SCS-C02 Security Logging and Monitoring Practice Question
A company wants to monitor for unauthorized API calls in real-time. The solution must meet the following requirements: - Detect calls that fail authentication (AccessDenied). - Detect calls that use a revoked IAM role. - Provide a centralized view across multiple accounts. Which THREE services should be used together to implement this solution? (Choose three.)
⚠ Common exam trap
Test-takers frequently confuse AWS IAM Access Analyzer with CloudTrail for monitoring API calls, but Access Analyzer only analyzes resource policies for external access, not real-time API activity or authentication failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations
AWS Organizations is correct because it enables centralized management of multiple AWS accounts, allowing the solution to aggregate CloudTrail logs from all accounts into a single CloudWatch Logs group. This centralization is essential for real-time monitoring of unauthorized API calls across the entire organization, as CloudTrail logs record all API activity including AccessDenied errors and actions taken by revoked IAM roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Organizations
Why this is correct
AWS Organizations is the correct answer because it lets you create a single organization trail in CloudTrail that captures API activity for every member account, including new accounts as they join. By aggregating all trails centrally, you gain a complete audit baseline and can enforce a trail that member accounts cannot disable or modify, preventing gaps in monitoring. This makes Organizations essential for managing and protecting your organization-wide API monitoring infrastructure.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct answer because it records every AWS API call made in an account, including failed calls that return AccessDenied, and delivers those events to an S3 bucket or CloudWatch Logs. Each event contains the caller's identity, source IP, request parameters, and response elements, providing the raw evidence needed to detect unauthorized API attempts. Without CloudTrail, there is no detailed record of API activity, so it is the primary data source for this use case.
- ✗
AWS IAM Access Analyzer
Why it's wrong here
AWS IAM Access Analyzer is incorrect because it does not monitor API calls; rather, it analyzes resource-based policies to identify resources that are shared with external principals, such as an S3 bucket that is inadvertently accessible to another AWS account. Its purpose is to reveal unintended permission exposures in your existing configuration, not to log or alert on API requests. Therefore, it cannot help you detect unauthorized API calls that have already occurred or are being attempted.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs is a correct supporting service because it enables you to ingest CloudTrail event logs and create metric filters and alarms to detect patterns like AccessDenied, triggering real-time notifications or automated responses. However, it is not the source of the API data—it depends on CloudTrail to deliver the logs. For monitoring unauthorized API calls, CloudWatch Logs is the alerting and analysis layer, while CloudTrail provides the recorded events themselves.
- ✗
AWS Config
Why it's wrong here
AWS Config is incorrect because it focuses on evaluating the configuration and compliance state of your AWS resources, such as ensuring an S3 bucket has encryption enabled, and it records configuration changes over time. It does not capture who made an API call, whether the call succeeded or failed, or the request parameters. Since it has no API-level activity data, it is unsuitable for monitoring unauthorized API calls and serves a completely different purpose.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.