Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company runs a multi-tier web application on AWS. The application consists of an Application Load Balancer (ALB), a fleet of EC2 instances in an Auto Scaling group, and an RDS MySQL database. The security team wants to monitor for SQL injection attempts. They have enabled AWS WAF on the ALB and are logging all requests. The security engineer needs to analyze the WAF logs to identify if any SQL injection attacks have been attempted. The logs are stored in an S3 bucket. The engineer needs to query the logs for patterns like 'SELECT * FROM' or 'DROP TABLE' in the URI. Which service should the engineer use to perform this analysis?

⚠ Common exam trap

SCS-C02 often tests the distinction between services that query S3 data (Athena) versus services that process streams (Kinesis) or visualize data (QuickSight), so candidates must match the tool to the data location and query need.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Athena

Amazon Athena is a serverless interactive query service that can query data directly from S3 using standard SQL, making it ideal for analyzing WAF logs stored in S3. The engineer can run SQL queries with LIKE clauses to search for patterns like 'SELECT * FROM' or 'DROP TABLE' in the URI field. Athena integrates natively with S3 and requires no infrastructure management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Kinesis Data Analytics

    Why it's wrong here

    Amazon Kinesis Data Analytics is built for continuous, real-time processing of streaming data from sources such as Kinesis Data Streams or Kinesis Data Firehose, using SQL or Apache Flink. Static WAF log files sitting in an S3 bucket are not a live stream, and Kinesis Data Analytics has no ability to issue a one-off SQL query directly against S3 objects. Using it here would require replaying logs into a stream first, which is unnecessary and delays the analysis.

  • ✗

    Amazon QuickSight

    Why it's wrong here

    Amazon QuickSight is a cloud-scale business intelligence service for creating dashboards and visualizations from data sources it is configured to connect to, such as Athena, Redshift, or RDS. It does not contain a query engine that can scan raw AWS WAF log files directly in S3, nor does it understand the arbitrary JSON schema of WAF logs without a query layer. To use QuickSight, you would first need Athena to query the S3 logs and then connect QuickSight to that Athena result set.

  • ✗

    CloudWatch Logs Insights

    Why it's wrong here

    CloudWatch Logs Insights is a query and analysis engine that operates only on log data already ingested into Amazon CloudWatch Logs as log groups and log streams. If AWS WAF logs are being delivered to an S3 bucket, those objects are not in CloudWatch Logs, so Insights cannot read or query them. Although WAF can also send logs to CloudWatch Logs, the question's scenario specifically places them in S3.

  • ✓

    Amazon Athena

    Why this is correct

    Amazon Athena is a serverless, interactive query service that runs standard SQL directly against structured, semistructured, or unstructured data stored in Amazon S3. For AWS WAF logs, which are JSON objects, you can define a table in the AWS Glue Data Catalog and query them with Athena using partitions by date, with no servers or clusters to provision. It is the natural fit for analyzing WAF log files in S3.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.