SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is setting up Amazon GuardDuty in a new AWS account. The engineer wants to ensure that GuardDuty can detect compromised EC2 instances that are exhibiting unusual network behavior, such as cryptocurrency mining. Which GuardDuty feature should the engineer enable to monitor network traffic for such threats?
⚠ Common exam trap
Test-takers frequently confuse GuardDuty's network monitoring capabilities with its other protections, such as S3 or EKS, which are specific to those services and not for EC2 network traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GuardDuty VPC Flow Logs and DNS Logs analysis
GuardDuty continuously monitors VPC Flow Logs and DNS logs to identify unusual network activity, including connections to known malicious IPs or domains used for cryptocurrency mining. This network-based detection is a fundamental feature of GuardDuty and is enabled by default. Other features like S3 Protection, EKS Protection, and Runtime Monitoring address different threat vectors and are not the primary mechanism for detecting network-based threats on EC2 instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
GuardDuty VPC Flow Logs and DNS Logs analysis
Why this is correct
GuardDuty analyzes VPC Flow Logs and DNS logs to detect unusual network behavior, such as communication with known malicious IPs or domains associated with cryptocurrency mining. This is a core capability of GuardDuty and is enabled by default. It does not require additional agents and provides network-level threat detection for EC2 instances.
- ✗
GuardDuty EKS Protection
Why it's wrong here
EKS Protection is designed to monitor Amazon EKS clusters for suspicious activity, such as unusual API calls or pod behavior. It does not monitor EC2 instance network traffic. While valuable for Kubernetes environments, it is not relevant to detecting cryptocurrency mining on standalone EC2 instances.
- ✗
GuardDuty S3 Protection
Why it's wrong here
S3 Protection focuses on detecting suspicious access to S3 buckets, such as unusual data retrieval patterns or attempts to disable S3 logging. It does not monitor EC2 network traffic for cryptocurrency mining or other network-based threats. Enabling it would not address the requirement to detect unusual network behavior on EC2 instances.
- ✗
GuardDuty Runtime Monitoring
Why it's wrong here
Runtime Monitoring provides visibility into runtime behavior of workloads, including processes and file system activity, to detect threats like malware or cryptocurrency mining. However, it requires the GuardDuty agent and is more focused on runtime events rather than network traffic analysis. It can complement network monitoring but is not the primary feature for network-based detection.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.