Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential data exfiltration incident. The engineer notices that an EC2 instance with an attached IAM role has been making API calls to an S3 bucket in another AWS account. The engineer wants to identify the source of the API calls and determine if the calls are malicious. Which AWS service should the engineer use to view the API calls made by the IAM role?

⚠ Common exam trap

Candidates often confuse VPC Flow Logs (which show network traffic) with CloudTrail (which shows API calls), or they assume GuardDuty provides raw logs instead of just alerts, leading them to pick a service that cannot directly answer the question of viewing the specific API calls made by the IAM role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made by IAM roles, including the source IP address, user agent, and the specific actions performed. In this scenario, CloudTrail logs will show the exact API calls made by the EC2 instance's IAM role to the S3 bucket in another account, enabling the security engineer to identify the source and determine if the calls are malicious.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs record packet headers between network interfaces, so they show that traffic reached S3 endpoints but never the IAM role identity or API action. They are tempting for tracing exfiltration paths, and would be correct for confirming connectivity, data volume or rejected connections at the network layer.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty produces its own findings from analysed telemetry; it does not let an engineer query the raw API call records needed to attribute specific calls to the IAM role. It is tempting because it surfaces exfiltration and credential-abuse findings, and would suit continuous detection rather than retrospective investigation.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and compliance against rules; it does not store API call events, so it cannot show which principal invoked S3 operations. It is tempting for auditing resource state, and would be correct for detecting an S3 bucket policy change or an unencrypted bucket.

  • ✓

    AWS CloudTrail

    Why this is correct

    CloudTrail records every API call, capturing the IAM role's identity, source IP, timestamp and requested S3 action. This lets the engineer trace the cross-account calls back to the specific EC2 instance and assess whether the pattern indicates malicious exfiltration.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.