SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating a potential compromise of an IAM user. The engineer sees that the user's access keys were used from an IP address outside the company's allowed geography. Which AWS service can provide the most immediate notification of such anomalous API calls?
⚠ Common exam trap
A common mix-up: candidates confuse AWS CloudTrail's logging capability with active threat detection, forgetting that CloudTrail only records events and requires an additional service like GuardDuty or a custom CloudWatch alarm to provide immediate notification of anomalous activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including anomalous API calls from unusual geographies. It uses machine learning and integrated threat intelligence to analyze CloudTrail events, VPC flow logs, and DNS logs in near real-time, enabling immediate notification of suspicious activity such as access key usage from an unexpected IP address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor is a service that provides recommendations for cost optimization, performance, security, and fault tolerance based on AWS Well-Architected best practices and service limits. It does not analyze API activity or generate security findings; it is a static review of your AWS environment configuration. During a potential compromise, Trusted Advisor would not detect anomalous behavior or ongoing attack activity, so it is not the right tool for this investigation.
- ✓
Amazon GuardDuty
Why this is correct
GuardDuty is a continuous, intelligent threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to identify unexpected and potentially malicious activity within your AWS environment. It analyzes CloudTrail management and data events, VPC Flow Logs, and DNS query logs to detect suspicious API calls, unusual network traffic, and compromised credentials. Findings are generated with severity levels and can automatically trigger remediation workflows via EventBridge, making it the ideal service for investigating a potential compromise.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records AWS API activity in your account, providing an audit log of who did what, when, and from which IP address. However, CloudTrail itself is a logging service and does not actively analyze or alert on suspicious patterns; it simply delivers event logs to an S3 bucket or CloudWatch Logs. To use CloudTrail for detecting a compromise, you would need to build separate rules or queries against those logs, so it is insufficient as a direct detection and investigation tool in real time.
- ✗
Amazon CloudWatch
Why it's wrong here
CloudWatch is a monitoring and observability service that collects metrics, logs, and events, and can trigger alarms based on user-defined thresholds. It is not a purpose-built security service; it would require you to manually configure custom metrics, log metric filters, and alarms to detect specific indicators of compromise. Without prior custom setup, CloudWatch would not proactively surface security findings about anomalous API calls or credential misuse during an active investigation.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.