SCS-C02 Security Logging and Monitoring Practice Question
A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to analyze web request logs to identify potential SQL injection attacks. Which AWS service should be used to collect and analyze the ALB access logs?
⚠ Common exam trap
Many exam-takers confuse AWS WAF's real-time blocking capability with the need for post-incident log analysis, leading them to choose WAF instead of recognizing that Athena is the appropriate service for querying stored ALB access logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Athena
Amazon Athena is the correct service because it allows you to query ALB access logs stored in Amazon S3 directly using standard SQL, without needing to load or transform the data. This makes it ideal for ad-hoc analysis of web request logs to identify patterns like SQL injection attempts, as you can run complex queries against the raw log data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs record network-level metadata such as source/destination IPs, ports, protocol, and packet counts, but they do not capture HTTP payloads, URLs, or query strings. Consequently, SQL injection patterns embedded in the request body or parameters are completely absent from Flow Logs. They can confirm that traffic occurred, but not what the application-layer request contained, so they cannot identify specific attack strings.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a web application firewall that inspects incoming HTTP(S) requests in real time and can block or allow them based on managed rules like SQL injection match conditions. However, it does not provide any capability to query or analyze historical ALB access logs stored in S3. WAF is a prevention control, not an investigative tool; after the fact you need a separate query engine to look for patterns in existing log data.
- ✗
Amazon CloudWatch Logs Insights
Why it's wrong here
CloudWatch Logs Insights is a query service designed for log data that already resides in CloudWatch Logs, not for files in S3. Since ALB access logs are typically delivered to an S3 bucket by default, Insights would have no data source to search unless the logs were explicitly streamed to CloudWatch. Even then, its purpose is simple structured queries over CloudWatch Logs, and it lacks the SQL flexibility and cost benefits of Athena for querying S3-resident data.
- ✓
Amazon Athena
Why this is correct
Amazon Athena is the correct choice because it allows you to query ALB access logs directly in S3 using standard SQL without needing to load or transform the data. You can create an external table over the gzipped log files, then run SQL queries that look for SQL injection indicators such as 'OR 1=1', suspicious quotes, or UNION SELECT statements in the request and URL fields. This serverless, on-demand query engine is ideal for post-incident forensic analysis of historical access logs stored in S3.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.