SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is reviewing AWS CloudTrail logs and notices repeated `CreateTrail` API calls from an IAM user that is not authorized to create trails. What is the MOST likely cause of these log entries?
⚠ Common exam trap
Many candidates think CloudTrail only logs successful API calls, but in reality, it logs all API calls, including those that are denied, which is why the repeated `CreateTrail` entries appear even though the user is not authorized.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM user attempted to create a trail but was denied due to lack of permissions.
The repeated `CreateTrail` API calls in CloudTrail logs indicate that an IAM user is attempting to create a trail. Since the user lacks the required `cloudtrail:CreateTrail` permission, the API call is recorded as an attempted action that was denied by AWS Identity and Access Management (IAM) policy evaluation. CloudTrail logs all API calls, including those that fail due to insufficient permissions, which is why these entries appear in the logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IAM user attempted to create a trail but was denied due to lack of permissions.
Why this is correct
CloudTrail is designed to record every API request made on an account, including actions that fail authorization. When the IAM user attempts CreateTrail, CloudTrail writes a management event with the userIdentity of that user, even if the call is denied with AccessDenied and an errorCode and errorMessage. The presence of this attempt in the logs is therefore normal, and it does not indicate that a trail was successfully created.
- ✗
AWS GuardDuty is generating simulated events.
Why it's wrong here
GuardDuty is a threat detection service, not a log generator; it consumes existing sources such as CloudTrail management events, VPC Flow Logs, and DNS logs to produce findings. A GuardDuty finding appears in the GuardDuty console or through its export mechanisms, but GuardDuty never injects simulated API calls into CloudTrail event history. Therefore, an unexpected IAM user action in CloudTrail cannot be caused by GuardDuty test events.
- ✗
S3 server access logs are enabled for the trail's S3 bucket.
Why it's wrong here
S3 server access logs are object-level audit logs of every HTTP request sent to the bucket, recording the requester, bucket name, key, and response status for operations like GET and PUT. If enabled, those logs are delivered as objects to a separate destination bucket and do not write entries into CloudTrail event history. Consequently, enabling them on the trail bucket explains object-level access documentation, not an API call attributed to an IAM user in CloudTrail.
- ✗
CloudTrail is configured to log only data events.
Why it's wrong here
A trail configured to log only data events captures object-level operations such as S3 object access or Lambda invocations, but it no longer captures management events, including CreateTrail calls. Since management events are logged by default unless explicitly excluded, a data-event-only trail would actually reduce the number of IAM user actions that appear in CloudTrail, not add an unexpected user event. This misconfiguration therefore cannot account for a mysterious IAM user API attempt.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.