Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is investigating a potential security incident. They suspect that an IAM user's credentials were compromised and used to launch EC2 instances in a region where the user normally does not operate. Which AWS service can help the engineer identify the source IP address and user agent of the API calls that launched the instances?

⚠ Common exam trap

Watch out — candidates often confuse CloudTrail with CloudWatch or other monitoring services, but CloudTrail is the only service that records the source IP and user agent of API calls, while CloudWatch focuses on metrics and logs from resources, not API call metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including the source IP address, user agent, and the identity of the caller. By examining CloudTrail logs for the `RunInstances` event, the engineer can identify the exact source IP address and user agent used to launch the EC2 instances, even if the region is unusual for the user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    CloudHSM is a hardware security module service that provides secure key storage and cryptographic operations, not a logging or monitoring service. It doesn't record API calls or user activity events like source IPs or user agents. Thus it cannot be used to investigate security incidents by reviewing API activity logs.

  • ✓

    AWS CloudTrail

    Why this is correct

    CloudTrail is the correct answer because it records API activity across AWS accounts, capturing details like source IP address, user agent, request parameters, and response elements. This enables security engineers to investigate potential security incidents by correlating who made the call, from what IP, and with what tool. CloudTrail events provide the forensic evidence needed to trace actions.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not API activity. It doesn't log who made API calls or from which IP. While it may help identify security weaknesses, it doesn't provide the audit trail required for investigating an active incident's actions.

  • ✗

    AWS Artifact

    Why it's wrong here

    AWS Artifact is a self-service portal for accessing AWS compliance reports and agreements, such as SOC reports and ISO certifications. It doesn't capture or store any operational logs or API activity. Therefore, it wouldn't help an engineer investigate a potential security incident involving specific user actions.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.