Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security analyst wants to monitor unsuccessful login attempts to the AWS Management Console. Which AWS service and log combination should be used?

⚠ Common exam trap

Candidates often confuse CloudWatch Logs (a log destination) with a log source, forgetting that CloudWatch Logs cannot capture console login events without CloudTrail delivering them first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail.

AWS CloudTrail is the correct service because it records all API calls made to the AWS Management Console, including failed login attempts (ConsoleLogin events with an 'errorMessage' field). CloudTrail logs these events as management events, which can be delivered to Amazon CloudWatch Logs or an S3 bucket for monitoring and alerting. This makes it the only option that captures authentication failures at the console level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon S3 server access logs.

    Why it's wrong here

    Amazon S3 server access logs capture object-level API requests sent directly to an S3 bucket, such as PUT, GET, LIST, and DELETE operations. These logs record the requester, bucket name, object key, action, and HTTP response status, but they are generated only for S3 data operations. IAM console authentication attempts are not S3 requests, so these logs contain no sign-in events or authentication results; therefore, they cannot reveal failed logins.

  • ✗

    VPC Flow Logs.

    Why it's wrong here

    VPC Flow Logs capture metadata about network traffic passing through elastic network interfaces, including source and destination IP addresses, ports, protocol, and packet/byte counts. They do not parse the application-layer payload because traffic is TLS-encrypted, so they cannot identify the IAM principal attempting to sign in or determine whether an authentication attempt succeeded or failed. A failed login attempt may not even generate meaningful network flow data beyond a brief TLS handshake, so flow logs are not a reliable source for monitoring authentication failures.

  • ✗

    Amazon CloudWatch Logs.

    Why it's wrong here

    Amazon CloudWatch Logs is a centralized log storage, monitoring, and alerting service that receives log data from other AWS services, but it does not natively produce IAM authentication events. You would need to configure a CloudTrail trail to deliver CloudTrail event history to a CloudWatch Logs log group, and then create a metric filter or alert on ConsoleLogin events with LoginResult equal to Failure. Simply enabling CloudWatch Logs without a log source such as CloudTrail gives you no login attempt data, making it a destination rather than a source of these events.

  • ✓

    AWS CloudTrail.

    Why this is correct

    AWS CloudTrail records the ConsoleLogin management event for every AWS Management Console sign-in attempt, including both successful and failed authentications. A failed login appears as an event with the eventName ConsoleLogin and responseElements.ConsoleLogin.LoginResult set to Failure, along with details like the IAM user or root principal, source IP address, user agent, and MFA usage. Security analysts can query these events with the AWS CLI lookup-events command, the CloudTrail console, or by analyzing the JSON log files delivered to S3 or CloudWatch Logs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.