SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is configuring logging for an application running on Amazon EC2 instances. The engineer needs to capture both operating system-level logs and application logs. Which TWO services can be used together to achieve this? (Choose two.)
⚠ Common exam trap
Candidates often confuse AWS CloudTrail (which logs AWS API calls) with the CloudWatch agent (which collects OS and application logs), leading them to select CloudTrail instead of the CloudWatch agent for internal instance logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs
Amazon CloudWatch Logs is the correct service because it provides a centralized location to store, monitor, and access log files from your EC2 instances. The Amazon CloudWatch agent is the correct companion service because it is specifically designed to collect both operating system-level logs (e.g., syslog, Windows Event Log) and application logs from EC2 instances and send them to CloudWatch Logs. Together, they fulfill the requirement of capturing both OS and application logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records the API activity performed on AWS accounts, logging who made calls, from which IP, when, and what actions were taken against resources. It captures control-plane and some data-plane events at the AWS service level, but it cannot read application stdout, syslog, or web server access logs produced inside an EC2 instance.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic traversing VPC ENIs, including source and destination addresses, ports, protocol, and byte counts, but never the payload content or process-level application messages. Because it operates at the network layer and does not have access to the OS file system or application writes, it cannot be used to collect application log files.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs is the managed destination where log data is stored, monitored, and queried; it centralizes log events from EC2, Lambda, and on-premises sources into log groups and log streams. When the CloudWatch agent publishes log records to this service, you can search them with Logs Insights, alarm on error patterns, and export them to S3 for long-term retention.
- ✓
Amazon CloudWatch agent
Why this is correct
The unified Amazon CloudWatch agent runs inside the EC2 instance and is responsible for collecting operating system and application logs by watching configured log files and emitting new records to CloudWatch Logs. It also gathers metrics such as CPU and memory usage, and supports multi-line log parsing, timestamp extraction, and log filters before forwarding, which makes it the collection mechanism rather than the storage service.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs automated security assessments on EC2 instances and container images, identifying software vulnerabilities, unintended network exposure, and deviations from security best practices. It does not ingest, store, or forward operating system or application log data, so it cannot fulfill a logging configuration requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.