SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is investigating a potential security incident. Which TWO AWS services can be used to analyze historical network traffic patterns? (Choose TWO.)
⚠ Common exam trap
Many exam-takers confuse CloudWatch Logs (a storage/monitoring service) with Athena (a query service), or mistakenly think CloudTrail captures network traffic data instead of API activity, leading them to select CloudWatch Logs or CloudTrail instead of Athena.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Flow Logs
VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, packet/byte counts) for network interfaces in a VPC. They are stored in Amazon CloudWatch Logs or Amazon S3, enabling historical analysis of network traffic patterns. Athena can query VPC Flow Logs stored in S3 using SQL, making it a powerful tool for analyzing historical traffic patterns at scale.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a continuous, real-time threat detection service that ingests VPC Flow Logs, CloudTrail events, and DNS logs to identify suspicious behavior and generate findings. It does not retain the underlying raw flow data for historical ad-hoc analysis, nor does it offer a query interface to reconstruct past traffic patterns beyond the alerts it already generated. Therefore, while GuardDuty can indicate that a threat occurred, it cannot serve as a data source for a retrospective investigation of network flows.
- ✓
VPC Flow Logs
Why this is correct
VPC Flow Logs capture IP traffic metadata—source and destination addresses, ports, protocol, packet and byte counts, and allow/deny actions—for traffic reaching network interfaces in your VPC. When published to Amazon S3, these logs become a durable, queryable history that can be analyzed with Athena using standard SQL to reconstruct past network behavior, such as whether an instance communicated with a suspicious host. This makes VPC Flow Logs the correct and most direct source for retrospective network traffic analysis.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a log collection, storage, and monitoring service that can receive VPC Flow Logs, CloudTrail events, and application logs, but it is not purpose-built for historical ad-hoc analysis of network traffic. While CloudWatch Logs Insights can run limited queries against ingested logs, it does not provide the full SQL flexibility that Athena offers over raw flow log files, and default retention policies may age out relevant data. If VPC Flow Logs were not delivered to CloudWatch Logs, the service would contain no network traffic data to analyze at all.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records control-plane API actions—such as RunInstances, CreateSubnet, or AuthorizeSecurityGroupIngress—along with the caller's identity, source IP, and timestamps. It captures management-plane activity, not the data-plane traffic that actually flows between instances or from a workload to the internet. Therefore, CloudTrail can reveal who made a configuration change during the incident window, but it cannot reconstruct the historical network connections required to analyze the security issue.
- ✓
Amazon Athena
Why this is correct
Amazon Athena can query VPC Flow Logs stored in Amazon S3 using standard SQL, enabling retrospective analysis of historical network traffic patterns. This satisfies the stem’s requirement to analyse past traffic without requiring pre-configured monitoring, as Athena directly parses the raw log data for ad‑hoc investigation.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.