SCS-C02 Threat Detection and Incident Response Practice Question
A company uses Amazon RDS for MySQL with automated backups enabled. The security team suspects that a database administrator (DBA) with full RDS access has exfiltrated data by creating a snapshot of the database and sharing it with an external AWS account. The team wants to detect such exfiltration in the future. Which step should the team take to detect and alert on snapshot sharing?
⚠ Common exam trap
Test-takers frequently confuse AWS Config (which is configuration-aware but not real-time) with EventBridge (which is event-driven and real-time), or they mistakenly think GuardDuty RDS Protection covers all RDS-related threats, including data exfiltration via snapshot sharing, when it actually focuses on database-level threats like brute-force attacks or anomalous queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon EventBridge rule that triggers on the `ModifyDBSnapshotAttribute` API call and sends an alert via Amazon SNS.
The `ModifyDBSnapshotAttribute` API call is the specific action used to share an RDS snapshot with an external AWS account. By creating an Amazon EventBridge rule that triggers on this API call, the team can immediately send an alert via Amazon SNS, enabling real-time detection and response to unauthorized snapshot sharing. This approach is automated, event-driven, and directly targets the exfiltration vector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config to detect changes to RDS snapshot attributes.
Why it's wrong here
AWS Config can record changes to RDS snapshot attributes and run managed rules like rds-snapshots-public-prohibited, but it evaluates configuration compliance on a periodic or change-triggered basis, not as an instantaneous response to the ModifyDBSnapshotAttribute API call. A Config rule that flags a public snapshot would still require you to build a custom remediation or notification workflow, and the evaluation delay makes it unsuitable for a security alerting requirement. This option does not provide the direct, near-real-time event-driven alerting that the scenario asks for.
- ✗
Enable Amazon GuardDuty with RDS Protection.
Why it's wrong here
Amazon GuardDuty RDS Protection is designed to detect suspicious database logins, such as brute-force attacks or activity from compromised credentials, by analyzing authentication events from Aurora and RDS instances. It has no visibility into resource-level administrative operations like modifying a DB snapshot's sharing attributes, so it would never see the action that needs to be monitored. Turning on GuardDuty would not generate an alert when someone changes snapshot permissions.
- ✓
Create an Amazon EventBridge rule that triggers on the `ModifyDBSnapshotAttribute` API call and sends an alert via Amazon SNS.
Why this is correct
Amazon EventBridge can receive AWS API events from CloudTrail and match a custom event pattern for the ModifyDBSnapshotAttribute API call from the rds source, then route that event to an SNS topic for immediate alerting. This gives you a near-real-time, automated response based on the exact administrative action, with no need to poll or manually review logs. Because the rule uses an event pattern keyed on the API name, it fires precisely when the snapshot attribute is modified and can be extended to trigger Lambda remediations.
- ✗
Enable AWS CloudTrail and review logs manually.
Why it's wrong here
AWS CloudTrail does capture every ModifyDBSnapshotAttribute API call as an event in the account, so the audit record is definitely there, but expecting staff to periodically review the logs does not satisfy a security monitoring requirement. In a production account with high API volume and many snapshots, manual inspection is slow, error-prone, and unlikely to produce a timely alert. The task requires automated detection and alerting, so this option lacks the necessary event-driven behavior.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.