Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential security incident involving an Amazon RDS database. The engineer needs to determine if someone attempted to access the database with incorrect credentials. Which AWS service should the engineer use to view authentication failures?

⚠ Common exam trap

Candidates often confuse AWS CloudTrail (which logs API calls) with database-level authentication logging, assuming CloudTrail captures all security events, but it does not log database engine authentication failures because those occur within the database session, not through the AWS API.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon RDS database logs (error logs)

Amazon RDS database error logs capture authentication failures, including attempts with incorrect credentials, because the database engine itself logs these events. For example, MySQL's error log records 'Access denied for user' messages, and PostgreSQL's log records 'FATAL: password authentication failed' entries. This makes RDS database logs the direct source for viewing authentication failures at the database level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a managed log aggregation and monitoring service, not a primary source of database authentication records. While Amazon RDS can stream database error logs to CloudWatch Logs, this streaming must be explicitly configured first; without it, CloudWatch Logs will not contain the 'Access denied' events. Additionally, CloudWatch Logs itself generates operational logs for log groups and delivery, but it does not natively record database logins. Thus, the correct place to investigate is the RDS error log itself, not the CloudWatch Logs destination.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture network-level metadata about IP traffic, such as source and destination addresses, ports, protocol, and whether the packet was accepted or rejected. They do not inspect application payloads, so they cannot distinguish a successful database login from a failed one, nor do they contain username or authentication error strings. While a flow log might show a TCP connection to port 3306 or 5432, it will not reveal that a specific user failed to authenticate. Therefore, VPC Flow Logs are irrelevant for investigating authentication failures within the database engine.

  • ✓

    Amazon RDS database logs (error logs)

    Why this is correct

    Amazon RDS database logs, specifically the error log, are the authoritative source for database-level authentication failure entries. For example, MySQL error logs record messages like 'Access denied for user 'alice'@'host' (using password: YES)' for each failed login, and PostgreSQL logs similarly capture 'FATAL: password authentication failed for user 'alice''. These logs are generated by the database engine itself and are accessible through the RDS console, the DescribeDBLogFiles API, or by streaming them to Amazon CloudWatch Logs. Because the question is about database authentication attempts, the RDS error log directly contains the required evidence.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records control-plane API calls made to the AWS RDS service, such as CreateDBInstance, ModifyDBInstance, or DescribeDBLogFiles, along with the identity of the IAM user or role making the call. However, CloudTrail does not capture the internal database activity that occurs within a database instance, including SQL queries, logins, or authentication failures. A botched database login using a database username and password happens entirely inside the database engine and is never translated into an AWS API call. Therefore, while CloudTrail might show when someone accessed the RDS API, it cannot show the database-level 'Access denied' events that indicate authentication failures.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.