SCS-C02 Threat Detection and Incident Response Practice Question
Exhibit
Refer to the exhibit. ``` 2024-03-15T10:30:00Z us-east-1 123456789012 ENI eni-0a1b2c3d4e5f67890 src 203.0.113.5 dst 10.0.1.5 port 443 proto 6 packets 10 bytes 1200 start 2024-03-15T10:30:00Z end 2024-03-15T10:30:05Z action ACCEPT log-status OK ```
A security engineer is analyzing VPC Flow Logs and sees the entry above. The source IP 203.0.113.5 is flagged as suspicious. What additional information would help determine if this is malicious?
⚠ Common exam trap
The trap here is that candidates focus on network-layer indicators (ports, ACLs, GuardDuty) instead of recognizing that VPC Flow Logs lack identity context, so CloudTrail is the only service that can tie an IP to an authenticated action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudTrail logs for any `ConsoleLogin` or `AssumeRole` events from 203.0.113.5.
VPC Flow Logs capture network traffic metadata (IPs, ports, protocols) but not the identity or authentication context of the source. CloudTrail logs record API calls, including ConsoleLogin and AssumeRole events, which can reveal whether 203.0.113.5 is associated with an authenticated user or role. If no such events exist, the traffic is likely from an unauthenticated external source, strengthening the case for malicious activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The source port used by 203.0.113.5.
Why it's wrong here
Source port is already present in the VPC Flow Log record, but it is ephemeral and randomly selected by the client's OS for each connection. It provides no indication of attacker identity, motive, or whether the traffic is malicious, since any TCP or UDP client uses a range of temporary source ports. Knowing the source port would not help validate whether 203.0.113.5 was attempting unauthorized access; it is simply transport-layer metadata.
- ✓
CloudTrail logs for any `ConsoleLogin` or `AssumeRole` events from 203.0.113.5.
Why this is correct
CloudTrail records identity-plane events such as `ConsoleLogin` (sign-in events) and `sts:AssumeRole` with the source IP address of the caller. If the same IP 203.0.113.5 appears in these events, it directly links the network traffic to authentication or authorization activity, suggesting the IP is an active user or an attacker leveraging compromised credentials. This correlation is the strongest indicator of malicious intent because VPC Flow Logs alone cannot attribute network flows to an IAM principal, whereas CloudTrail can.
- ✗
Network ACL changes associated with the destination subnet.
Why it's wrong here
Network ACL changes on the destination subnet alter which traffic is allowed into or out of the subnet, but they represent a configuration action, not evidence of an attack from a specific IP. Even if a NACL was recently modified to block 203.0.113.5, that would be a reaction to the traffic, not proof that the traffic was malicious—it could equally be a routine update or a misconfigured rule. Investigating NACL changes would not establish whether the source IP was attempting unauthorized access through a service like SSH or RDP.
- ✗
Amazon GuardDuty findings for the destination 10.0.1.5.
Why it's wrong here
GuardDuty findings for destination 10.0.1.5 would describe suspicious activity involving that EC2 instance or workload, such as crypto-mining or a brute force attempt, but they may not reference 203.0.113.5 as the actor. Findings are generated from multiple data sources including DNS, NetFlow, and threat intelligence, and the absence of a finding for that specific IP does not rule out malicious behavior, nor does a finding about the destination prove this particular flow was hostile. The question specifically seeks evidence tying the source IP to malicious activity, which GuardDuty findings for the destination are too indirect to provide.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.