Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential compromise of an EC2 instance. The engineer needs to capture network traffic to and from the instance for forensic analysis. Which AWS service should be used to capture this traffic?

⚠ Common exam trap

It's easy for candidates to confuse VPC Traffic Mirroring with AWS Network Firewall, assuming that a firewall inherently captures traffic, but Network Firewall only inspects and filters traffic in-line without providing a separate packet capture stream for forensic analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Traffic Mirroring

VPC Traffic Mirroring captures and inspects network traffic at the Elastic Network Interface (ENI) level by copying packets from a source ENI to a target, such as a Network Load Balancer or another ENI. This allows the security engineer to perform deep packet inspection and forensic analysis without impacting the production traffic flow. It supports both IPv4 and IPv6 traffic and can filter by protocol, port, or packet direction, making it ideal for incident response scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a service that records and evaluates configuration changes to resources like EC2 security groups, IAM policies, and VPC settings. While it can help identify misconfigurations or drift that might have contributed to a compromise, it does not capture or inspect actual network traffic flows or packet payloads. Thus, it cannot provide the raw network data needed for deep investigation of a suspected breach.

  • ✗

    AWS Network Firewall

    Why it's wrong here

    AWS Network Firewall is a stateful managed firewall that inspects traffic at the VPC level using Suricata-based rules, and can generate alert logs via Amazon S3, CloudWatch, or Kinesis. However, its primary function is to allow or deny traffic based on policy; it does not provide full packet capture or a deep packet capture repository for retrospective forensic analysis. While it may log flow details or intrusion alerts, it is not designed to mirror raw traffic for a separate analysis tool.

  • ✓

    VPC Traffic Mirroring

    Why this is correct

    VPC Traffic Mirroring copies the full packet content from one or more elastic network interfaces (ENIs) of an EC2 instance and forwards it to a target such as a security appliance, an NLB, or an ENI that hosts a packet capture tool. This gives investigators the raw traffic needed to detect and analyze anomalies, lateral movement, or exfiltration without affecting the workload's primary network path. It is the correct choice when the goal is to capture and inspect actual network packets for a suspected compromise.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that continuously scans workloads for software vulnerabilities and network reachability issues, producing risk scores based on CVEs and the Common Vulnerability Scoring System. It evaluates the security state of a resource but does not ingest or retain live network traffic, so it cannot be used to examine the contents of communications that occurred during an incident. For forensic packet analysis, a packet-capture mechanism would be required.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.