Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is investigating a potential security incident involving an EC2 instance that was used to launch an outbound DDoS attack. The engineer needs to determine the source of the attack and the commands executed on the instance. Which logs should be analyzed?

⚠ Common exam trap

Candidates often assume VPC Flow Logs or CloudTrail alone are sufficient, but they fail to recognize that OS-level logs are required to see actual commands executed on the instance, which CloudTrail never captures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EC2 instance OS logs (e.g., /var/log/secure) and CloudTrail logs for API calls that launched the instance

The EC2 instance's OS logs (e.g., auditd logs, bash history) contain the exact commands executed and user authentication events, which are essential for identifying the source and actions of the attacker. CloudTrail logs for API calls that launched the instance provide the identity of the principal (IAM user/role), source IP, and the time the instance was created, linking the instance to the initiating entity. Together, these logs allow the engineer to trace both the operational commands on the instance and the administrative actions that created it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs and Network ACL logs

    Why it's wrong here

    VPC Flow Logs capture only network-layer metadata—source/destination IP, ports, protocol, and whether the packet was accepted or rejected—not the application payload or guest OS command input. A 'Network ACL log' does not exist as a service; Network ACLs themselves are stateless filters and do not emit logs. Therefore, this pair cannot reveal what commands were executed inside the instance, so it fails the investigation requirement.

  • ✓

    EC2 instance OS logs (e.g., /var/log/secure) and CloudTrail logs for API calls that launched the instance

    Why this is correct

    This is correct because the two data sources complement each other: EC2 OS logs (e.g., /var/log/secure on Linux, or Windows Event Logs) record interactive logins, sudo usage, and command execution on the guest OS, while CloudTrail logs the RunInstances API call, identifying the IAM principal, source IP, and timestamp of instance launch. Together they give you both the actor who created the instance and the subsequent commands run within it, enabling a full forensic timeline of the security incident.

  • ✗

    S3 server access logs and CloudWatch Logs

    Why it's wrong here

    S3 server access logs record requests made to an S3 bucket, which has no bearing on what was executed on an EC2 instance unless the instance was specifically interacting with that bucket. CloudWatch Logs can contain OS logs only if you have installed and configured the CloudWatch Logs agent or unified CloudWatch agent on the instance; it does not collect /var/log/secure by default. Even if OS logs were present, this combination would not link them to the IAM identity that launched the instance, so it is missing the actor attribution the investigation needs.

  • ✗

    AWS CloudTrail and AWS Config history

    Why it's wrong here

    CloudTrail logs AWS API calls, such as RunInstances or SendCommand, and AWS Config records configuration changes (e.g., instance type, security groups, AMI), but neither captures the actual commands entered into the guest OS shell. For example, a user could launch an instance via the console and then run arbitrary commands over SSH—those commands appear only in OS-level audit logs, not in CloudTrail or Config. Thus this pair provides the 'who created it' and 'what changed' but not the 'what command was executed inside it,' leaving a critical gap.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.