Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company wants to detect and alert on suspicious IAM role usage, such as a role being assumed from an unusual geographic location. Which AWS service should be used to generate the alerts?

⚠ Common exam trap

It's easy for candidates to confuse AWS CloudTrail's logging capability with detection, assuming that because CloudTrail records the AssumeRole event, it can also alert on it, but CloudTrail requires an additional service like GuardDuty or CloudWatch with custom rules to generate alerts, whereas GuardDuty provides built-in, automated anomaly detection for this exact scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is the correct choice because it is a threat detection service that continuously monitors for suspicious activity, including unusual IAM role usage such as a role being assumed from an anomalous geographic location. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze CloudTrail management events and VPC flow logs, generating alerts (findings) for deviations from baseline behavior. This directly meets the requirement to detect and alert on suspicious role assumptions without needing to write custom rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS IAM Access Analyzer

    Why it's wrong here

    AWS IAM Access Analyzer identifies resources shared with external entities by analyzing resource policies, but it does not monitor CloudTrail activity or detect anomalous usage patterns of IAM roles. Its purpose is to flag overly permissive policies, not to alert on suspicious post-authentication behavior, so it cannot fulfill the requirement.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty continuously monitors CloudTrail management events, including IAM role assumptions and API activity, using machine learning and threat intelligence to detect suspicious behavior such as credential exfiltration or anomalous role usage. It generates findings that can trigger alerts via EventBridge, making it the correct choice for detecting and alerting on suspicious IAM role activity.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail captures a complete audit trail of API calls and IAM role usage, but it is a logging service that merely stores events; it has no built-in anomaly detection or alerting capability. To get alerts, you would need to write custom rules against the event history, whereas GuardDuty provides automated analysis.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch can monitor and alarm on metrics or log patterns, but IAM role usage is not exposed as a default CloudWatch metric, so you would need custom log filters, metric filters, and alarms—essentially building your own detection logic. This lacks GuardDuty's prebuilt threat detection and machine learning-driven anomaly identification for low-level IAM activity.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.