SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is investigating a potential data exfiltration incident. They see that an EC2 instance with an IAM role is making API calls to S3 to download objects. The IAM role has an S3 bucket policy that allows access from that role. However, CloudTrail logs show that the calls are being made from an IP address outside the company's network. What is the most likely explanation?
⚠ Common exam trap
Many candidates assume the external IP is due to a NAT gateway or AWS service endpoint, but CloudTrail always logs the actual client IP, not the service endpoint IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role credentials were stolen and are being used from an external machine.
The CloudTrail logs show the API calls originating from an IP address outside the company's network, which indicates that the IAM role credentials (temporary security credentials from the instance metadata) have been compromised and are being used from an external machine. The S3 bucket policy allows access from the IAM role, but the source IP in the logs is external, confirming the credentials are being used outside the EC2 instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IAM role credentials were stolen and are being used from an external machine.
Why this is correct
The CloudTrail event shows the calls were made using the IAM role's temporary credentials but with a sourceIP address that does not match the EC2 instance's IP. Because the role's credentials are obtainable from the instance metadata service (IMDS), if an attacker gains access (e.g., via SSRF) they can extract the credentials and replay them from an external machine, making CloudTrail log that external source IP. This is a classic credential exfiltration scenario, and it explains why the identity is the role while the network origin is elsewhere.
- ✗
The EC2 instance has a public IP and the calls are originating from the instance itself.
Why it's wrong here
If the calls originated from the instance itself over the public S3 endpoint, CloudTrail would record the instance's public IP (or the public IP of the NAT gateway if used) as the sourceIP. An external IP that is not associated with the instance or any egress gateway contradicts this, because a single instance cannot present two different public source IPs for the same outbound requests. Therefore this option cannot explain the observed discrepancy.
- ✗
CloudTrail is logging the IP address of the AWS service endpoint, not the client.
Why it's wrong here
CloudTrail logs the sourceIP address of the actual API requester as determined from the TCP connection, not the IP of the AWS service endpoint that forwarded or processed the request. The endpoint receives the request but is not the originator, so CloudTrail never substitutes the endpoint's IP for the client's address. This misconception would incorrectly imply that all CloudTrail sourceIPs were identical AWS-owned addresses, which is not true.
- ✗
The S3 bucket policy allows public access.
Why it's wrong here
A bucket policy that allows public access would permit unauthenticated requests, and CloudTrail would then show a userIdentity with anonymous access or no role-based identity. The observed events, however, are authenticated with the IAM role's credentials, as evidenced by the role's ARN in the userIdentity field. Public policy grants access without credentials; it does not cause existing authenticated credentials to appear as coming from an external IP.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.