Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company wants to monitor for unauthorized API calls in real-time. The solution must meet the following requirements: - Detect calls that fail authentication (AccessDenied). - Detect calls that use a revoked IAM role. - Provide a centralized view across multiple accounts. Which THREE services should be used together to implement this solution? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse AWS IAM Access Analyzer with CloudTrail for monitoring API calls, but Access Analyzer only analyzes resource policies for external access, not real-time API activity or authentication failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations

AWS Organizations is correct because it enables centralized management of multiple AWS accounts, allowing the solution to aggregate CloudTrail logs from all accounts into a single CloudWatch Logs group. This centralization is essential for real-time monitoring of unauthorized API calls across the entire organization, as CloudTrail logs record all API activity including AccessDenied errors and actions taken by revoked IAM roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Organizations

    Why this is correct

    AWS Organizations is the correct answer because it lets you create a single organization trail in CloudTrail that captures API activity for every member account, including new accounts as they join. By aggregating all trails centrally, you gain a complete audit baseline and can enforce a trail that member accounts cannot disable or modify, preventing gaps in monitoring. This makes Organizations essential for managing and protecting your organization-wide API monitoring infrastructure.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the correct answer because it records every AWS API call made in an account, including failed calls that return AccessDenied, and delivers those events to an S3 bucket or CloudWatch Logs. Each event contains the caller's identity, source IP, request parameters, and response elements, providing the raw evidence needed to detect unauthorized API attempts. Without CloudTrail, there is no detailed record of API activity, so it is the primary data source for this use case.

  • ✗

    AWS IAM Access Analyzer

    Why it's wrong here

    AWS IAM Access Analyzer is incorrect because it does not monitor API calls; rather, it analyzes resource-based policies to identify resources that are shared with external principals, such as an S3 bucket that is inadvertently accessible to another AWS account. Its purpose is to reveal unintended permission exposures in your existing configuration, not to log or alert on API requests. Therefore, it cannot help you detect unauthorized API calls that have already occurred or are being attempted.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs is a correct supporting service because it enables you to ingest CloudTrail event logs and create metric filters and alarms to detect patterns like AccessDenied, triggering real-time notifications or automated responses. However, it is not the source of the API data—it depends on CloudTrail to deliver the logs. For monitoring unauthorized API calls, CloudWatch Logs is the alerting and analysis layer, while CloudTrail provides the recorded events themselves.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is incorrect because it focuses on evaluating the configuration and compliance state of your AWS resources, such as ensuring an S3 bucket has encryption enabled, and it records configuration changes over time. It does not capture who made an API call, whether the call succeeded or failed, or the request parameters. Since it has no API-level activity data, it is unsuitable for monitoring unauthorized API calls and serves a completely different purpose.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.