Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is analyzing a potential security incident involving an Amazon RDS for MySQL database. The engineer suspects that a SQL injection attack was successful. Which AWS service can the engineer use to review the actual SQL queries that were executed against the database?

⚠ Common exam trap

Test-takers frequently confuse AWS CloudTrail (which logs control-plane API calls) with database audit logs (which log data-plane SQL queries), leading them to incorrectly select CloudTrail for reviewing executed SQL statements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon RDS Audit Logs

Amazon RDS for MySQL supports audit logs that capture detailed records of database activities, including the actual SQL queries executed. By enabling the `audit_log` plugin and configuring the `server_audit_events` parameter, the engineer can review the exact SQL statements that were run, which is essential for identifying a SQL injection attack. This is the only AWS service that provides query-level visibility into RDS database operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic at the network layer — source/destination addresses, ports, protocol, packet and byte counts — but they do not decode application payloads. Therefore, they might reveal that a client connected to an RDS instance on port 3306, but they will never contain the actual SQL text of semicolon-delimited queries. This makes Flow Logs useless for identifying an unauthorized SELECT or INSERT statement, which is exactly what a SQL injection investigation requires.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events using machine learning and threat intelligence to surface suspicious behaviors like crypto mining, compromised EC2 instances, or anomalous API calls. It does not, however, record or store the SQL statements executed against an RDS database, nor does it function as a database-level audit logger. GuardDuty might alert on a compromised host that reaches an RDS database, but it will not tell you the exact SQL query or which table was accessed.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity in the AWS control plane, such as CreateDBInstance, ModifyDBInstance, or AuthorizeDBSecurityGroupIngress, for governance and compliance. For RDS specifically, CloudTrail does not capture data-plane events like SQL queries executed over a database connection. Unless you are using CloudTrail data events for S3 or Lambda, you will not see any per-statement SQL; thus CloudTrail is the wrong source for a SQL injection audit trail.

  • ✓

    Amazon RDS Audit Logs

    Why this is correct

    Amazon RDS Audit Logs are the correct source because they record the actual SQL statements executed against the database, along with the connecting user, source IP, and timestamp. For RDS MySQL or MariaDB, you enable the audit_log plugin via a DB parameter group and then export the logs to CloudWatch Logs; for PostgreSQL, you use the pgaudit extension. Misconfigured database users or SQL injection attempts will appear in these logs, making them the definitive forensic evidence during a security incident.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.