Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is investigating a potential security incident. Which TWO AWS services can be used to analyze historical network traffic patterns? (Choose TWO.)

⚠ Common exam trap

Many exam-takers confuse CloudWatch Logs (a storage/monitoring service) with Athena (a query service), or mistakenly think CloudTrail captures network traffic data instead of API activity, leading them to select CloudWatch Logs or CloudTrail instead of Athena.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Flow Logs

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, packet/byte counts) for network interfaces in a VPC. They are stored in Amazon CloudWatch Logs or Amazon S3, enabling historical analysis of network traffic patterns. Athena can query VPC Flow Logs stored in S3 using SQL, making it a powerful tool for analyzing historical traffic patterns at scale.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous, real-time threat detection service that ingests VPC Flow Logs, CloudTrail events, and DNS logs to identify suspicious behavior and generate findings. It does not retain the underlying raw flow data for historical ad-hoc analysis, nor does it offer a query interface to reconstruct past traffic patterns beyond the alerts it already generated. Therefore, while GuardDuty can indicate that a threat occurred, it cannot serve as a data source for a retrospective investigation of network flows.

  • ✓

    VPC Flow Logs

    Why this is correct

    VPC Flow Logs capture IP traffic metadata—source and destination addresses, ports, protocol, packet and byte counts, and allow/deny actions—for traffic reaching network interfaces in your VPC. When published to Amazon S3, these logs become a durable, queryable history that can be analyzed with Athena using standard SQL to reconstruct past network behavior, such as whether an instance communicated with a suspicious host. This makes VPC Flow Logs the correct and most direct source for retrospective network traffic analysis.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a log collection, storage, and monitoring service that can receive VPC Flow Logs, CloudTrail events, and application logs, but it is not purpose-built for historical ad-hoc analysis of network traffic. While CloudWatch Logs Insights can run limited queries against ingested logs, it does not provide the full SQL flexibility that Athena offers over raw flow log files, and default retention policies may age out relevant data. If VPC Flow Logs were not delivered to CloudWatch Logs, the service would contain no network traffic data to analyze at all.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records control-plane API actions—such as RunInstances, CreateSubnet, or AuthorizeSecurityGroupIngress—along with the caller's identity, source IP, and timestamps. It captures management-plane activity, not the data-plane traffic that actually flows between instances or from a workload to the internet. Therefore, CloudTrail can reveal who made a configuration change during the incident window, but it cannot reconstruct the historical network connections required to analyze the security issue.

  • ✓

    Amazon Athena

    Why this is correct

    Amazon Athena can query VPC Flow Logs stored in Amazon S3 using standard SQL, enabling retrospective analysis of historical network traffic patterns. This satisfies the stem’s requirement to analyse past traffic without requiring pre-configured monitoring, as Athena directly parses the raw log data for ad‑hoc investigation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.