans workloads for software vulnerabilities and unintended network exposure, not a configuration change tracker. It does not record or evaluate changes to security group rules, nor does it maintain a configuration history. Therefore, while it may flag security groups that are overly permissive, it cannot detect when a specific rule was added or removed over time.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API calls made in your account, including the AuthorizeSecurityGroupIngress and RevokeSecurityGroupIngress calls, but it stores them as raw event logs without a notion of the final configuration state or compliance rules. You would need to build custom log parsing and alerting logic to detect an unauthorized change, and even then you wouldn't get an ongoing evaluation of how the current rules differ from your desired baseline. CloudTrail is an essential audit trail, but it is not a monitoring service that proactively evaluates security group rule compliance.
- ✓
Amazon CloudWatch Events
Why this is correct
Amazon CloudWatch Events (now Amazon EventBridge) is the event-driven component that makes the monitoring solution reactive. You can create a rule that listens for the security group change events emitted by AWS Config and then invoke an AWS Lambda function or send an Amazon SNS notification to alert your security team immediately. By itself it does not detect or record changes; instead, it delivers and routes the change notifications that Config generates, making it a correct choice as part of a complete event-driven monitoring pipeline.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.