SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer needs to analyze large volumes of VPC Flow Logs stored in Amazon S3 to identify anomalous traffic patterns. Which approach is MOST cost-effective and scalable?
⚠ Common exam trap
Test-takers frequently confuse AWS Glue's cataloging role with a query engine, or assume QuickSight can directly query S3 without an intermediate service, leading them to overlook Athena's serverless, pay-per-query model as the optimal choice for scalable log analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Amazon Athena with partitioned data in S3.
Amazon Athena is the most cost-effective and scalable solution for querying large volumes of VPC Flow Logs stored in S3 because it uses a serverless, pay-per-query model with no infrastructure to manage. By partitioning the data (e.g., by date or region), Athena minimizes the amount of data scanned per query, directly reducing costs while enabling complex SQL-based analysis for anomaly detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Glue to catalog and query the logs.
Why it's wrong here
AWS Glue is a serverless data integration service used primarily for extract, transform, and load (ETL) work. It can crawl and catalog the VPC Flow Logs' metadata in its Data Catalog, but it does not provide an interactive query engine to directly SELECT from those logs. You would still need Athena or another query service to analyze the data, so using Glue alone to 'query' logs is a misunderstanding of its role.
- ✗
Download the logs to an EC2 instance and use grep commands.
Why it's wrong here
Downloading VPC Flow Logs to an EC2 instance and running grep makes a single instance the bottleneck for storage, network transfer, and CPU-bound pattern matching, which doesn't scale to the large data volumes common in flow log analysis. You also have to provision, patch, and monitor the instance capacity, a significant operational burden compared to a serverless service. As data accumulates, grep's performance degrades sharply, whereas a query engine with partitioning and columnar storage would remain responsive.
- ✓
Use Amazon Athena with partitioned data in S3.
Why this is correct
Amazon Athena is serverless and lets you run standard SQL directly against VPC Flow Logs stored in S3, requiring no ETL or infrastructure to manage. By partitioning the logs in S3—for example by year/month/day or by hour—you drastically reduce the amount of data scanned per query, and Athena charges per byte scanned, so partitioning cuts costs substantially. Athena is built on Presto, supports filtering, grouping, and joins, and is well suited for ad-hoc security investigations over large volumes of network traffic.
- ✗
Use Amazon QuickSight to directly query the logs.
Why it's wrong here
Amazon QuickSight is a business intelligence and visualization service, not a raw data-query engine. While QuickSight can connect to Athena or other SQL engines to build dashboards, it does not let you run arbitrary SQL directly against S3 or interactively drill into logs with the same flexibility as an ad-hoc query engine. Its purpose is to present pre-aggregated insights visually, not to serve as the primary tool for deep, iterative log analysis in security incident response.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.