SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating an AWS CloudTrail log entry that shows an unauthorized API call to delete an S3 bucket. Which service should the engineer use to analyze the log data for patterns of similar malicious activity?
⚠ Common exam trap
The trap is that candidates may choose GuardDuty because it is a threat detection service, but the question specifically asks for a service the engineer should use to analyze log data. That is a manual query task, which CloudWatch Logs Insights handles, not GuardDuty.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs Insights
Amazon CloudWatch Logs Insights is the service designed for interactively querying and analyzing log data stored in CloudWatch Logs. In this scenario, the security engineer already has a CloudTrail log entry and needs to search through the logs for patterns of similar malicious activity. CloudWatch Logs Insights allows running queries to identify such patterns. Amazon GuardDuty is a threat detection service that automatically monitors for malicious activity, but it does not provide a means for the engineer to directly analyze log data; it generates findings based on its own analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and evaluates them against compliance rules, but it does not ingest or analyse CloudTrail log data for patterns of malicious API activity. It is tempting because Config can track S3 bucket deletions as configuration changes and trigger alerts, yet it lacks the log-analysis and anomaly-detection engine needed to identify repeated unauthorised calls across time. For investigating historical API patterns, the correct service is Amazon Detective or Amazon GuardDuty, which ingest CloudTrail events and apply machine learning to surface suspicious sequences.
- ✓
Amazon CloudWatch Logs Insights
Why this is correct
Amazon CloudWatch Logs Insights is a log query and analysis engine, not a purpose-built threat detection service. While it can search CloudTrail logs if they are streamed to Amazon CloudWatch Logs, it lacks GuardDuty's machine-learning models, anomaly detection, and integrated threat intelligence to automatically identify suspicious API activity. It requires you to manually craft queries based on prior knowledge of attack patterns, making it a reactive tool rather than a proactive detector of malicious behavior.
- ✗
AWS Artifact
Why it's wrong here
AWS Artifact is a compliance and audit documentation portal that provides access to AWS compliance reports, such as SOC, PCI DSS, and ISO certifications. It does not ingest or analyze CloudTrail logs, nor does it monitor API activity or network traffic for threats. Its purpose is to support external audit and regulatory requirements, not to provide security detection or investigation of historical API calls.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is correct because it is a managed threat detection service that ingests AWS CloudTrail event logs, VPC Flow Logs, and DNS logs, applying machine learning, anomaly detection, and threat intelligence to identify malicious or unauthorized activity. For example, it can detect repeated failed API calls, unusual IAM user behavior, or compromised credentials by analyzing patterns across CloudTrail events. GuardDuty generates actionable findings with severity levels, enabling security engineers to investigate and respond without needing to write custom detection queries.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.