Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is setting up Amazon GuardDuty in a new AWS account. The engineer wants to ensure that GuardDuty can detect compromised EC2 instances that are exhibiting unusual network behavior, such as cryptocurrency mining. Which GuardDuty feature should the engineer enable to monitor network traffic for such threats?

⚠ Common exam trap

Test-takers frequently confuse GuardDuty's network monitoring capabilities with its other protections, such as S3 or EKS, which are specific to those services and not for EC2 network traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GuardDuty VPC Flow Logs and DNS Logs analysis

GuardDuty continuously monitors VPC Flow Logs and DNS logs to identify unusual network activity, including connections to known malicious IPs or domains used for cryptocurrency mining. This network-based detection is a fundamental feature of GuardDuty and is enabled by default. Other features like S3 Protection, EKS Protection, and Runtime Monitoring address different threat vectors and are not the primary mechanism for detecting network-based threats on EC2 instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    GuardDuty VPC Flow Logs and DNS Logs analysis

    Why this is correct

    GuardDuty analyzes VPC Flow Logs and DNS logs to detect unusual network behavior, such as communication with known malicious IPs or domains associated with cryptocurrency mining. This is a core capability of GuardDuty and is enabled by default. It does not require additional agents and provides network-level threat detection for EC2 instances.

  • ✗

    GuardDuty EKS Protection

    Why it's wrong here

    EKS Protection is designed to monitor Amazon EKS clusters for suspicious activity, such as unusual API calls or pod behavior. It does not monitor EC2 instance network traffic. While valuable for Kubernetes environments, it is not relevant to detecting cryptocurrency mining on standalone EC2 instances.

  • ✗

    GuardDuty S3 Protection

    Why it's wrong here

    S3 Protection focuses on detecting suspicious access to S3 buckets, such as unusual data retrieval patterns or attempts to disable S3 logging. It does not monitor EC2 network traffic for cryptocurrency mining or other network-based threats. Enabling it would not address the requirement to detect unusual network behavior on EC2 instances.

  • ✗

    GuardDuty Runtime Monitoring

    Why it's wrong here

    Runtime Monitoring provides visibility into runtime behavior of workloads, including processes and file system activity, to detect threats like malware or cryptocurrency mining. However, it requires the GuardDuty agent and is more focused on runtime events rather than network traffic analysis. It can complement network monitoring but is not the primary feature for network-based detection.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.