Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential compromise of an IAM user. The engineer sees that the user's access keys were used from an IP address outside the company's allowed geography. Which AWS service can provide the most immediate notification of such anomalous API calls?

⚠ Common exam trap

A common mix-up: candidates confuse AWS CloudTrail's logging capability with active threat detection, forgetting that CloudTrail only records events and requires an additional service like GuardDuty or a custom CloudWatch alarm to provide immediate notification of anomalous activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including anomalous API calls from unusual geographies. It uses machine learning and integrated threat intelligence to analyze CloudTrail events, VPC flow logs, and DNS logs in near real-time, enabling immediate notification of suspicious activity such as access key usage from an unexpected IP address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    Trusted Advisor is a service that provides recommendations for cost optimization, performance, security, and fault tolerance based on AWS Well-Architected best practices and service limits. It does not analyze API activity or generate security findings; it is a static review of your AWS environment configuration. During a potential compromise, Trusted Advisor would not detect anomalous behavior or ongoing attack activity, so it is not the right tool for this investigation.

  • ✓

    Amazon GuardDuty

    Why this is correct

    GuardDuty is a continuous, intelligent threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to identify unexpected and potentially malicious activity within your AWS environment. It analyzes CloudTrail management and data events, VPC Flow Logs, and DNS query logs to detect suspicious API calls, unusual network traffic, and compromised credentials. Findings are generated with severity levels and can automatically trigger remediation workflows via EventBridge, making it the ideal service for investigating a potential compromise.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records AWS API activity in your account, providing an audit log of who did what, when, and from which IP address. However, CloudTrail itself is a logging service and does not actively analyze or alert on suspicious patterns; it simply delivers event logs to an S3 bucket or CloudWatch Logs. To use CloudTrail for detecting a compromise, you would need to build separate rules or queries against those logs, so it is insufficient as a direct detection and investigation tool in real time.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    CloudWatch is a monitoring and observability service that collects metrics, logs, and events, and can trigger alarms based on user-defined thresholds. It is not a purpose-built security service; it would require you to manually configure custom metrics, log metric filters, and alarms to detect specific indicators of compromise. Without prior custom setup, CloudWatch would not proactively surface security findings about anomalous API calls or credential misuse during an active investigation.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.