SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is designing a monitoring solution for a multi-account AWS environment using AWS Organizations. The solution must provide a centralized view of all API activities and send alerts for suspicious events. Which TWO services together can achieve this? (Choose TWO.)
⚠ Common exam trap
The trap here is that candidates often pick GuardDuty (A) because it is a security service, but they overlook that GuardDuty does not provide a centralized view of all API activities or allow custom alerting on specific API events, which requires CloudTrail and CloudWatch Logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is correct because it records all API activity across an AWS environment, and when integrated with AWS Organizations, it can deliver a centralized view of API calls from all accounts into a single CloudTrail trail. Amazon CloudWatch Logs is correct because it can ingest CloudTrail logs from a centralized logging account, allowing the security engineer to create metric filters and alarms that trigger alerts for suspicious events based on specific API patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS query logs, and AWS CloudTrail management events to identify malicious activity and compromised credentials. It does not itself capture or retain an authoritative record of every API call; instead it consumes CloudTrail events as a source, so it cannot serve as the centralized API activity log for auditing or compliance. Its output is a prioritized list of findings, not a complete queryable history of API actions.
- ✗
AWS Lambda
Why it's wrong here
AWS Lambda is a serverless compute service that runs code in response to events; it can process or transform log records, but it has no native capability to capture AWS API activity. Without a separate service such as CloudTrail to generate the events, Lambda has nothing to ingest, and it does not provide persistent storage, search, or an audit trail on its own. Using Lambda would require you to build custom ingestion, storage, and alerting logic, making it an implementation component rather than a centralized monitoring service.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records management events (and optionally data events) for every API call made in an AWS account, capturing the identity, source IP, time, request parameters, and response elements. When enabled for an AWS Organization, you can create an organization trail that logs events for all accounts and delivers them to a single Amazon S3 bucket, enabling centralized auditing. This makes CloudTrail the definitive source of API activity for security monitoring, compliance, and forensic investigation.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs can aggregate CloudTrail logs by receiving them from an S3 bucket via a CloudWatch Logs subscription, and then use metric filters to detect patterns such as unauthorized API calls or IAM policy changes, triggering CloudWatch Alarms. It provides centralized storage, search, and monitoring across accounts when configured in a central logging account. However, CloudWatch Logs is the destination and analysis layer; it is not the source of API call records and depends on CloudTrail or other log producers to supply the data.
- ✗
AWS Config
Why it's wrong here
AWS Config records the configuration state and changes of AWS resources over time, evaluating them against desired policies such as whether an S3 bucket is publicly accessible, but it does not capture the individual API calls or the identity that made them. While Config can reference CloudTrail events to understand what changed a resource, it is not an API activity log and its primary purpose is configuration compliance, not monitoring every action. Therefore, it cannot substitute for CloudTrail when you need a complete record of API activity across accounts.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.