Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security analyst is reviewing AWS CloudTrail logs and notices a series of API calls from an unfamiliar IAM user. The calls include CreateUser, AttachUserPolicy, and CreateAccessKey. The analyst wants to quickly determine if this activity is anomalous and receive real-time alerts. Which AWS service should the analyst use to achieve this with minimal configuration?

⚠ Common exam trap

Many candidates confuse services that aggregate or investigate findings with the service that actually performs the initial anomaly detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is the correct service because it automatically analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to detect anomalous behavior, including suspicious IAM activity. It requires no additional infrastructure and generates findings in near real-time. Security Hub and Detective are for aggregation and investigation, while AWS Config focuses on configuration compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon GuardDuty

    Why this is correct

    GuardDuty continuously monitors CloudTrail management events and uses machine learning and threat intelligence to detect anomalous IAM behavior, such as unusual user creation or policy attachment. It generates findings in near real-time with minimal setup, requiring only that GuardDuty be enabled. This directly addresses the analyst's need for quick anomaly detection and alerts.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configurations and evaluates them against rules, but it does not analyze API call patterns for anomalies. It can alert on configuration changes, but the sequence of IAM API calls is not a configuration item. Config would not detect the anomalous behavior or provide real-time alerts for these API calls.

  • ✗

    Amazon Detective

    Why it's wrong here

    Detective is designed for investigating and analyzing security findings, not for real-time alerting on anomalous API calls. It helps visualize and analyze relationships after a finding is generated. It does not proactively detect the IAM activity described or send real-time alerts. It is an investigation tool, not a detection service.

  • ✗

    AWS Security Hub

    Why it's wrong here

    Security Hub aggregates findings from multiple services and can detect some issues, but it does not natively analyze CloudTrail logs for anomalous IAM behavior in real time. It relies on other services like GuardDuty to generate findings. Using Security Hub alone would not provide the immediate anomaly detection for these specific API calls without additional configuration.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.