Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer wants to ensure that all member accounts send findings to the delegated administrator account. However, some member accounts are not sending findings. What is the most likely cause?

⚠ Common exam trap

Many exam-takers assume that enabling GuardDuty via AWS Organizations automatically activates it in all member accounts and forwards findings, but in reality, each member account must either accept the invitation or be explicitly enabled by the delegated administrator using the appropriate API call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GuardDuty is not enabled in the member accounts, or they have not accepted the invitation.

GuardDuty requires that each member account has the service explicitly enabled and has accepted the invitation from the delegated administrator account. Without these steps, the member accounts cannot send findings to the administrator, even if AWS Organizations is configured correctly. The delegated administrator can only manage findings from accounts that have completed the onboarding process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The GuardDuty service-linked role is missing in the member accounts.

    Why it's wrong here

    This is wrong because when GuardDuty is enabled in an account, AWS automatically creates the service-linked role (AWSServiceRoleForGuardDuty) and attaches the necessary permissions. The role is not a prerequisite for member accounts to send findings; it is managed by the service. In a multi-account setup, the administrator account initiates the invitation, and member accounts simply need to enable GuardDuty and accept the invitation.

  • ✗

    AWS CloudTrail is not enabled in the member accounts.

    Why it's wrong here

    GuardDuty does not require CloudTrail to be enabled in order to generate or deliver findings. GuardDuty analyzes multiple data sources, including VPC Flow Logs, DNS logs, and CloudTrail events, but it operates with whatever data sources are available; CloudTrail is not a mandatory prerequisite. The absence of findings in the administrator account is more likely caused by the member account not having GuardDuty enabled or not accepting the invitation, not by CloudTrail being disabled.

  • ✓

    GuardDuty is not enabled in the member accounts, or they have not accepted the invitation.

    Why this is correct

    In a GuardDuty multi-account setup, the administrator account sends invitations to member accounts. Each member account must explicitly enable GuardDuty and accept the invitation before it can begin sending findings to the administrator. If a member account has not enabled GuardDuty or has not accepted the invitation, no findings are received from that account. This is the most common reason for missing findings in the administrator console.

  • ✗

    VPC Flow Logs are not enabled in the member accounts.

    Why it's wrong here

    GuardDuty can generate findings even without VPC Flow Logs; it uses those logs if they are available, but they are not required for GuardDuty to function. VPC Flow Logs are only one of several data sources that GuardDuty analyzes, and the absence of VPC Flow Logs does not prevent GuardDuty from producing findings based on other sources such as DNS logs or CloudTrail events. The core problem of missing findings is usually the member account not having GuardDuty enabled or the invitation not accepted.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.