Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential data exfiltration incident where an EC2 instance is sending large volumes of data to an unknown IP address. Which AWS service should the engineer use to capture and analyze the network traffic for evidence?

⚠ Common exam trap

Test-takers frequently confuse VPC Traffic Mirroring with VPC Flow Logs, but Flow Logs only capture metadata (source/destination IP, ports, protocol, packet count) and not the actual packet payloads, making them insufficient for evidence of data exfiltration content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Traffic Mirroring

VPC Traffic Mirroring is the correct choice because it allows you to capture and inspect network traffic from an EC2 instance by mirroring the traffic to a monitoring appliance or a security tool. This enables deep packet inspection to analyze the contents of the data being sent to the unknown IP address, providing evidence for data exfiltration. Unlike other services, Traffic Mirroring operates at the network level, copying all packets (including payloads) without affecting the source instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a Layer 7 web application firewall that inspects HTTP/HTTPS requests forwarded to Amazon CloudFront, Application Load Balancer, or API Gateway, applying rules to block common attack signatures; it is not a packet capture service. It lacks the ability to mirror full network packets or record raw network flows from an EC2 instance, and it only sees permitted web protocol traffic at configured ingress points, not arbitrary outbound traffic such as DNS or C2 channels. Thus, while WAF logs can show blocked or allowed web requests, they cannot be used to reconstruct or analyze a data exfiltration stream that may occur over non-HTTP protocols.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is a managed distributed denial-of-service (DDoS) protection service—Standard is always-on for CloudFront, Route 53, and elastic load balancers, while Advanced adds enhanced detection, cost protection, and DDoS response. Its purpose is to detect and mitigate volumetric, state-exhaustion, or application-layer attacks that aim to overwhelm availability, not to capture or inspect all network traffic for forensic investigation. Shield does not provide packet capture, traffic mirroring, or content-level visibility into EC2 network flows, so even if an attack is inferred, it cannot reveal data exfiltration payloads. Data exfiltration is often low-and-slow and specifically not a high-volume DDoS event, making Shield the wrong tool for this investigation.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that continuously scans EC2 instances and container images for software vulnerabilities (CVEs), unintended network exposure, and deviations from security best practices (e.g., CIS benchmarks). It generates findings based on agent-based assessments and network reachability analysis, but it does not capture, log, or store network traffic packets between instances or to external destinations. Even if Inspector identified a vulnerable package or an open port on an instance, it cannot provide the raw traffic evidence needed to determine whether data was actually exfiltrated and what was sent. Its snapshot-style assessment is fundamentally different from a network forensic capture tool like VPC Traffic Mirroring.

  • ✓

    VPC Traffic Mirroring

    Why this is correct

    VPC Traffic Mirroring captures IP traffic flowing to and from an EC2 instance's elastic network interface and copies it to a chosen destination—such as a security appliance or a workload running another ENI—for inspection and storage. It supports both inbound and outbound traffic, can mirror multiple ENIs, and allows filtering by protocol, source, destination, port, or TCP flags, enabling the security engineer to focus on suspicious or unauthorized transfers. Unlike the other services, it provides full packet contents, not just metadata or aggregated flow logs, so it is the appropriate method to investigate and potentially prove data exfiltration from a compromised instance. Note, it is not a native log store; the mirrored traffic must be sent to a tool like a network analyzer or a custom capture environment, but that is exactly why it is suitable for an in-depth forensic investigation.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.