Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is investigating a potential data exfiltration incident. The engineer notices that an EC2 instance in a private subnet is making outbound connections to an external IP address on port 443. The VPC has a NAT gateway in a public subnet, and the route table for the private subnet directs 0.0.0.0/0 to the NAT gateway. The security group for the instance allows all outbound traffic. Which AWS service can the engineer use to determine which IAM role or user is responsible for launching the instance?

⚠ Common exam trap

SCS-C02 often tests the difference between network-level logs (VPC Flow Logs) and API-level audit logs (CloudTrail), so candidates pick Flow Logs when the question asks about identity attribution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail records API activity, including the RunInstances call that launched the EC2 instance, along with the identity (IAM user or role) that made the request. By querying CloudTrail events for the instance ID, the engineer can determine which principal launched it. This directly answers the attribution question.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a resource-centric service that records configuration items and compliance history for resources such as EC2 instances, security groups, and volumes. While it would show that a new instance appeared in your account and track subsequent configuration changes, its data model does not include the IAM principal, source IP, or API request context that initiated the RunInstances call. Therefore, AWS Config can tell you what changed but not who performed the action, making it insufficient for investigating the identity behind a potential data exfiltration.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture network-level metadata about IP traffic at the elastic network interface level, including source/destination IP addresses, ports, protocols, and byte counts. They might reveal large outbound transfers to an external endpoint, which could indicate data exfiltration, but they contain no identity information about the IAM user or role that launched the EC2 instance. Flow logs cannot attribute the RunInstances API call to a specific user, so they are not the right service for determining who initiated the instance launch.

  • ✗

    IAM Access Analyzer

    Why it's wrong here

    IAM Access Analyzer is designed to analyze resource policies, such as S3 bucket policies, KMS key policies, and IAM role trust policies, to identify resources that are shared with external principals. It does not record or query historical API calls, and it cannot show who performed a specific action like RunInstances. At most, Access Analyzer might reveal that an S3 bucket is publicly accessible, which could be a pathway for exfiltration, but it provides no audit trail of the user identity behind instance launches or other API events.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the authoritative audit service for API activity in AWS, and it records RunInstances as a management event. Each CloudTrail event includes the userIdentity object with the IAM principal, role, or assumed-role session, along with sourceIPAddress, eventTime, userAgent, requestParameters, and responseElements containing the new instance IDs. By searching CloudTrail logs for RunInstances events, the security engineer can directly identify which IAM user or role launched the instance, enabling attribution and further investigation of the alleged data exfiltration.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.