Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company wants to detect and alert on SSH brute force attacks on EC2 instances. Which AWS service should be used?

⚠ Common exam trap

A common mix-up: candidates confuse Amazon Inspector (which scans for vulnerabilities) with GuardDuty (which detects active threats), or they assume CloudTrail alone can alert on brute force attacks without realizing it lacks built-in threat analysis and alerting capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, including SSH brute force attacks. It uses machine learning and integrated threat intelligence to analyze VPC Flow Logs, DNS logs, and CloudTrail events, and can generate findings for 'UnauthorizedAccess:EC2/SSHBruteForce' when repeated failed SSH login attempts are detected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and assesses those configurations against compliance rules, but it never inspects network traffic or authentication events. An SSH brute force attempt is an operational incident, not a configuration item, so Config cannot observe repeated failed login attempts or trigger security findings on the attack itself. It could only verify that a security group or NACL is misconfigured, not detect the ongoing attack.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is purpose-built for threat detection, analyzing continuous data from VPC Flow Logs, AWS CloudTrail events, and DNS query logs with machine learning and threat intelligence. It recognizes SSH brute force patterns, such as a single source IP making a large number of TCP connections to port 22 on an EC2 instance, and surfaces findings like UnauthorizedAccess:EC2/SSHBruteForce. Those findings can be pushed to Amazon EventBridge to trigger automated alerting or remediation, making it the correct service here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans instances and container images for software vulnerabilities, unintended network exposure, and deviations from security best practices. It runs assessments periodically and reports on weaknesses like missing patches, but it does not monitor live network traffic or recognize repeated authentication failures in real time. Inspector would tell you that an instance is weak to attack, not that a brute force attack is currently happening.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity in the AWS control plane, including actions performed by IAM users, roles, or services, and it does not capture TCP packets or application-layer payloads. SSH connections to an EC2 instance occur over the VPC data plane, so CloudTrail never sees port 22 sessions or login failures on the guest OS. While CloudTrail could show API calls that alter a security group or launch an instance, it cannot alert on actual SSH brute force attempts.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is designed to absorb and mitigate distributed denial of service attacks, such as volumetric floods, SYN floods, or DNS amplification, at AWS edge locations. It protects availability and network infrastructure, but it does not inspect individual SSH sessions or track authentication failures, so a brute force attack targeting one instance's login is beyond its scope. Shield Advanced may provide DDoS cost protection and attack diagnostics, but it will not generate findings for repeated failed logins.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.