SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is investigating a possible data exfiltration from an S3 bucket. Which THREE AWS services can be used to detect and alert on suspicious activity? (Choose THREE.)
⚠ Common exam trap
Test-takers frequently confuse AWS Config with a security detection service, but Config only tracks configuration changes and compliance, not the actual data access or network activity needed to detect exfiltration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty (B) is correct because it continuously monitors CloudTrail management and S3 data events, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to generate findings such as Exfiltration:S3/ObjectRead.Unusual or Discovery:S3, which directly detect suspicious S3 access patterns. AWS CloudTrail (C) is correct because it records S3 data events (GetObject, PutObject, DeleteObject) and management events, providing the audit trail needed to identify anomalous API calls and feed GuardDuty and CloudWatch analysis. Amazon Macie (E) is correct because it uses machine learning and pattern matching to discover sensitive data in S3, and its findings (e.g., Policy:IAMUser/S3BucketPublic, SensitiveData:S3Object/Multiple) plus CloudWatch Events integration can alert on potential exfiltration of sensitive objects. Amazon CloudWatch Logs (A) is not a detection service for S3 activity by itself; it stores and monitors log streams but requires CloudTrail or other sources to capture S3 API calls. AWS Config (D) tracks resource configuration changes and compliance but does not analyze S3 object access behavior or sensitive data movement, so it cannot detect exfiltration activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized log storage and monitoring service that ingests, stores, and surfaces log events from resources such as EC2, Lambda, or S3 server access logs. It does not perform behavior-based anomaly detection on its own; while you can create metric filters or subscription filters to search for patterns, detecting a data exfiltration event would require you to already know and express the suspicious pattern in advance. Therefore, it is a supporting component for log aggregation, not a detective control that autonomously identifies unusual S3 data access.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a managed threat detection service that continuously analyzes AWS account activity, including CloudTrail management and S3 data events, VPC Flow Logs, and DNS query logs, using integrated threat intelligence and anomaly-detection machine learning. It can generate findings such as an S3 bucket compromised finding or unusual data-access patterns that strongly indicate data exfiltration, and it alerts security engineers without requiring manually defined thresholds. This makes it the most direct, purpose-built service for spotting suspicious S3 activity in near real time.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is an auditing service that records every S3 API call, such as GetObject, ListBucket, and CopyObject, into immutable audit logs that capture the identity, source IP, time, and request parameters. It is correct for this investigation because it provides the forensic evidence needed to trace the exact sequence of operations involved in a suspected exfiltration and to identify which user or role accessed or downloaded objects. However, CloudTrail is a logging mechanism, not a detection engine; it supplies the data that a service like GuardDuty analyzes to surface the anomaly.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration management and compliance service that records the configuration state of AWS resources over time, allowing you to evaluate resource settings against rules such as S3 bucket encryption enabled or MFA delete turned on. It does not inspect data-plane access activity, API call patterns, or object-level read and download volumes, so it lacks the visibility needed to detect the exfiltration of objects from within a bucket. Its value lies in auditing how resources are configured, not in detecting how data is being accessed or moved.
- ✓
Amazon Macie
Why this is correct
Amazon Macie is a data security service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in Amazon S3, such as credentials, financial records, and personally identifiable information. It also monitors S3 access patterns and generates alerts for anomalies like large downloads, publicly accessible buckets, or suspicious data movement, which makes it a valid detective control for data exfiltration. Its focus is on sensitive-data protection and understanding exposure, complementing GuardDuty's broader threat-detection findings.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.