Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is investigating a potential security incident involving an EC2 instance. The engineer needs to determine if any unauthorized SSH keys were added to the instance's authorized_keys file. Which AWS service should be used to detect this change?

⚠ Common exam trap

Many candidates confuse AWS CloudTrail's ability to track API-level changes (e.g., modifying an EC2 instance) with the need to monitor guest OS file changes, which requires a configuration management service like AWS Config, not CloudTrail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the correct service because it can be used to monitor configuration changes to EC2 instances, including changes to the authorized_keys file when integrated with AWS Systems Manager. While AWS Config does not natively track guest OS file changes, you can create a custom AWS Config rule that invokes a Lambda function to check the instance's Systems Manager inventory or run a command to verify the file contents. CloudTrail tracks API calls but does not monitor internal OS changes. Amazon Inspector and GuardDuty focus on vulnerabilities and threats, not configuration changes. Therefore, AWS Config, with appropriate custom rules, is the best choice among the options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector performs automated vulnerability and network exposure assessments by scanning EC2 instances and container images against rule packages, but it does not maintain a file-level baseline or alert when file contents are changed. Its purpose is to identify missing patches, weak network configurations, and known CVEs, not to provide an audit trail of integrity modifications. Inspector therefore cannot answer the question of which files changed or when.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records an immutable trail of API activity across the AWS control plane, such as RunInstances, TerminateInstances, or AssumeRole calls, delivered as JSON event logs. It does not have direct visibility into an EC2 instance's operating system, user-level file edits, or binary content modifications because those events occur outside the AWS API layer. CloudTrail is useful for determining who made a management change to infrastructure, not for tracking file integrity on a launched instance.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty continuously analyzes VPC Flow Logs, DNS query logs, and CloudTrail management events, along with anomalous behavior models and threat intelligence, to detect suspicious activity indicative of a compromise. It has no native mechanism to register a file-manifest hash, compare checksums, or log when a file is altered by an OS process. Even if it flags indicators of compromise such as crypto mining or command-and-control traffic, it does not provide the file-forensics history needed to pinpoint unauthorized modifications.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is the correct service because it records configuration state changes and can track software and file inventory from managed instances through an integration with AWS Systems Manager Inventory. When SSM Inventory collects file attributes such as path, size, and modification time, AWS Config can use custom rules or advanced queries to flag deviations from a known-good baseline. This makes AWS Config the service that directly supports file-change audits and compliance enforcement in response to suspected tampering.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.