SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is investigating a potential compromise. They notice that an IAM user 'svc-backup' has been making unusual API calls from an IP address outside the company's VPC. The engineer wants to ensure all future API calls from this user are logged with full event details. However, the current CloudTrail trail is set to log only management events. What should the engineer do to capture the required details?
⚠ Common exam trap
Watch out — candidates often confuse 'data events' with only S3 object-level operations, forgetting that IAM also has data events that must be explicitly enabled to capture user-level API calls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the existing trail to log data events for IAM.
CloudTrail trails configured to log only management events do not capture IAM user activity such as API calls made by the user. By updating the existing trail to log data events for IAM, the engineer ensures that all future API calls from 'svc-backup' are logged with full event details, including the source IP address and request parameters. This directly addresses the requirement without creating unnecessary additional trails or services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable VPC Flow Logs and correlate with CloudTrail logs.
Why it's wrong here
VPC Flow Logs capture IP flow metadata such as source and destination addresses, ports, protocols, and byte counts at the elastic network interface level, but they do not record IAM API calls. CloudTrail already logs IAM management events, yet the investigation requires data events like GetUser and ListAccessKeys, which Flow Logs cannot see. Even correlating Flow Logs with existing CloudTrail logs only maps network connections to AWS endpoints against management-level activity, leaving the identity-specific IAM data calls undiscovered.
- ✓
Update the existing trail to log data events for IAM.
Why this is correct
Updating the existing trail to log data events for IAM captures the exact API calls needed for the investigation, including GetUser, ListAccessKeys, GetLoginProfile, and other IAM data-plane operations. By default, a trail only records management events, so these data events are absent unless you explicitly add an event selector for the IAM resource type. Doing this on the existing trail preserves the current delivery configuration and eliminates the need for a separate, redundant trail, giving investigators a direct, complete audit of the user's activity.
- ✗
Create a new trail that logs data events for S3 and configure it to deliver to a separate S3 bucket.
Why it's wrong here
Creating a separate trail that logs S3 data events would capture object-level operations such as GetObject and PutObject, which are irrelevant to an IAM principal compromise. S3 data events are typically high-volume and would add significant noise while still omitting the IAM data events (like ListAccessKeys) that the investigation actually requires. The problem is not an S3 access anomaly, so adding a second trail for S3 does not address the gap; the correct fix is to enable IAM data events on the existing trail.
- ✗
Enable CloudTrail Insights to detect unusual activity for the user.
Why it's wrong here
CloudTrail Insights uses machine learning on the existing trail's management events to detect anomalous patterns, such as unusual API call rates or abnormal access key usage, but it does not broaden the set of recorded event types. Because IAM data events are not written to the trail by default, Insights has no additional data to analyze and cannot surface calls like GetUser or ListAccessKeys. Enabling Insights may be a useful complement for future anomaly detection, but it cannot retroactively provide the missing data-event history needed for this investigation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.