SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is investigating a potential compromise. The engineer notices that an EC2 instance is sending outbound traffic to an unknown IP address on port 443. The engineer needs to determine if the instance is communicating with a known command and control (C2) server. Which AWS service can the engineer use to check the reputation of the destination IP address?
⚠ Common exam trap
Watch out — candidates often confuse VPC Flow Logs (which only capture raw network metadata) with a security analysis service like GuardDuty, assuming that flow logs alone can determine IP reputation without additional threat intelligence integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including communication with known command and control (C2) servers. It uses threat intelligence feeds, such as those from AWS and third-party partners, to check the reputation of destination IP addresses and alert on suspicious outbound traffic. In this scenario, GuardDuty can directly identify if the EC2 instance is communicating with a known C2 server by analyzing VPC Flow Logs, DNS logs, and other data sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an audit service that records management and data-plane API activity, such as which principal made an API call, the source IP, and the request parameters. During a compromise, CloudTrail can reveal credential misuse or anomalous API sequences, but it does not analyze network flows or apply IP reputation scoring to outbound connections. Therefore, CloudTrail alone cannot tell you that an EC2 instance is communicating with a known malicious IP; it lacks the traffic visibility and threat-intelligence enrichment required for that specific detection.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic reaching and leaving an elastic network interface, including source and destination addresses, ports, and protocol. They are passive logs with no built-in threat-intelligence context, so they do not identify whether a destination IP is known to be malicious. To detect communication with a malicious IP, you would need to export these logs to Athena and join them against an external reputation list, making VPC Flow Logs a raw telemetry source rather than a managed detection service that generates findings.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor inspects your AWS environment against best-practice checks for cost optimization, performance, security, and service limits. It does not ingest network traffic, monitor runtime behavior, or consult external threat intelligence to flag IP reputation. Because it is a policy-based advisory tool, Trusted Advisor cannot detect an active compromise involving outbound calls to a known malicious IP.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a managed threat detection service that continuously consumes VPC Flow Logs, DNS query logs, CloudTrail events, and S3 data events. It applies integrated threat intelligence from AWS and third-party sources, along with machine learning and anomaly detection, to generate findings when an EC2 instance communicates with a known malicious IP, Bitcoin miner, or Tor node. Its findings include the affected resource, the malicious IP, the protocol and port, and confidence indicators, enabling a security engineer to quickly investigate and respond.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.