SCS-C02 Security Logging and Monitoring Practice Question
A company uses AWS Organizations with multiple accounts. The security team wants to centrally monitor and analyze all CloudTrail logs from all accounts. The logs must be stored in a centralized S3 bucket with encryption and access logging enabled. Additionally, the team needs to detect anomalous API activity across accounts using machine learning. Which combination of services meets these requirements?
⚠ Common exam trap
Candidates often confuse Amazon Detective as a proactive detection service when it is actually a reactive investigation tool that relies on findings from GuardDuty, not a standalone ML-based anomaly detector for API activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption and S3 server access logs; Amazon GuardDuty enabled in all accounts.
It combines AWS CloudTrail for centralized log delivery to an S3 bucket with default encryption and server access logs, and Amazon GuardDuty, which uses machine learning to detect anomalous API activity across accounts. GuardDuty analyzes CloudTrail management events, VPC flow logs, and DNS logs to identify suspicious behavior, meeting the requirement for ML-based anomaly detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; AWS Config to monitor API activity; S3 server access logs enabled.
Why it's wrong here
AWS Config is a compliance and governance service that records resource configuration changes and evaluates them against rules; it does not capture or analyze API activity. CloudTrail does record API calls, but without a detection engine like GuardDuty, no service is examining those logs for unusual patterns such as impossible travel or credential misuse. S3 server access logs only provide raw request data and do not have anomaly detection logic. Thus, this combination provides logging but fails to deliver the required ML-based API anomaly detection.
- ✗
AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; Amazon Macie to detect anomalous API activity; S3 server access logs enabled.
Why it's wrong here
Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data such as PII or financial information stored in S3. Its focus is data visibility and data security posture, not on analyzing CloudTrail API events for anomalous behavior. While Macie can alert on public bucket policy changes, it does not correlate API activity across accounts to identify suspicious patterns like API calls from a compromised role. Without GuardDuty, this solution has no dedicated anomaly detection for API activity.
- ✗
AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; Amazon Detective to analyze API activity; S3 server access logs enabled.
Why it's wrong here
Amazon Detective is an investigation service that visualizes and analyzes security findings by building a graph of resources, users, and network traffic. It does not itself perform real-time anomaly detection; it relies on findings generated by GuardDuty (or other services) as input. With no GuardDuty enabled, Detective would have no security findings to analyze, leaving it unable to identify anomalous API activity. Thus, Detective is a complement, not a replacement, for GuardDuty's ML-based detection.
- ✓
AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption and S3 server access logs; Amazon GuardDuty enabled in all accounts.
Why this is correct
CloudTrail captures every API call across all accounts and delivers a tamper-evident log to the centralized S3 bucket, with default encryption protecting it at rest. Amazon GuardDuty, enabled in all accounts, continuously analyzes CloudTrail events along with VPC Flow Logs and DNS logs using machine learning and threat intelligence to detect anomalies such as compromised credentials or unusual API sequences. S3 server access logs provide object-level request logging for the centralized bucket itself. Together these components deliver both comprehensive API activity logging and proactive ML-based anomaly detection across the organization.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.