Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential incident where an EC2 instance was compromised. The engineer has access to the following logs: CloudTrail, VPC Flow Logs, and OS-level logs from the instance. Which TWO log sources would be MOST useful to determine the initial attack vector? (Choose TWO.)

⚠ Common exam trap

The trap here is that candidates often pick VPC Flow Logs (option E) thinking network traffic will show the attack vector, but flow logs only show metadata like IP addresses and ports, not the authentication success or API calls that actually prove how the attacker got in.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OS-level authentication and system logs

OS-level authentication and system logs (option B) are critical because they record local login attempts, sudo commands, and process executions that can reveal how an attacker gained initial access—such as via SSH brute force, a compromised user account, or a vulnerable service. CloudTrail logs (option C) are equally important because they capture API calls made to AWS services, including RunInstances, CreateKeyPair, and ModifySecurityGroup, which can show if the attacker launched the instance from a compromised AWS account or modified security groups to allow inbound traffic. Together, these two sources provide the evidence needed to trace the initial compromise vector, whether it originated from within the OS or through AWS API manipulation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch Metrics for the instance

    Why it's wrong here

    Amazon CloudWatch Metrics provide only numerical time-series data, such as CPU utilization, disk I/O, and network throughput, which are aggregated into 1-minute or 5-minute periods. Even with detailed monitoring, they do not capture login attempts, executed commands, or file modifications—the forensic evidence needed to identify how an attacker gained access. While metrics can highlight an anomaly like a CPU spike, they are far too coarse to reveal the attack vector, making them unsuitable for incident investigation.

  • ✓

    OS-level authentication and system logs

    Why this is correct

    OS-level authentication and system logs (e.g., /var/log/auth.log on Linux or the Security Event Log on Windows) record each successful and failed login attempt, source IP, user account, timestamp, and sudo/su command usage. These logs can directly expose the initial access vector, such as an SSH brute-force attack or a compromised credential, and also trace post-exploitation actions like privilege escalation. Because they reside on the instance itself, they contain ground-truth details about what actually occurred inside the compromised system, which no AWS service-level log can provide.

  • ✓

    AWS CloudTrail logs

    Why this is correct

    AWS CloudTrail records all EC2 control-plane API calls, such as RunInstances, with the requesting IAM user or role, source IP address, user agent, and full request parameters. This allows a security engineer to determine exactly who launched the instance and from where, which is critical if the instance was spawned by an attacker using stolen credentials. However, CloudTrail does not capture activities inside the instance after boot, so it is a vital complement to OS logs rather than a substitute for them.

  • ✗

    AWS Config configuration history

    Why it's wrong here

    AWS Config tracks configuration changes to AWS resources over time, such as security group rule modifications, instance type changes, or tag updates, and maintains a timeline of those states for compliance auditing. While it could show that a security group was opened to the internet hours before the incident, it does not contain any authentication attempts, command execution, or attacker movement within the instance. Config history is therefore useful for understanding infrastructure evolution but cannot reveal the initial compromise vector or the attacker's actions on the host.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic at the network interface level, including source and destination addresses, ports, protocols, and byte counts, but they do not perform deep packet inspection or payload analysis. A flow log might show a burst of connections from a suspicious IP, yet it cannot tell whether that traffic was a successful exploit, a brute-force login, or benign scanning. This lack of application-layer context means flow logs alone cannot prove maliciousness or identify the specific attack vector that compromised the instance.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.