SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating a potential data exfiltration from an S3 bucket. The engineer needs to identify which IAM role or user accessed the bucket and from which IP address. Which AWS service should the engineer use to obtain this information?
⚠ Common exam trap
Watch out — candidates often confuse VPC Flow Logs (which show network traffic but not user identity) with CloudTrail (which shows API calls with identity), leading them to select VPC Flow Logs for IP-based investigation without realizing they need the IAM role or user context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made to S3, including the IAM role or user identity (via the `userIdentity` field) and the source IP address (via the `sourceIPAddress` field). For data exfiltration investigation, you need these specific details from management events or data events (e.g., `GetObject`, `PutObject`), which CloudTrail captures. Other services either lack identity-level detail or focus on network-level traffic without user attribution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct choice because, for S3 data-plane operations, it logs every API request — including GetObject, PutObject, and ListObjects — with the authenticated IAM principal, source IP, user agent, and the bucket/key requested. Management events like bucket policy changes are also captured. This enables a security engineer to trace exactly who accessed and extracted objects, and when, providing the access-level history needed to investigate exfiltration.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration tracking service, not an audit log of API activity. It records state changes of resources such as an S3 bucket's encryption settings, lifecycle policy, or bucket policy, but it does not record individual API calls like GetObject or the identity of the caller. While a sudden bucket policy change could be a precursor to exfiltration, Config cannot show who downloaded objects or from which IP.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs operate at the network layer, capturing ENI traffic metadata including source/destination IP, port, protocol, and packet counts. They do not contain the IAM principal, the S3 API operation, or the object key, and traffic to S3 may traverse an S3 gateway endpoint or public internet, losing application context. Flow logs can show a connection to S3's endpoint, but cannot attribute that connection to a specific user or confirm any data was actually retrieved.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty provides intelligent threat findings by analyzing CloudTrail logs, VPC Flow Logs, and DNS logs, and it will alert on anomalous S3 access patterns, such as unusual downloads from a bucket. However, a GuardDuty finding only points to the suspicious event; it does not replace the underlying CloudTrail data event log containing each request, principal, and object. To perform a thorough forensics, you still need to inspect CloudTrail records, making GuardDuty a detection layer rather than a raw access log.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.