SCS-C02 Threat Detection and Incident Response Practice Question
A security analyst is reviewing AWS CloudTrail logs and notices a series of API calls from an unfamiliar IAM user. The calls include CreateUser, AttachUserPolicy, and CreateAccessKey. The analyst wants to quickly determine if this activity is anomalous and receive real-time alerts. Which AWS service should the analyst use to achieve this with minimal configuration?
⚠ Common exam trap
Many candidates confuse services that aggregate or investigate findings with the service that actually performs the initial anomaly detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is the correct service because it automatically analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to detect anomalous behavior, including suspicious IAM activity. It requires no additional infrastructure and generates findings in near real-time. Security Hub and Detective are for aggregation and investigation, while AWS Config focuses on configuration compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon GuardDuty
Why this is correct
GuardDuty continuously monitors CloudTrail management events and uses machine learning and threat intelligence to detect anomalous IAM behavior, such as unusual user creation or policy attachment. It generates findings in near real-time with minimal setup, requiring only that GuardDuty be enabled. This directly addresses the analyst's need for quick anomaly detection and alerts.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configurations and evaluates them against rules, but it does not analyze API call patterns for anomalies. It can alert on configuration changes, but the sequence of IAM API calls is not a configuration item. Config would not detect the anomalous behavior or provide real-time alerts for these API calls.
- ✗
Amazon Detective
Why it's wrong here
Detective is designed for investigating and analyzing security findings, not for real-time alerting on anomalous API calls. It helps visualize and analyze relationships after a finding is generated. It does not proactively detect the IAM activity described or send real-time alerts. It is an investigation tool, not a detection service.
- ✗
AWS Security Hub
Why it's wrong here
Security Hub aggregates findings from multiple services and can detect some issues, but it does not natively analyze CloudTrail logs for anomalous IAM behavior in real time. It relies on other services like GuardDuty to generate findings. Using Security Hub alone would not provide the immediate anomaly detection for these specific API calls without additional configuration.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.