Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all API calls in the organization are logged and retained for at least one year. Which AWS services or features should be used to meet these requirements? (Choose TWO.)

⚠ Common exam trap

A common mix-up: candidates confuse AWS Config (which records resource configuration changes) with CloudTrail (which records API calls), leading them to select Config as a logging solution for API activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.

An Amazon S3 lifecycle policy can automatically transition CloudTrail log objects from S3 Standard to S3 Glacier after one year, meeting the retention requirement cost-effectively. Option E is correct because AWS CloudTrail with an organization trail logs all API calls across all accounts in the AWS Organization, ensuring comprehensive logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty with threat detection enabled.

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that consumes CloudTrail management events, VPC Flow Logs, and DNS logs to identify malicious behavior; it does not itself record or expose the raw API-call history needed for compliance audits. Enabling GuardDuty would give you findings and alerts, but it would not provide a queryable, timestamped record of every API action across your accounts. Therefore, it cannot satisfy a requirement to audit API activity.

  • ✗

    AWS Config with recording enabled for all resources.

    Why it's wrong here

    AWS Config records configuration state changes and resource relationships, with configuration history delivered to S3 and compliance evaluated through rules. Although it may capture a resource's changed configuration and sometimes last-change information, it does not log the individual API calls, user identities, or request parameters that produced those changes. Config is configuration governance, not an API activity or cloud-trail audit.

  • ✓

    Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.

    Why this is correct

    An S3 lifecycle policy can transition delivered log objects from frequently accessed storage classes to S3 Glacier after one year, preserving the logs for long-term audit needs while reducing cost. This is a correct component for the retention half of the requirement, provided that a delivery mechanism such as an organization CloudTrail trail first places the logs into the S3 bucket. It does not record any API activity by itself, so it is complementary to CloudTrail rather than a replacement.

  • ✗

    VPC Flow Logs for all VPCs.

    Why it's wrong here

    VPC Flow Logs capture metadata about network traffic at the elastic network interface level—source/destination IPs, ports, protocol, and packet/byte counts—but they contain no information about IAM users, roles, or API actions in AWS. They can help investigate network anomalies or exfiltration, yet they cannot serve as a record of who performed which API call. Thus, enabling VPC Flow Logs alone fails the API-auditing requirement.

  • ✓

    AWS CloudTrail with organization trail.

    Why this is correct

    An organization trail in AWS CloudTrail records management events—API calls made via the AWS Console, SDKs, CLI, and infrastructure-as-code tools—for all current and future accounts in the AWS Organization, delivering the logs to a centralized S3 bucket. It captures the identity, event time, source IP, user agent, and request/response details, making it the definitive service for cross-account API auditing. This is correct for the API-activity requirement and can be paired with lifecycle policies for long-term, low-cost retention.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.