Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company wants to detect and alert on suspicious IAM user behavior, such as accessing services that are not typically used. Which AWS service provides prebuilt anomaly detection for IAM users?

⚠ Common exam trap

A common mix-up: candidates confuse AWS CloudTrail's logging capability with active threat detection, assuming that because CloudTrail records API calls, it can also detect anomalies, but it lacks the machine learning engine required for prebuilt anomaly detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is the correct answer because it is a threat detection service that uses machine learning and anomaly detection to identify suspicious IAM user behavior, such as accessing services not typically used. It analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs to establish baselines and generate findings for unusual API calls or access patterns. This prebuilt capability directly addresses the requirement for detecting atypical IAM activity without manual configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is a best-practice recommendation engine that checks your account against AWS's predefined pillars—cost optimization, performance, fault tolerance, service limits, and security. For security, its IAM checks are configuration-focused, such as verifying access-key rotation or deleting unused credentials, and it reports against a static snapshot. It does not perform continuous, real-time analysis of CloudTrail events to spot behavioral anomalies like a user logging in from a new country or making atypical API calls. Therefore, while it might flag an insecure IAM config, it cannot detect and alert on suspicious IAM user activity as it happens.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is the audit mechanism that records API calls made by or on behalf of an IAM user, delivering immutable logs to S3 or CloudWatch Logs for later analysis. However, it is purely a data capture service—it has no built-in machine learning or threshold-based logic to compare events against an expected baseline or produce a security finding. You could theorize and query the logs with Athena, or ship them to a SIEM, but the service itself will not 'alert' you to an anomalous pattern without that extra tooling. In short, CloudTrail answers 'what happened' but does not answer 'is this suspicious?', which is why it is not the correct answer.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is the correct answer because it is a managed threat detection service that combines machine learning, anomaly detection, and threat intelligence to monitor suspicious activity across your AWS environment. Specifically, it consumes CloudTrail management events to profile each IAM user's normal behavior—typical IP addresses, geographic locations, login times, and API call frequency—and then flags deviations as findings like 'Unusual IAM User Login' or 'Impossible Travel' activity. When a finding is generated, GuardDuty automatically emits an event to Amazon EventBridge, which you can pipe to SNS, Lambda, or Security Hub to trigger near-real-time alerts and automated responses. This provides exactly the detect-and-alert capability the company needs without requiring them to build custom analytics.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that focuses on compute workloads, specifically Amazon EC2 instances, ECR container images, and Lambda functions at the package and network level. It assesses whether your resources have known CVEs, software flaws, or unintended network exposure, and it does not ingest CloudTrail data or interact with IAM roles' usage patterns. Since Inspector has no visibility into an IAM user's API behavior—whether that user is signing in from an odd location, making anomalous calls, or showing other red flags—it cannot generate findings for suspicious IAM activity. Therefore, using Inspector for this use case would simply be the wrong tool, as it addresses workload vulnerabilities rather than identity behavior.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.