SCS-C02 Management and Security Governance Practice Question
A security engineer is investigating a potential data exfiltration incident. The engineer notices that an EC2 instance in a private subnet is making outbound connections to an external IP address on port 443. The VPC has a NAT gateway in a public subnet, and the route table for the private subnet directs 0.0.0.0/0 to the NAT gateway. The security group for the instance allows all outbound traffic. Which AWS service can the engineer use to determine which IAM role or user is responsible for launching the instance?
⚠ Common exam trap
SCS-C02 often tests the difference between network-level logs (VPC Flow Logs) and API-level audit logs (CloudTrail), so candidates pick Flow Logs when the question asks about identity attribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records API activity, including the RunInstances call that launched the EC2 instance, along with the identity (IAM user or role) that made the request. By querying CloudTrail events for the instance ID, the engineer can determine which principal launched it. This directly answers the attribution question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is a resource-centric service that records configuration items and compliance history for resources such as EC2 instances, security groups, and volumes. While it would show that a new instance appeared in your account and track subsequent configuration changes, its data model does not include the IAM principal, source IP, or API request context that initiated the RunInstances call. Therefore, AWS Config can tell you what changed but not who performed the action, making it insufficient for investigating the identity behind a potential data exfiltration.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture network-level metadata about IP traffic at the elastic network interface level, including source/destination IP addresses, ports, protocols, and byte counts. They might reveal large outbound transfers to an external endpoint, which could indicate data exfiltration, but they contain no identity information about the IAM user or role that launched the EC2 instance. Flow logs cannot attribute the RunInstances API call to a specific user, so they are not the right service for determining who initiated the instance launch.
- ✗
IAM Access Analyzer
Why it's wrong here
IAM Access Analyzer is designed to analyze resource policies, such as S3 bucket policies, KMS key policies, and IAM role trust policies, to identify resources that are shared with external principals. It does not record or query historical API calls, and it cannot show who performed a specific action like RunInstances. At most, Access Analyzer might reveal that an S3 bucket is publicly accessible, which could be a pathway for exfiltration, but it provides no audit trail of the user identity behind instance launches or other API events.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the authoritative audit service for API activity in AWS, and it records RunInstances as a management event. Each CloudTrail event includes the userIdentity object with the IAM principal, role, or assumed-role session, along with sourceIPAddress, eventTime, userAgent, requestParameters, and responseElements containing the new instance IDs. By searching CloudTrail logs for RunInstances events, the security engineer can directly identify which IAM user or role launched the instance, enabling attribution and further investigation of the alleged data exfiltration.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.