SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is investigating a potential security incident involving an EC2 instance. The engineer needs to capture network traffic to and from the instance for analysis. Which method should be used to capture this traffic without installing any software on the instance?
⚠ Common exam trap
Many exam-takers confuse VPC Flow Logs (metadata only) with full packet capture; candidates often pick VPC Flow Logs because they are a familiar logging feature, but they lack the payload data needed for deep packet analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use VPC Traffic Mirroring.
VPC Traffic Mirroring captures and inspects network traffic at the Elastic Network Interface (ENI) level without requiring any software installation on the EC2 instance. It copies traffic from a source ENI to a target, such as a Network Load Balancer or another ENI, for analysis by security appliances. This meets the requirement of capturing traffic without installing software on the instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable VPC Flow Logs for the subnet.
Why it's wrong here
VPC Flow Logs capture only flow-level metadata, such as source and destination IP addresses, ports, protocol, and packet/byte counts, plus the allow/deny action. They do not include the actual payload of the traffic, so an engineer cannot inspect content for malware, command-and-control payloads, or exfiltrated data. Therefore, enabling flow logs cannot substitute for full packet capture.
- ✗
Configure AWS Network Firewall in the VPC.
Why it's wrong here
AWS Network Firewall is a managed firewall service that performs stateful and stateless packet inspection, filtering, and intrusion prevention based on rules and Suricata-compatible rule groups. While it can log alerts and flow metadata, it is designed to block or allow traffic rather than to capture and store complete raw packets for forensic reconstruction. Thus it fails to provide the full packet content needed for this investigation.
- ✗
Install the Amazon CloudWatch agent on the instance.
Why it's wrong here
Installing the Amazon CloudWatch agent on the instance enables collection of operating-system metrics, logs, and even custom high-resolution metrics, but the agent does not tap the network interface or capture raw packets transiting the VPC. It runs at user space and only forwards metric/log data to CloudWatch, leaving packet payloads entirely invisible. Consequently, this option cannot yield the packet-level detail the engineer requires.
- ✓
Use VPC Traffic Mirroring.
Why this is correct
VPC Traffic Mirroring copies live traffic from Elastic Network Interfaces and forwards it to a chosen monitoring appliance or security tool, such as a customer-managed NGFW or packet analyzer, using VXLAN-encapsulated tunnels. It captures full packet content, including headers and payload, without requiring any software installation on the source instance and without impacting the production traffic path. This makes it the correct choice for deep packet inspection and forensic analysis of network traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.