Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses Amazon RDS for its database. The security team needs to detect when a database instance is started or stopped outside of maintenance windows. Which AWS service should the team use to monitor these API calls?

⚠ Common exam trap

Many candidates confuse CloudWatch's ability to create alarms on CloudTrail events with CloudWatch itself being the service that records API calls, but CloudWatch only processes logs delivered by CloudTrail and cannot natively capture API activity without CloudTrail as the source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records API activity in your AWS account, including StartDBInstance and StopDBInstance calls from the RDS service. By monitoring CloudTrail logs, the security team can detect when a database instance is started or stopped outside of maintenance windows, as each API call is logged with a timestamp and user identity. CloudTrail is specifically designed for auditing API calls, making it the appropriate tool for this use case.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch is a monitoring service that collects and tracks metrics, logs, and alarms for AWS resources. It does not natively record API-level events such as StartDBInstance or StopDBInstance; those actions are captured by CloudTrail, not CloudWatch. You could create an EventBridge rule to react to CloudTrail events and trigger a CloudWatch alarm, but CloudWatch itself cannot provide the audit trail or notify you directly about the API call. Therefore, CloudWatch is not the correct service for monitoring who started or stopped the RDS instance.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes telemetry from sources like VPC Flow Logs, DNS logs, and CloudTrail management events to identify malicious behavior. It is not designed to be a comprehensive audit log or a targeted monitor for specific API actions such as RDS start/stop events. While GuardDuty might raise an alert if the stop/start pattern is deemed anomalous, it does not capture or retain the full history of every RDS API call for operational auditing or compliance. Hence, GuardDuty is not the appropriate tool for this requirement.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the correct service because it records all management events, including every RDS API call such as StartDBInstance and StopDBInstance. Each CloudTrail event contains the identity of the caller, the time of the action, the source IP address, and request parameters, enabling a complete audit trail. You can also configure CloudTrail to deliver logs to Amazon S3 and set up EventBridge rules to trigger real-time alerts whenever a specific RDS API action occurs. This makes CloudTrail the definitive source for monitoring and alerting on RDS instance lifecycle changes.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records configuration changes to AWS resources, such as alterations to DB instance settings, security groups, or parameter groups. While starting or stopping an RDS instance changes its state (e.g., from 'available' to 'stopped'), AWS Config only reflects that the resource state changed; it does not capture the API call, the identity of the user, or the exact time of the action. Additionally, AWS Config does not provide event-driven notifications for these state transitions out of the box. Therefore, it cannot tell you who initiated the stop/start action, which makes it unsuitable for this monitoring requirement.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.