Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is investigating a potential data breach. The engineer wants to analyze historical API calls made by a specific IAM user. Which TWO AWS services can be used together to achieve this? (Select TWO.)

⚠ Common exam trap

Many candidates confuse CloudWatch Logs Insights (a query tool) with CloudWatch Logs (the storage service), or mistakenly think S3 Server Access Logs or VPC Flow Logs can capture IAM user API activity, when in fact only CloudTrail records management-plane API calls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the service that records API activity across AWS accounts, including who made the call, the source IP address, and the time of the call. By enabling CloudTrail for the specific IAM user, the security engineer can retrieve a history of all API calls made by that user. CloudWatch Logs can then be used to store and query those CloudTrail logs for analysis, such as filtering by user ARN or event name.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S3 Server Access Logs

    Why it's wrong here

    S3 Server Access Logs contain detailed records of requests made directly to an S3 bucket—object-level GET, PUT, and DELETE actions, requester identity, and response status—but they do not capture management-plane calls such as IAM role changes, EC2 launches, or Lambda invocations. A data breach investigation needs a complete history of API activity across all services, so these logs are limited to S3 data-plane operations and cannot reveal broader attacker actions.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic traversing your VPC network interfaces—source and destination addresses, ports, protocol, and packet/byte counts—but they never include the identity of the caller, the access key used, or the API action invoked. They can show that a resource communicated with a malicious IP, but they cannot tell you which principal executed a destructive API call or what that call intended to do. Therefore, flow logs are network telemetry, not an API-activity audit trail.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the authoritative audit service because it logs every supported AWS API call (management events, and optionally data events) with the caller's IAM identity, source IP address, user agent, request parameters, and response elements. A CloudTrail event history can be delivered to an S3 bucket and subsequently ingested into CloudWatch Logs or Amazon Security Lake, making it the primary evidence source for reconstructing who did what during a breach. It is the correct service to use when investigating suspicious API activity.

  • ✗

    Amazon CloudWatch Logs Insights

    Why it's wrong here

    Amazon CloudWatch Logs Insights is a query engine that runs structured queries using a SQL-like syntax against log groups stored in CloudWatch Logs; it does not independently collect or record AWS API activity. It can be a powerful forensic tool for interrogating CloudTrail delivery log groups—for example, searching for specific IAM users, error codes, or source IPs—but it produces nothing unless CloudTrail is already streaming logs into CloudWatch Logs. As a standalone investigation service, it is not the source of truth for API calls.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs can be the destination where CloudTrail delivers its API activity trail, giving investigators a centralized, searchable log group with metric filters and subscription options for real-time alerting. Although CloudTrail is the original recorder of the API events, CloudWatch Logs is often the practical interface for querying and correlating those events during an incident. In this scenario, if you see the CloudTrail events in CloudWatch Logs, you can use it to investigate the breach, but it depends on CloudTrail integration.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.