SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating a potential credential compromise. An IAM user's access key was used to launch EC2 instances in a region where the user has never operated before. The engineer wants to quickly identify all API calls made by this user in the last 24 hours, including the source IP addresses. Which AWS service or feature should be used?
⚠ Common exam trap
Watch out — candidates often confuse VPC Flow Logs (network-level traffic) with CloudTrail (API-level activity), mistakenly thinking flow logs can identify which IAM user performed an action, when in fact flow logs only show IP addresses and ports without user identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made by IAM users, including the source IP address, user identity, and request details. By querying CloudTrail logs for the specific IAM user's access key over the last 24 hours, the engineer can identify every EC2-related and other API call, along with the originating IP addresses, enabling rapid investigation of the potential credential compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the authoritative audit trail for AWS API activity, recording every management and data event with the invoking IAM identity, source IP address, user agent, and timestamp. For a credential investigation, CloudTrail lets you reconstruct exactly which programmatic or console actions were performed with the suspected credentials, including failed authentication attempts and sign-in events from the us-east-1 region. It can also be configured to deliver those immutable logs to S3 for long-term forensics and to CloudWatch Logs for real-time alerting, making it the primary service to answer 'who did what, when, and from where'.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic passing through VPC network interfaces, such as source and destination IP addresses, ports, protocol, and bytes transferred. They do not record the API request's content, the authenticated IAM identity, or the specific AWS operation performed, so they cannot directly reveal which credentials were used or what actions were attempted. Even if a malicious credential is used, Flow Logs might only show a network connection to an AWS API endpoint, offering no forensic detail about the call itself.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor provides point-in-time assessments and recommendations across cost optimization, performance, security, and fault tolerance, using checks such as leaked IAM access keys or overly permissive security groups. It does not maintain a historical log of API calls or user authentication events, so it cannot be used to trace how a credential was used or when it may have been compromised. In an investigation, Trusted Advisor can flag that a credential is publicly exposed or that IAM key rotation is overdue, but it offers no event-level audit data.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized log storage and analysis service, but it does not natively ingest or generate AWS API call records. To get API activity into CloudWatch Logs, a security engineer must explicitly configure AWS CloudTrail to deliver management and data events to a CloudWatch Logs log group, or have applications ship their own logs via an agent — without that setup, no credential usage history exists there. While useful for monitoring or searching CloudTrail-delivered events, it is only a downstream consumer and cannot serve as the primary forensic source for investigating credential misuse.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.