SCS-C02 Security Logging and Monitoring Practice Question
A security analyst wants to monitor unsuccessful login attempts to the AWS Management Console. Which AWS service and log combination should be used?
⚠ Common exam trap
Candidates often confuse CloudWatch Logs (a log destination) with a log source, forgetting that CloudWatch Logs cannot capture console login events without CloudTrail delivering them first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail.
AWS CloudTrail is the correct service because it records all API calls made to the AWS Management Console, including failed login attempts (ConsoleLogin events with an 'errorMessage' field). CloudTrail logs these events as management events, which can be delivered to Amazon CloudWatch Logs or an S3 bucket for monitoring and alerting. This makes it the only option that captures authentication failures at the console level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 server access logs.
Why it's wrong here
Amazon S3 server access logs capture object-level API requests sent directly to an S3 bucket, such as PUT, GET, LIST, and DELETE operations. These logs record the requester, bucket name, object key, action, and HTTP response status, but they are generated only for S3 data operations. IAM console authentication attempts are not S3 requests, so these logs contain no sign-in events or authentication results; therefore, they cannot reveal failed logins.
- ✗
VPC Flow Logs.
Why it's wrong here
VPC Flow Logs capture metadata about network traffic passing through elastic network interfaces, including source and destination IP addresses, ports, protocol, and packet/byte counts. They do not parse the application-layer payload because traffic is TLS-encrypted, so they cannot identify the IAM principal attempting to sign in or determine whether an authentication attempt succeeded or failed. A failed login attempt may not even generate meaningful network flow data beyond a brief TLS handshake, so flow logs are not a reliable source for monitoring authentication failures.
- ✗
Amazon CloudWatch Logs.
Why it's wrong here
Amazon CloudWatch Logs is a centralized log storage, monitoring, and alerting service that receives log data from other AWS services, but it does not natively produce IAM authentication events. You would need to configure a CloudTrail trail to deliver CloudTrail event history to a CloudWatch Logs log group, and then create a metric filter or alert on ConsoleLogin events with LoginResult equal to Failure. Simply enabling CloudWatch Logs without a log source such as CloudTrail gives you no login attempt data, making it a destination rather than a source of these events.
- ✓
AWS CloudTrail.
Why this is correct
AWS CloudTrail records the ConsoleLogin management event for every AWS Management Console sign-in attempt, including both successful and failed authentications. A failed login appears as an event with the eventName ConsoleLogin and responseElements.ConsoleLogin.LoginResult set to Failure, along with details like the IAM user or root principal, source IP address, user agent, and MFA usage. Security analysts can query these events with the AWS CLI lookup-events command, the CloudTrail console, or by analyzing the JSON log files delivered to S3 or CloudWatch Logs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.