SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all API calls in the organization are logged and retained for at least one year. Which AWS services or features should be used to meet these requirements? (Choose TWO.)
⚠ Common exam trap
A common mix-up: candidates confuse AWS Config (which records resource configuration changes) with CloudTrail (which records API calls), leading them to select Config as a logging solution for API activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.
An Amazon S3 lifecycle policy can automatically transition CloudTrail log objects from S3 Standard to S3 Glacier after one year, meeting the retention requirement cost-effectively. Option E is correct because AWS CloudTrail with an organization trail logs all API calls across all accounts in the AWS Organization, ensuring comprehensive logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty with threat detection enabled.
Why it's wrong here
Amazon GuardDuty is a threat detection service that consumes CloudTrail management events, VPC Flow Logs, and DNS logs to identify malicious behavior; it does not itself record or expose the raw API-call history needed for compliance audits. Enabling GuardDuty would give you findings and alerts, but it would not provide a queryable, timestamped record of every API action across your accounts. Therefore, it cannot satisfy a requirement to audit API activity.
- ✗
AWS Config with recording enabled for all resources.
Why it's wrong here
AWS Config records configuration state changes and resource relationships, with configuration history delivered to S3 and compliance evaluated through rules. Although it may capture a resource's changed configuration and sometimes last-change information, it does not log the individual API calls, user identities, or request parameters that produced those changes. Config is configuration governance, not an API activity or cloud-trail audit.
- ✓
Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.
Why this is correct
An S3 lifecycle policy can transition delivered log objects from frequently accessed storage classes to S3 Glacier after one year, preserving the logs for long-term audit needs while reducing cost. This is a correct component for the retention half of the requirement, provided that a delivery mechanism such as an organization CloudTrail trail first places the logs into the S3 bucket. It does not record any API activity by itself, so it is complementary to CloudTrail rather than a replacement.
- ✗
VPC Flow Logs for all VPCs.
Why it's wrong here
VPC Flow Logs capture metadata about network traffic at the elastic network interface level—source/destination IPs, ports, protocol, and packet/byte counts—but they contain no information about IAM users, roles, or API actions in AWS. They can help investigate network anomalies or exfiltration, yet they cannot serve as a record of who performed which API call. Thus, enabling VPC Flow Logs alone fails the API-auditing requirement.
- ✓
AWS CloudTrail with organization trail.
Why this is correct
An organization trail in AWS CloudTrail records management events—API calls made via the AWS Console, SDKs, CLI, and infrastructure-as-code tools—for all current and future accounts in the AWS Organization, delivering the logs to a centralized S3 bucket. It captures the identity, event time, source IP, user agent, and request/response details, making it the definitive service for cross-account API auditing. This is correct for the API-activity requirement and can be paired with lifecycle policies for long-term, low-cost retention.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.