SCS-C02 Threat Detection and Incident Response Practice Question
A company uses a hybrid architecture with on-premises servers and AWS. The company uses AWS Site-to-Site VPN to connect to a VPC. The security team suspects that a VPN tunnel has been compromised and an attacker is intercepting traffic. The team needs to verify the integrity of the VPN connection. What is the MOST effective way to detect if traffic is being intercepted?
⚠ Common exam trap
Test-takers frequently confuse configuration compliance (AWS Config) or traffic analysis (VPC Flow Logs) with active tunnel integrity verification, overlooking that CloudWatch metrics directly monitor the VPN tunnel's operational state and performance, which is the most reliable indicator of compromise without requiring decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Monitor Amazon CloudWatch metrics for the VPN tunnel, such as tunnel state and data throughput.
Monitoring Amazon CloudWatch metrics for the VPN tunnel, specifically the 'TunnelState' metric, directly indicates whether the tunnel is up or down. A compromised tunnel that is intercepting traffic would likely cause the tunnel to flap or drop unexpectedly, which CloudWatch can alert on. Additionally, abnormal data throughput patterns (e.g., sudden spikes or drops) can signal interception or rerouting of traffic, making this the most effective way to detect integrity issues without relying on traffic content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Monitor Amazon CloudWatch metrics for the VPN tunnel, such as tunnel state and data throughput.
Why this is correct
Amazon CloudWatch publishes VPN tunnel metrics natively, including TunnelState (UP/DOWN) and DataTransferred. A sudden, unexplained tunnel flap, prolonged DOWN state, or throughput spike during an idle period can signal a renegotiation attack, a man-in-the-middle redirecting traffic to an unauthorized peer, or a compromised customer gateway. Because these metrics are captured from the AWS side of the IPsec tunnel and are continuously recorded, they can be compared against historical baselines to detect abnormal behavior that would indicate interception or tampering.
- ✗
Use AWS Config to check VPN configuration compliance.
Why it's wrong here
AWS Config is a configuration auditing service that evaluates your VPN connection's settings—such as whether static routes are configured correctly, whether encryption algorithms meet policy, or whether redundant tunnels are in place—against rules you define. However, it only examines the desired state of the resource definitions and does not inspect the actual traffic flowing through the tunnel. An intercepted VPN tunnel, where an attacker is actively capturing or modifying encrypted packets, can still be fully compliant with all your Config rules because the configuration remains unchanged. Therefore, Config cannot detect active interception or data-plane anomalies.
- ✗
Use a third-party network monitoring tool to perform deep packet inspection.
Why it's wrong here
While a third-party deep packet inspection (DPI) tool can analyze packet payloads for malware or protocol anomalies, IPsec VPN traffic is encrypted end-to-end, so the tool would need to terminate the tunnel, decrypt the traffic, or be positioned inline on both ends to see plaintext. This approach is not only operationally heavy and expensive but also introduces a new point of failure and potential attack surface, making it impractical for routine monitoring of a hybrid connection. Additionally, DPI focuses on content, not on whether the tunnel itself has been hijacked or rerouted; the encrypted outer IPsec headers may not reveal interception to a passive observer. Thus, DPI is not a native, pragmatic, or reliable method for detecting tunnel compromise.
- ✗
Enable VPC Flow Logs and analyze traffic patterns for unusual destinations.
Why it's wrong here
VPC Flow Logs capture metadata about IP flows within a VPC, such as source/destination IP, port, protocol, and bytes transferred, but they record traffic only after it has been decrypted by the AWS VPN endpoint or traffic that originates inside the VPC. They do not log the outer IPsec encapsulated packets traversing the on-premises-to-AWS tunnel segment, so a man-in-the-middle intercepting the tunnel before it reaches the endpoint would be entirely invisible to Flow Logs. While unusual destination patterns could indicate a compromised workload exfiltrating data, they would not reflect interception or tampering of the VPN link itself. Since Flow Logs do not provide visibility into the encrypted tunnel path, they are unsuitable for detecting this specific threat.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.