SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating a potential data breach. AWS CloudTrail logs show that an IAM user 'svc-backup' created an S3 bucket in the us-east-1 region and then uploaded a large number of objects. The engineer suspects that the user's credentials were compromised. What is the MOST efficient way to quickly identify the source IP address and user agent of the API calls made by this user?
⚠ Common exam trap
A common mix-up: candidates confuse VPC Flow Logs (which show network-level traffic) with CloudTrail logs (which show API-level activity), failing to recognize that only CloudTrail captures the IAM user identity and user agent required for this investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query AWS CloudTrail logs in Amazon Athena for the user's API calls.
CloudTrail logs capture detailed records of all API calls, including the source IP address and user agent for each request. By querying these logs with Amazon Athena, the security engineer can efficiently filter for the specific IAM user 'svc-backup' and extract the source IP and user agent from the relevant event records, enabling rapid identification of the compromised credentials' origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Query AWS CloudTrail logs in Amazon Athena for the user's API calls.
Why this is correct
AWS CloudTrail records every S3 management and data event, including the IAM user or role, sourceIPAddress, userAgent, event name, and request parameters, and it delivers these logs as gzipped JSON to an S3 bucket. Amazon Athena can run SQL queries directly against that CloudTrail log set, allowing you to quickly filter for a specific user's API calls over a time range and correlate source IPs, user agents, and event names to determine the scope of the breach. This is the standard, authoritative method for investigating API-level activity after an incident.
- ✗
Analyze VPC Flow Logs for traffic to the S3 bucket.
Why it's wrong here
VPC Flow Logs only capture network-level metadata for traffic traversing ENIs, such as source/destination IP, port, and packet counts, but they contain no IAM principal information, API operation names, or S3 request parameters. Because S3 access uses HTTPS, flow logs would only show TCP 443 connections to an S3 endpoint IP, leaving you unable to identify which user made which call or what action was attempted. This makes them unsuitable for tracing a specific user's API activity.
- ✗
Enable Amazon GuardDuty and review the generated findings.
Why it's wrong here
Amazon GuardDuty is a threat-detection service that analyzes telemetry from sources like DNS logs, VPC Flow Logs, and CloudTrail management events to produce curated findings about suspicious behavior. It does not retain the full, historically queryable record of every API call with request-level detail that a forensic investigation requires, and enabling it after the fact will not retroactively generate findings for past activity. It may supplement an investigation, but it cannot replace querying the raw CloudTrail log archive.
- ✗
Use AWS Config to review the configuration history of the S3 bucket.
Why it's wrong here
AWS Config tracks resource configuration changes and evaluates compliance over time, producing a configuration history for resources such as an S3 bucket (for example, policy changes or encryption settings) but it does not capture who made the change or the underlying API call details. It might show that a bucket policy was altered at a particular timestamp, but it will not reveal the principal's identity, the source IP, or the exact API action that triggered the change. Therefore, it cannot tell you which user made which API calls or where the calls originated.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.