Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company wants to monitor for unauthorized changes to security group rules in their VPC. Which TWO AWS services can be used together to detect and alert on such changes?

⚠ Common exam trap

Test-takers frequently confuse VPC Flow Logs (which show traffic) with CloudTrail (which shows API calls), or think GuardDuty monitors configuration changes when it actually focuses on threat detection in network and account activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is correct because it records API calls made to the EC2 service, including AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and CreateSecurityGroup. By monitoring CloudTrail events for these specific API actions, you can detect unauthorized changes to security group rules. AWS Config is correct because it provides a managed rule called 'restricted-common-ports' or custom rules that can evaluate security group configurations against desired policies, and it can trigger alerts via Amazon SNS when a security group rule is changed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the correct answer because it records management events for all API calls made in your account, including ec2:AuthorizeSecurityGroupIngress, ec2:RevokeSecurityGroupIngress, and ec2:CreateSecurityGroup. Each event captures the identity of the caller, the source IP address, and a timestamp, giving you full attribution for who changed a security group rule and when. This makes CloudTrail the go-to service for auditing who took a specific action against a security group, which directly answers the requirement to monitor for unauthorized changes.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is also correct because it continuously records the configuration state of resources, including security group rules, and detects any changes as they occur. It maintains a configuration history for each security group, allowing you to see exactly what rule was added, removed, or modified, and you can pair it with managed rules or EventBridge to trigger alerts on noncompliant changes. Unlike CloudTrail's API-log view, Config focuses on the actual resource state, so it will tell you that the security group now allows port 22 from 0.0.0.0/0, regardless of which API call produced that change.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic entering and leaving network interfaces, not the configuration state of security group rules. They would not detect a rule change unless that change immediately generated traffic, and they provide no mechanism to alert on the modification itself. This option tempts because Flow Logs are commonly used for network monitoring and anomaly detection, and in a scenario requiring visibility into actual traffic patterns or bandwidth usage, they would be the correct choice.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is not the right choice because it is a threat detection service that analyzes telemetry such as VPC Flow Logs, DNS query logs, and CloudTrail management events to identify malicious activity like compromised instances, unusual API behavior, or port scanning. It does not natively track or alert on the configuration state of security group rules, and while a sudden change in traffic patterns could indirectly indicate a rule modification, GuardDuty has no mechanism to detect the modification itself. For an explicit security group change monitor, you need CloudTrail or Config, not GuardDuty.

  • ✗

    Amazon Macie

    Why it's wrong here

    Amazon Macie is incorrect because it is purpose-built for data security and privacy, using machine learning and pattern matching to discover sensitive data such as PII, credentials, or financial information stored in Amazon S3 buckets. It has no integration or ability to inspect security group configurations, network ACLs, or any other VPC infrastructure settings, so it cannot detect unauthorized changes to security groups. Choosing Macie would be a category error, as it addresses data classification, not infrastructure configuration monitoring.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.